Senior Platform Security Engineer
Owns production-edge security for enterprise financial-institution connectivity, including PKI, mTLS, AWS networking, webhook security, and vulnerability remediation. Requires 6+ years of hands-on platform, infrastructure, or network security engineering experience.
About the job
Responsibilities
- Own and operate mutual-TLS certificate infrastructure for enterprise bank onboarding and product operations.
- Build and maintain security workflows for private network connectivity, including endpoint tenancy mapping and connection monitoring.
- Operate webhook delivery security, including signing-secret rotation, client-certificate management, and delivery-failure response for outbound integrations.
- Drive vulnerability remediation end-to-end, from application and infrastructure scanning through verified closure.
- Set and codify secure-build standards for the engineering team.
- Continuously improve the security posture by collaborating across engineering, product, and go-to-market teams.
Requirements
- 6+ years of experience in platform, infrastructure, or network security engineering, with hands-on ownership of production systems.
- Deep experience with PKI and certificate lifecycle management.
- Strong understanding of TLS and mTLS.
- Hands-on AWS networking and security experience.
- Working knowledge of OAuth 2.0, including client-credentials flow and JWT validation.
- Familiarity with certificate-bound token patterns.
- Experience setting security standards and working with engineering teams to adopt them.
Nice-to-haves
- Fintech or payments background, including experience integrating with bank or financial institution network edges.
- Experience with cloud infrastructure and tools such as AWS CDK.
- PCI DSS or SOC 2 technical control implementation experience.
- Prior experience on a small or early-stage security team.
Compensation and Benefits
- Anticipated base salary range: $210,000–$240,000 USD.
- Equity and benefits are included in total compensation.
- 100% paid medical, mental, dental, and vision premium option, plus One Medical membership for US-based employees.
- 401(k).
- 12 weeks of fully paid parental leave.
- Unlimited PTO.
- Work-from-home stipend.
- Company-paid lunches and Citibike membership.
- Flexible in-person culture at the NYC headquarters, with remote opportunities for certain roles in the US/Canada.
Skills
Pki, Certificate Lifecycle Management, Tls, Mtls, AWS, Aws Networking, Aws Security, Oauth 2.0, Jwt, Aws Cdk, Vulnerability Management, Pci Dss, SOC 2, Network Security
Similar jobs
Security Engineering jobsBuild secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.
Own and advance the security of Anyscale’s production and multi-cloud infrastructure, including hardening, segmentation, Kubernetes runtime protection, and access controls. Requires 8+ years of security engineering experience and hands-on expertise with AWS, Azure, Kubernetes, and cloud security tooling.
Leads a hands-on security engineering function spanning AI security, application and cloud security, detection and response, identity, and compliance controls. The role requires 8+ years of security engineering experience, deep AWS expertise, production code review ability, and experience operating in PCI DSS scope.