Remote job
Security Engineer, Platform
Job details
About this role
Role overview
Strengthen the security foundations of a high-scale developer platform and make secure engineering practices practical to adopt. As the first dedicated security hire, you will work across infrastructure, applications, deployment systems, and operational processes to reduce risk while preserving a strong developer experience.
Responsibilities
- Build and improve controls for API keys, service permissions, secrets, tenant isolation, audit logs, and internal access. - Establish secure defaults for services, workers, queues, databases, internal tools, and deployment pipelines. - Improve detection and response for suspicious access, leaked credentials, unusual sending activity, privilege changes, and other sensitive events. - Review engineering processes and delivery pipelines so security is integrated into normal development work. - Raise the organization’s security baseline through practical improvements, prioritization, and direct technical execution. - Independently manage day-to-day priorities while partnering with engineering and other operational teams.
Requirements
- Experience securing production infrastructure, cloud environments, APIs, developer platforms, or multi-tenant SaaS products. - Ability to write code and confidently read application, infrastructure, and deployment code. - Working knowledge of authentication, authorization, secrets management, IAM, logging, audit trails, incident response, and secure delivery pipelines. - Strong independent judgment and a practical approach that avoids unnecessary process. - Direct, curious, low-ego communication and a willingness to learn from others. - Commitment to making security easy for engineering teams to use correctly.
Nice to have
- Experience with email infrastructure, transactional email, sender reputation, domain verification, or SPF. - Familiarity with AWS, Terraform, Kubernetes, Cloudflare, or comparable systems. - Background in open-source security, organization hardening, dependency review, package publishing, or supply-chain security. - Experience with SOC 2, ISO 27001, GDPR, enterprise security reviews, security observability, detection pipelines, incident response, trust and safety, fraud, or platform integrity.
Benefits and work setup
- Fully remote role for candidates in the Americas or European time zones. - Flexible working schedules, with some travel expected for team offsites, conferences, and meetups. - High autonomy, flexible ownership, and a collaborative, low-ego environment. - Published compensation range: $140,000–$160,000 USD, depending on experience.