Remote job
Security Engineer, Platform
Job details
About this role
Role overview A fast-growing developer product company is hiring its first dedicated security engineer to harden the internal platform that powers how teams build, deploy, observe, and operate services. The position focuses on embedding security into foundations and pipelines rather than layering it on after the fact, with broad influence across infrastructure, access control, and incident response.
Responsibilities - Strengthen core security foundations such as API key management, service permissions, secrets handling, tenant isolation, audit logging, and internal access controls. - Design secure defaults for new services, workers, queues, databases, internal tools, and deployment pipelines so new systems ship safely by construction. - Build and tune detection and response for suspicious access, leaked credentials, abnormal activity, privilege changes, and other high-signal security events. - Review and update engineering processes so that security considerations are integrated early, not bolted on at the end. - Operate as the first dedicated security hire, setting priorities independently and raising the overall security bar across the organization.
Requirements - Hands-on experience securing production infrastructure, cloud environments, APIs, developer platforms, or multi-tenant SaaS products. - Comfort writing code and reading application, infrastructure, and deployment codebases to evaluate and improve them. - Working knowledge of authentication, authorization, secrets management, IAM, logging, audit trails, incident response, and secure deployment pipelines. - Self-directed approach to prioritization and the judgment to favor practical improvements over heavy process. - Collaborative, low-ego communication style and a genuine care for developer experience, believing security should be easy to adopt.
Nice to have - Familiarity with email infrastructure, transactional sending, sender reputation, domain verification, and related DNS-based authentication concepts. - Experience with cloud and infrastructure tooling such as AWS, Terraform, Kubernetes, or Cloudflare. - Background in open source security, organization hardening, package publishing, dependency review, or supply-chain security. - Prior work preparing a company for SOC 2, ISO 27001, GDPR, or enterprise security reviews without slowing engineering velocity. - Experience building security observability, alerting, detection pipelines, or incident response workflows, ideally in collaboration with trust and safety, anti-abuse, fraud, or platform integrity teams.
Benefits and work setup - Fully remote position with flexible working hours, plus occasional travel for team offsites, conferences, and meetups. - High-autonomy culture with direct ownership of problems and solutions. - Base compensation of $140,000 to $160,000 USD, depending on experience. - Remote team spread across many countries, using a modern collaboration and development stack.