Staff Platform Security Engineer (Security)
Core
Own and improve security across AWS and Kubernetes environments, securing control planes, identities, workloads, and deployment systems for a crypto wallet platform serving tens of millions of users.
Role type
Senior Platform Security Engineer (Cloud & Kubernetes)
Builds
Production-grade security controls, automated remediation tools, and hardened CI/CD pipelines for AWS and EKS.
Domain
Cloud Security, Kubernetes Security, Infrastructure Security
Required skills
AWS security (IAM, networking, secrets, logging), Kubernetes security (RBAC, workload identity, admission controls, network policies), Identity and Access Management (least privilege), CI/CD and supply chain security, Infrastructure as Code (Pulumi, Terraform), Production code automation (TypeScript, Python, Go, Rust), Incident response, Security automation
Preferred skills
AWS Nitro Enclaves, Financial/custody system security, Key management infrastructure (AWS KMS, CloudHSM), Multi-region cloud operations, Service meshes (Istio), Cloud-native networking (eBPF, PrivateLink), Policy-as-code, Blockchain/wallet architecture
Technologies
AWS, Amazon EKS, Pulumi, Terraform, Kubernetes, GitHub Actions, TypeScript, Python, Go, Rust, Wiz, Datadog, GuardDuty, Security Hub, CloudTrail, Argo CD, Helm, Crossplane
Responsibilities
Design least-privilege access models for engineers and services; Secure production Kubernetes environments including cluster configuration and tenant isolation; Lead security design for new infrastructure and major architectural changes; Harden build, deployment, and release systems including dependency signing and provenance; Build tools to identify and remediate cloud and Kubernetes risks at scale; Partner with infrastructure and engineering teams to establish and adopt platform-security standards.
Seniority
Senior, hands-on IC