This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As a Platform Security Engineer, you are a developing security professional building expertise in securing cloud-native infrastructure, container platforms, CI/CD pipelines, and product services within the Platform Engineering organization. You take ownership of moderately complex security tasks with increasing autonomy while receiving guidance on architectural decisions and strategic direction. Your focus is the security posture of our platform and product infrastructure — the container orchestration layer, service mesh, observability stack, CI/CD pipelines, and cloud infrastructure that engineering teams build and deploy on. You implement and maintain security controls, build standardized security processes for engineering teams (vulnerability management, production security checks, secure build pipelines), support penetration testing and SOC operations for the product environment, contribute to compliance-related activities from the product security perspective, and help embed security practices into the developer experience through tooling and documentation. You are building depth and maturity in infrastructure security, application security, and shift-left practices needed to progress toward a senior platform security role.
Job Responsibility:
Implement and maintain security controls across the platform, including container orchestration security policies, network segmentation, role-based access controls, and admission control mechanisms
Manage container image scanning and enforce image policies in CI/CD pipelines and cluster admission, ensuring only vetted and signed images reach production environments
Support infrastructure-as-code security scanning using policy-as-code tooling, flagging and remediating misconfigurations in infrastructure definitions before they reach production
Maintain and improve secrets management workflows, ensuring rotation policies are enforced, access is audited, and no secrets are hardcoded or exposed in source code or configuration
Support cloud security posture management across cloud environments, monitoring for drift, misconfiguration, and compliance deviations against established baselines
Support service mesh security configuration including mutual TLS enforcement, authorization policies, and traffic policies that enforce zero-trust communication between platform services
Contribute to tenant isolation and access control configuration for shared platform services, ensuring appropriate segmentation between teams and environments
Conduct vulnerability assessments of platform and product infrastructure components, coordinating remediation with SRE, Platform Engineering, and product service teams
Maintain a vulnerability tracking system and produce regular reporting on security posture, remediation velocity, and risk trends for engineering leadership
Implement and maintain security gates in CI/CD pipelines including dependency scanning, static application security testing (SAST), software composition analysis (SCA), and container image scanning
Participate in security incident response for platform and product-related events, supporting investigation, containment, evidence preservation, and documentation under guidance from the Senior Platform Security Engineer
Support compliance-related activities from the product security perspective, providing evidence, documentation, and technical validation for audits and assessments (SOC 2, ISO 27001, CIS Benchmarks) without owning the compliance program itself
Vulnerability report generation, security posture dashboards, and remediation workflow tooling
Contribute to security reviews for infrastructure and product changes, providing feedback on pull requests and architecture proposals from a security perspective
Explain security concepts and requirements to engineering teams, empowering them to build securely and understand the rationale behind security controls
Requirements:
Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or related field
or equivalent combination of education and experience
2+ years of professional experience in security engineering, infrastructure security, DevSecOps, application security, or related field
Hands-on experience with at least one major cloud platform (Azure or AWS)
Working knowledge of container orchestration security concepts in Kubernetes: pod security, role-based access control, network policies, admission controllers
Experience with infrastructure-as-code tools and understanding of how to secure IaC workflows