Full Scale

Staff Platform Security Engineer

Full Scale Cebu City, Central Visayas, Philippines

Outsourcing and Offshoring Consulting · 201-500 employees

14 h ago
Remote security Principal (10+ yrs) Full-time Philippines
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Staff Platform Security Engineer will own and strengthen security across cloud infrastructure, Kubernetes environments, and production access. They will partner with engineering and compliance teams to implement security controls, manage vulnerabilities, and drive security architecture reviews.

What they look for

Cloud security Platform security Azure Kubernetes AKS Infrastructure as code DevSecOps Vulnerability management IAM RBAC CI/CD Threat modeling Security architecture Network security Secrets management Compliance

Requirements

Candidates must have 8+ years of experience in cloud or platform security with deep hands-on expertise in Microsoft Azure and Kubernetes. Strong proficiency in infrastructure as code, CI/CD security, and identity access management is required.

Benefits

100% remote work setup Work from anywhere in the Philippines Direct visibility and collaboration with the CTO High-impact role with significant technical ownership and autonomy Opportunity to work on a cloud-native healthcare/SaMD platform Exposure to modern Azure, AKS, Kubernetes, and cloud security technologies Opportunity to work in a regulated, high-assurance environment Collaboration with Engineering, Product, IT, Quality, and Compliance teams

Full description

This is a remote position

Join one of the Philippines' fastest-growing tech companies! Open to Philippine-based candidates only.

About Us

Full Scale is a fully remote-first company that helps businesses build dedicated teams of skilled software engineers. We make it easier for growing companies to find, onboard, and retain high-performing software talent.

About the Role

We are looking for a Senior / Staff Platform Security Engineer to own and strengthen security across SOTA Cloud's cloud infrastructure, Kubernetes environment, production access, vulnerability management, and security tooling. This is a hands-on individual contributor role with direct visibility to the CTO. You will work closely with Engineering, IT, Quality, Product, and Security & Privacy Compliance teams to implement practical security controls, identify and reduce risk, and help engineering teams build and operate securely.

The role is primarily focused on cloud and platform security, with DevOps, infrastructure as code, and CI/CD security as important supporting areas.

What You'll Do

  • Own and improve security across Azure, AKS, Azure SQL, networking, storage, identity, secrets, and production environments.
  • Harden Kubernetes workloads, containers, ingress, workload identity, secrets, and network controls.
  • Design and improve least-privilege and privileged access models, including RBAC, PIM, just-in-time access, MFA, and access reviews.
  • Own vulnerability management, including triage, risk-based prioritization, remediation tracking, exceptions, and reporting.
  • Configure and optimize security and monitoring tools to improve threat detection and reduce unnecessary security noise.
  • Implement security guardrails across CI/CD and Infrastructure as Code, including SAST, SCA, secrets scanning, IaC scanning, and container scanning.
  • Partner with software engineers to make security findings understandable, actionable, and resolved at the source.
  • Support security architecture reviews, threat modeling, incident response, and root-cause analysis when needed.
  • Partner with Security & Privacy Compliance on audits, risk assessments, customer reviews, and technical security evidence.
  • Develop security recommendations, standards, and implementation plans and communicate them clearly to technical and executive stakeholders.

Requirements

  • 8+ years of experience in cloud security, platform security, security engineering, infrastructure security, DevSecOps, SRE, DevOps, or related technical infrastructure roles.
  • 4+ years of security-focused experience in cloud security, platform security, application security, DevSecOps, or production security engineering.
  • Deep hands-on experience with Microsoft Azure, particularly AKS, Entra ID, networking, storage, Azure SQL, Key Vault/secrets management, monitoring, and production access controls.
  • Strong understanding of cloud and platform security architecture, least privilege, secure configuration, production access, and vulnerability remediation.
  • Hands-on experience with Kubernetes and container security, including workload identity, ingress, network controls, secrets, and runtime hardening.
  • Experience with IAM, RBAC, PIM, privileged access, just-in-time access, and access reviews.
  • Strong Infrastructure as Code experience using Terraform, Bicep, ARM, or comparable tools.
  • Practical experience with CI/CD pipelines and software delivery workflows, including security controls and automated scanning.
  • Strong ability to assess vulnerabilities based on exploitability, exposure, business impact, and blast radius, rather than relying solely on severity scores.

What Makes Someone Successful

You will be successful in this role if you can own platform security from strategy through implementation, identify meaningful risks, and turn security requirements into practical controls.

  • Excellent communication skills and the ability to work independently, identify security gaps, make recommendations, and drive solutions through completion.

Nice to Have

  • Experience working in regulated environments such as HIPAA, SOC 2, ISO 13485, ISO 27001, FDA-regulated software, healthcare SaaS, fintech, or other high-assurance environments.
  • Experience with SaMD, medical device software, FDA QMSR, ISO 13485/MDSAP, or validated software development environments.
  • Familiarity with Aikido, CrowdStrike, Vanta, New Relic, Microsoft Defender for Cloud, Microsoft Sentinel, or comparable tools.
  • Experience with SAML, OIDC, SCIM, SSO, MFA, Conditional Access, and PIM.
  • Experience with Azure Policy, Log Analytics, Key Vault, managed identities, and workload identity.
  • Experience with GitHub Actions, Azure DevOps, or comparable CI/CD platforms.
  • Experience with threat modeling, secure architecture reviews, incident response, or root-cause analysis.
  • Certifications such as Azure Security Engineer Associate, Certified Kubernetes Security Specialist (CKS), CCSP, CISSP, or equivalent hands-on experience.
  • Experience with .NET, Angular, or multi-tenant SaaS environments.

Benefits

Why join us:

  • 100% remote work setup
  • Work from anywhere in the Philippines
  • Direct visibility and collaboration with the
  • High-impact role with significant technical ownership and autonomy
  • Opportunity to work on a cloud-native healthcare/SaMD platform
  • Exposure to modern Azure, AKS, Kubernetes, and cloud security technologies
  • Opportunity to work in a regulated, high-assurance environment
  • Collaboration with Engineering, Product, IT, Quality, and Compliance teams

Similar roles