Jobgether

Staff Platform Security Engineer (Security)

Jobgether Canada · $200K–$250K/yr

Internet Marketplace Platforms · 11-50 employees

23 h ago
Remote security Senior (5-10 yrs) Full-time Canada
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will own and improve security across critical AWS and Kubernetes infrastructure while partnering with engineering teams to embed security into the platform. The role involves designing security architecture, building infrastructure-as-code controls, and developing automated workflows to enhance security coverage.

What they look for

AWS Kubernetes Cloud security Identity and access management Infrastructure as code CI/CD Software supply chain security Python Go TypeScript Rust Terraform Pulumi Amazon EKS Security architecture Incident response

Requirements

Candidates must have 7+ years of experience in platform or cloud security with deep hands-on expertise in AWS and Kubernetes environments. Proficiency in writing production-quality code and managing infrastructure-as-code is essential for this high-impact role.

Benefits

Equity participation Performance bonus program Medical insurance Dental insurance Vision insurance Remote-work stipend Flexible working hours Unlimited vacation 401(k) retirement plan Monthly wellness benefit Weekly meal benefit Global company off-sites

Full description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Platform Security Engineer (Security) based in Canada.

As a Staff Platform Security Engineer, you will own security across critical AWS and Kubernetes infrastructure supporting products used by millions of people. You will work hands-on across cloud security, identity and access, workload isolation, CI/CD, software supply chains, and production systems. The role combines security architecture with practical engineering, requiring you to write code, build infrastructure controls, respond to incidents, and drive verified remediation. You will partner closely with infrastructure, SRE, developer experience, and product engineering teams to embed security into the platform without slowing delivery. You will also help shape an AI-native security function that uses automation and AI-assisted workflows to increase security coverage and response speed. This is a high-impact opportunity to influence architecture and strengthen the security of mission-critical systems in a fully remote environment.

\n

Accountabilities:

  • Own and continuously improve security across a multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails.
  • Secure production Kubernetes environments running on Amazon EKS, covering cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation.
  • Design and implement least-privilege access models for engineers, services, and automation, including scoped, auditable, and time-bound access to sensitive production systems.
  • Protect mission-critical infrastructure supporting systems that process sensitive information and high-value operations.
  • Lead security architecture and design for new infrastructure, platform services, and major architectural changes.
  • Build reusable infrastructure and policy-as-code controls using technologies such as Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation.
  • Harden CI/CD and software supply chains, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and production access.
  • Develop security automation that identifies and remediates cloud and Kubernetes risks at scale, using AI-assisted workflows where they can materially improve analysis, coverage, or response speed.
  • Partner closely with Infrastructure, SRE, Developer Experience, and product engineering teams to establish practical platform security standards and drive adoption.
  • Take ownership of security issues from initial investigation through implementation, remediation, and production verification.
  • Contribute directly to incident response and security improvements while maintaining a balance between strong controls and engineering velocity.

Requirements:

  • 7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering discipline.
  • Deep hands-on experience securing production AWS environments, including IAM and resource policies, workload identity, network security, secrets management, logging, organization-level controls, and common cloud security failure modes.
  • Strong production Kubernetes security experience, preferably with Amazon EKS, including RBAC, workload identity, admission policies, network policies, pod security, secrets, and cluster hardening.
  • Experience securing mission-critical systems where compromise, excessive privilege, or loss of availability could have significant customer or business consequences.
  • Strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction across both human and machine access.
  • Experience securing CI/CD pipelines and software supply chains, including GitHub Actions or comparable systems, build runners, workload federation, artifacts, and production deployment paths.
  • Experience writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar technologies.
  • Ability to write production-quality code and automation using a language such as TypeScript, Python, Go, or Rust.
  • High degree of ownership and agency, with the ability to take ambiguous platform security problems from investigation through implementation and verified remediation.
  • Strong communication skills and a proven ability to collaborate effectively with infrastructure and engineering teams while maintaining a high security standard.
  • Experience with AWS Nitro Enclaves or other trusted execution environments is an advantage.
  • Background securing financial, payments, wallet, custody, or other high-value transaction systems is a plus.
  • Familiarity with AWS KMS, CloudHSM, cryptographic signing systems, key-management infrastructure, or secrets-management platforms is beneficial.
  • Experience operating or securing multi-region AWS and Kubernetes environments at significant scale is a plus.
  • Familiarity with Istio, PrivateLink, Transit Gateway, eBPF-based controls, or other cloud-native networking technologies is advantageous.
  • Experience with GitHub OIDC, Argo CD, Helm, Crossplane, or Kubernetes-based infrastructure delivery is beneficial.
  • Familiarity with security and observability platforms such as Wiz, Datadog, GuardDuty, Security Hub, or CloudTrail is a plus.
  • Experience building policy-as-code, automated remediation, or security tooling used across large engineering organizations is valuable.
  • Familiarity with blockchain infrastructure or self-custodial wallet architecture is an advantage.

Benefits:

  • $200,000–$250,000 USD target base salary, with final compensation influenced by skills, relevant experience, interview performance, and market factors such as location.
  • Equity participation.
  • Eligibility for a performance bonus program.
  • Comprehensive medical, dental, and vision insurance with 100% coverage.
  • Stipend for an ideal remote-work setup.
  • Flexible working hours.
  • Fully remote and supportive work environment.
  • Unlimited vacation.
  • 401(k) retirement plan.
  • Monthly wellness benefit.
  • Weekly meal benefit.
  • Global company off-sites.
  • Opportunity to secure AWS and Kubernetes infrastructure supporting products used by millions of people.
  • High-impact work spanning cloud identity, production access, workload isolation, software supply chains, and mission-critical infrastructure.
  • Opportunity to build security controls directly into the platform rather than operating solely in an advisory or review capacity.
  • Ability to influence architecture early and own security improvements through implementation and production verification.
  • Opportunity to contribute to an AI-native security team focused on engineering, automation, and scalable security operations.

\nHow Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Similar roles