Polymarket
prediction market platform
CloudSecurityEngineer
Neural analysis suggests this role is
optimal for Mid candidates.
“Cloud Security Engineer at Polymarket. Skills: AWS security, Infrastructure as code, Cloud security engineering, Security automation. Own and continuously improve Polymarket's AWS security posture across accounts, regions, and services. Review and contribute to IaC modules that encode security”
What You'll Achieve.
Reduce risk without slowing down engineering velocity; Make secure-by-default the path of least resistance
Industry & Context.
Evaluate architectural decisions for security risk
What They're Looking For.
Must Have
4+ years of experience in cloud security, cloud engineering, or a security-focused infrastructure role, Deep, hands-on expertise with AWS security services: IAM, SCP, GuardDuty, Security Hub, CloudTrail, Config, KMS, WAF, Inspector, and VPC, Hands-on experience writing infrastructure as code (Pulumi, Terraform, CDK, or equivalent) with a security-first mindset, understanding of AWS networking and how misconfigurations translate to real attack surface, Proficiency in at least one scripting or programming language (Python, TypeScript, or Go) for automation and tooling, Ability to evaluate architectural decisions for security risk and communicate findings clearly to engineering peers
Nice to Have
Familiarity with Pulumi, specifically TypeScript-based stacks, Familiarity with Web3, blockchain infrastructure, or crypto-sector threat models, Experience securing containerized workloads on ECS or EKS, including image scanning and runtime security, AWS certifications: Security Specialty, Solutions Architect — Professional, or equivalent, Exposure to SOC 2 Type II or PCI-DSS cloud control requirements
What You'll Do.
Own and continuously improve Polymarket's AWS security posture across accounts
Review and contribute to IaC modules that encode security
Integrate automated security checks into the deployment pipeline
Own cloud-side security telemetry
Develop and tune detection logic for cloud-specific threats
Govern secrets management
Manage KMS key policies
and envelope encryption patterns
Drive remediation of findings from AWS Inspector
Maintain benchmarks aligned to CIS AWS Foundations
Support audit and compliance activities (SOC 2
Conduct regular access reviews to identify and remediate privilege creep
How You'll Work.
Team & Collaboration
Embedded in engineering and security teams; Work closely with DevOps, Platform, and Application Engineering; Partner with the SOC team on alert fidelity, incident response runbooks, and AWS-level investigations; Communicate findings clearly to engineering peers
Communication Scope
Communicate findings clearly to engineering peers
Full Job Description
ABOUT POLYMARKET Polymarket is the world's largest prediction market platform. We enable individuals to express views on real-world events by trading on outcomes across politics, economics, sports, culture, and current affairs. Built as a peer-to-peer marketplace with no centralized "house," Polymarket aggregates diverse opinions into transparent, market-based probabilities that reflect collective expectations about the future. We're growing fast — both in terms of volume ($21B traded in 2025) and adoption as an alternative news source. Our ambition is to become a ubiquitous beacon of truth in global media and we need your help adding fuel to the fire. ABOUT THE ROLE Polymarket is hiring a Cloud Security Engineer to own the security posture of our AWS environment. You'll be embedded in our engineering and security teams, designing and enforcing security controls directly in infrastructure code, building guardrails that scale with the product, and reducing risk without slowing down engineering velocity. This role is hands-on and highly cross-functional. You'll work closely with DevOps, Platform, and Application Engineering to make secure-by-default the path of least resistance. WHAT YOU'LL DO - Own and continuously improve Polymarket's AWS security posture across accounts, regions, and services — including IAM policies, SCPs, VPC segmentation, and account-level security baselines - Review and contribute to IaC modules that encode security defaults; integrate automated security checks into the deployment pipeline including policy-as-code validation and misconfiguration scanning - Own cloud-side security telemetry: CloudTrail, GuardDuty, Security Hub, Config Rules, VPC Flow Logs, and S3 access logging - Develop and tune detection logic for cloud-specific threats; partner with the SOC team on alert fidelity, incident response runbooks, and AWS-level investigations - Govern secrets management using AWS Secrets Manager and SSM Parameter Store; manage KMS key policies,
Applying for this Cloud Security Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about Polymarket?
Real rants from real employees. Read before you apply.