Company
Technology
StaffSecurityEngineer
Neural analysis suggests this role is
optimal for Senior candidates.
“Staff Security Engineer. Skills: Platform Security, DevSecOps, Cloud Security, Infrastructure as Code. Define platform security strategy. Evolve platform security strategy”
Industry & Context.
Complex systemic security problems
What They're Looking For.
Must Have
6+ years experience software engineering, 6+ years experience information security, Experience with AWS, Experience with GCP, Experience with Azure, Proficiency in Python, Proficiency in Go, Solid expertise in Infrastructure as Code, Solid expertise in Terraform, Solid expertise in modern cloud infrastructure, Hands-on experience implementing DevSecOps, Hands-on experience integrating security into CI/CD, Ability to design complex security problems, Ability to solve complex security problems, Experience with security architecture, Experience with microservices, Experience with API-based systems, Advanced English proficiency, Fluent English proficiency
Nice to Have
Java is a plus, Familiarity with compliance frameworks, Knowledge of threat modeling methodologies, MITRE ATT&CK knowledge desirable
What You'll Do.
Define platform security strategy
Evolve platform security strategy
Align engineering practices
Design secure architectures
Implement secure architectures
Build security standards
Build security guardrails
Develop security automation tools
Develop reusable frameworks
Develop internal platforms
Implement secure CI/CD pipelines
Integrate security testing practices
Conduct threat modeling
Conduct security design reviews
Collaborate with engineering teams
Integrate security into development
Participate in incident response
Participate in post-mortem analysis
Partner with SRE teams
Partner with product teams
Partner with engineering teams
Act as technical reference
How You'll Work.
Team & Collaboration
Engineering teams; SRE teams; Product teams; Cross-functional teams
Communication Scope
Influence stakeholders
Process & Methodology
Roadmap planning
Full Job Description
## Accountabilities Define and evolve the platform security strategy, aligning engineering practices with business and compliance requirements. Design and implement secure architectures for cloud-native systems, ensuring resilience, scalability, and strong security posture. Build security standards and guardrails as code, including Infrastructure as Code (Terraform), CI/CD pipelines, and containerized environments. Develop security automation tools, reusable frameworks, and internal platforms to embed security across engineering workflows. Implement and improve secure CI/CD pipelines, integrating security testing practices such as SAST, DAST, and SCA. Conduct threat modeling and security design reviews for critical systems, APIs, and platform features. Collaborate with engineering teams to integrate security into development lifecycles using shift-left and security-by-default principles. Participate in incident response processes and post-mortem analysis to strengthen system resilience. Partner with SRE, product, and engineering teams to balance security, performance, and usability in architectural decisions. Mentor engineers and act as a technical reference for secure development practices and DevSecOps adoption. Requirements 6+ years of experience in software engineering and information security, with a focus on platform or infrastructure security. Strong experience with cloud platforms such as AWS, GCP, or Azure and their security services. Proficiency in Python or Go for building automation, tooling, and security platforms (Java is a plus). Solid expertise in Infrastructure as Code (Terraform) and modern cloud infrastructure practices. Hands-on experience implementing DevSecOps practices and integrating security into CI/CD pipelines. Strong knowledge of container security and orchestration platforms such as Kubernetes. Ability to design and solve complex systemic security problems in distributed environments. Experience with security architecture, microservices,
Applying for this Staff Security Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Lever
- Lever uses a streamlined one-page form — apply in under 5 minutes.
- LinkedIn import works well; review parsed data before submitting.
- The cover letter field is optional but visible to reviewers — use it to differentiate.
- Referral codes from employees can significantly boost visibility of your application.
ANONYMOUS · UNFILTERED
What do employees actually say about this company?
Real rants from real employees. Read before you apply.