Gorgias
Tech / AI / Software
StaffSecurityPlatformEngineer
Neural analysis suggests this role is
optimal for Senior candidates.
“Staff Security Platform Engineer at Gorgias. Skills: Cloud security, Kubernetes security, Platform security, Detection and response, Compliance. Contribute to security program. Implement and manage essential security tools and processes”
Industry & Context.
Responding to incidents; Drive meaningful signal-to-noise improvements in SIEM; Ensure least-privilege is real, not theoretical
What They're Looking For.
Must Have
5+ years in infrastructure security, cloud security, or security engineering, Deep GCP and Kubernetes expertise, Networking fundamentals, Hands-on CI/CD and IaC hardening, Auth expertise, Policy-as-code experience, Detection and response background, Compliance experience, Scripting fluency
Nice to Have
SOC 2 Type II preferred
What You'll Do.
Contribute to security program
Implement and manage essential security tools and processes
Ensure resilience against potential external threats and attacks
Set up proactive security measures
Own cloud and Kubernetes security (IAM
Design secure-by-default platforms (guardrails
Harden CI/CD and IaC pipelines
Lead secrets management (design and implement decoupled secrets architecture)
Strengthen networking fundamentals (VPC design
cross-cloud connectivity
zero-trust segmentation)
Build security-focused logging and monitoring
Implement runtime detection
Develop incident response playbooks
Manage and evolve the SIEM
Design and enforce auth standards
Audit and mature privileged access management
Own ongoing health of SOC 2 Type II
Drive next compliance milestones (ISO 27001
How You'll Work.
Team & Collaboration
Working directly with SRE team; Working directly with engineering leadership; Guiding teams without blocking them with guardrails and policy enforcement
Full Job Description
We believe conversations will become the #1 way to shop. At Gorgias, we’re building the platform that makes this real: a unified AI agent that sells, supports, and re-engages customers across the entire journey. Conversational Commerce is the future of ecommerce, and we’re leading that shift. Our mission is to turn every interaction between a brand and its customers into a relationship: personal, seamless, and intelligent. By combining deep product expertise with the latest in AI, we’re making shopping feel more natural, human, and connected than ever before. To win, we focus relentlessly on: - Quality: conversations that feel authentic and on-brand. - Experience: effortless shopping from chat to checkout. - Re-engagement: personal, 1-1 dialogue instead of noisy marketing. The opportunity is massive. As AI reshapes how people buy, Gorgias is building the foundation for the next decade of ecommerce, where every brand has its own intelligent agent and every customer feels understood. Join us to make Conversational Commerce real. About the role As a Gorgias Platform Security Engineer, you will contribute to our security program, working directly with our SRE team and engineering leadership. You will implement and manage essential security tools and processes, with a particular focus on ensuring resilience against potential external threats and attacks. This role will be critical in setting up proactive security measures and responding to incidents, making a tangible impact on Gorgias’ ability to meet enterprise-grade security standards. What you will do Platform & cloud security - Own cloud and Kubernetes security — IAM, RBAC, network policies, workload identity, and GKE hardening across 10+ global clusters - Design secure-by-default platforms — build guardrails and policy enforcement (OPA, Kyverno, or similar) that guide teams without blocking them - Harden CI/CD and IaC pipelines — secure GitHub Actions, ArgoCD, and Terraform workflows end-to-end - Lead secrets manag
Applying for this Staff Security Platform Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about Gorgias?
Real rants from real employees. Read before you apply.