Staff Platform Security Engineer @Phantom
All Others
Salary usd 200,000 - 2..
Remote Location
Employment Type full-time
Posted 2wks ago

[Hiring] Staff Platform Security Engineer @Phantom

2wks ago - Phantom is hiring a remote Staff Platform Security Engineer. 💸 Salary: usd 200,000 - 250,000 per year 📍Location: USA, Canada

Role Description

Phantom is hiring a Senior Platform Security Engineer to own and improve security across our AWS and Kubernetes environments. You’ll work directly with infrastructure and engineering teams to secure the control planes, identities, workloads, and deployment systems behind our most critical products.

We’re building an AI-native security team that aggressively uses AI to expand the speed, depth, and reach of our work. This is a hands-on role for someone who is comfortable working in production systems, writing code and infrastructure, responding to incidents, and making security improvements without slowing down the teams building on the platform.

This role is fully remote; however, we’re only open to candidates based in the US and Canada.

Responsibilities

  • AWS Security: Own and improve security across Phantom’s multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails.
  • Kubernetes Security: Secure production Kubernetes environments running on Amazon EKS, including cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation.
  • Identity and Access: Design least-privilege access models for engineers, services, and automation. Build scoped, auditable, and time-bound access paths for sensitive production systems.
  • Mission-Critical Systems: Protect the infrastructure supporting products and services that handle sensitive data and high-value operations.
  • Cloud Security Architecture: Lead security design for new infrastructure, platform services, and major architectural changes.
  • Infrastructure and Policy as Code: Build reusable security controls using tools such as Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation.
  • CI/CD and Supply Chain Security: Harden build, deployment, and release systems, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and access to production environments.
  • Security Automation: Build tools that identify and remediate cloud and Kubernetes risks at scale. Apply AI-assisted workflows where they materially improve analysis, coverage, or response speed.
  • Cross-Functional Leadership: Partner closely with Infrastructure, SRE, Developer Experience, and product engineering teams. Establish practical platform-security standards and help teams adopt them.

Qualifications

  • 7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering role.
  • Deep, hands-on experience securing production AWS environments, including IAM and resource policies, workload identity, network security, secrets management, logging, organization-level controls.
  • Deep experience securing Kubernetes in production, preferably Amazon EKS, including RBAC, workload identity, admission policy, network policy, pod security, secrets, and cluster hardening.
  • Experience designing or securing mission-critical systems where compromise, excessive privilege, or loss of availability could have significant customer or business impact.
  • Strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction across both human and machine access.
  • Experience securing CI/CD and software supply chains, including GitHub Actions or similar systems.
  • Experience writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar tools.
  • Ability to write production-quality code or automation in a language such as TypeScript, Python, Go, or Rust.
  • High agency and ownership in taking an ambiguous platform-security problem from initial investigation through implementation and verified remediation.
  • Clear communication and a strong track record of partnering with infrastructure and engineering teams while maintaining a high security bar.

Nice To Haves

  • Experience with AWS Nitro Enclaves or other trusted execution environments.
  • Experience securing financial, payments, wallet, custody, or other high-value transaction systems.
  • Familiarity with key-management infrastructure, AWS KMS, CloudHSM, cryptographic signing systems, or secrets-management platforms.
  • Experience operating or securing multi-region Kubernetes and AWS environments at significant scale.
  • Familiarity with service meshes and cloud-native networking technologies such as Istio, PrivateLink, Transit Gateway, or eBPF-based controls.
  • Experience with GitHub OIDC, Argo CD, Helm, Crossplane, or Kubernetes-based infrastructure delivery.
  • Experience using cloud-security and observability platforms such as Wiz, Datadog, GuardDuty, Security Hub, or CloudTrail.
  • Experience building policy-as-code, automated remediation, or security tooling used by a large engineering organization.
  • Familiarity with blockchain infrastructure or self-custodial wallet architecture.

Benefits

  • Competitive salary and equity
  • Eligibility to participate in the company’s performance bonus program
  • Comprehensive medical, dental, and vision insurance with 100% coverage
  • Stipend for your ideal remote setup
  • Flexible hours and a supportive remote environment
  • Unlimited vacation—take time when you need it
  • 401(k) retirement plan
  • Monthly wellness benefit
  • Weekly meal benefit
  • Global off-sites
Before You Apply
️
remote Be aware of the location restriction for this remote position: USA, Canada
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Staff Platform Security Engineer @Phantom
All Others
Salary usd 200,000 - 2..
Remote Location
Employment Type full-time
Posted 2wks ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: USA, Canada
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 127,070+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later