Phantom

Staff Platform Security Engineer (Security)

Phantom
Apply
3 hours ago
Remote, United States or Remote, CanadaStaff+
H1B sponsor

Base Salary

$200k - $250k/yr

Responsibilities

  • Own and improve security across Phantom’s multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails.
  • Secure production Kubernetes environments on Amazon EKS through cluster hardening, workload identity, RBAC, admission controls, network boundaries, secrets protection, container security, and tenant isolation.
  • Design least-privilege, scoped, auditable, and time-bound access models for engineers, services, and automation.
  • Protect mission-critical infrastructure supporting sensitive data and high-value operations.
  • Lead security design for new infrastructure, platform services, and major architectural changes.
  • Build reusable security controls with Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation.
  • Harden CI/CD and software supply chains, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and production access.
  • Build tools that identify and remediate cloud and Kubernetes risks at scale, including AI-assisted workflows where useful.
  • Partner with Infrastructure, SRE, Developer Experience, and product engineering teams to establish and adopt platform-security standards.
  • Respond to incidents and drive security problems from investigation through implementation and verified remediation.

Requirements

  • 7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering role.
  • Deep hands-on experience securing production AWS environments, including IAM, resource policies, workload identity, network security, secrets management, logging, and organization-level controls.
  • Deep production Kubernetes security experience, preferably with Amazon EKS, including RBAC, workload identity, admission policy, network policy, pod security, secrets, and cluster hardening.
  • Experience securing mission-critical systems where compromise, excessive privilege, or loss of availability could significantly affect customers or the business.
  • Strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction for human and machine access.
  • Experience securing CI/CD and software supply chains, including GitHub Actions or similar systems, build runners, workload federation, artifacts, and production deployment paths.
  • Experience writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar tools.
  • Ability to write production-quality code or automation in TypeScript, Python, Go, or Rust.
  • Experience with AWS Nitro Enclaves or other trusted execution environments, financial or high-value transaction systems, key-management infrastructure, multi-region AWS and Kubernetes environments, service meshes, cloud-native networking, policy as code, automated remediation, or security tooling is preferred.
  • Clear communication, high agency, ownership, and experience partnering with infrastructure and engineering teams.

Benefits

  • Fully remote role for candidates based in the US and Canada.
  • Competitive salary, equity, and eligibility for the company’s performance bonus program.
  • Comprehensive medical, dental, and vision insurance with 100% coverage.
  • Stipend for an ideal remote setup.
  • Flexible hours and a supportive remote environment.
  • Unlimited vacation, 401(k) retirement plan, monthly wellness benefit, weekly meal benefit, and global off-sites.

Tech Stack

Argo CDAWSDatadogGitHub ActionsGoHelmIstioKubernetesPythonRustTerraformTypeScript

Categories

Contact me