Staff Platform Security Engineer (Security)
Phantom - United States
Hiring: Staff Platform Security Engineer (Security) Company: Phantom Location: United States Job Posted Time: 2026-09-17 01:27:18 Employment Type: Remote Target Skills & Keywords : AWS, ArgoCD, Blockchain, CI/CD, CloudFormation, Datadog, EKS, GitHub, GitHub Actions, Helm, IAM, Infrastructure as Code, Istio, Kubernetes, OIDC, Pulumi, Python, RBAC, Rust, Stripe, Terraform, TypeScript About the job Experience: •7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering role. Required Skills: •AWS Security: Own and improve security across Phantom’s multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails. •Kubernetes Security: Secure production Kubernetes environments running on Amazon EKS, including cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation. •Identity and Access: Design least-privilege access models for engineers, services, and automation. Build scoped, auditable, and time-bound access paths for sensitive production systems. •Mission-Critical Systems: Protect the infrastructure supporting products and services that handle sensitive data and high-value operations. •Cloud Security Architecture: Lead security design for new infrastructure, platform services, and major architectural changes. •Infrastructure and Policy as Code: Build reusable security controls using tools such as Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation. •CI/CD and Supply Chain Security: Harden build, deployment, and release systems, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and access to production environments. •Security Automation: Build tools that identify and remediate cloud and Kubernetes risks at scale. Apply AI-assisted workflows where they materially improve analysis, coverage, or response speed. Qualifications: •Deep, hands-on experience securing production AWS environments. You understand IAM and resource policies, workload identity, network security, secrets management, logging, organization-level controls, and the ways these systems fail in practice. •Deep experience securing Kubernetes in production, preferably Amazon EKS, including RBAC, workload identity, admission policy, network policy, pod security, secrets, and cluster hardening. •In-depth knowledge of identity, authorization, least privilege, isolation, and blast-radius reduction across both human and machine access. •Demonstrated capacity to write production-quality code or automation in a language such as TypeScript, Python, Go, or Rust. •High agency and ownership. You can take an ambiguous platform-security problem from initial investigation through implementation and verified remediation. •Clear communication and a strong track record of partnering with infrastructure and engineering teams while maintaining a high security bar. •Operational familiarity with key-management infrastructure, AWS KMS, CloudHSM, cryptographic signing systems, or secrets-management platforms. Compensation: •$200,000 - $250,000 / year •Flexible work environment (work from home / hybrid options) •Phantom is built by a team of experienced product and engineering leaders working to make crypto-powered finance safer and easier to use Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!