Quick Overview
Job Description
The Client is a technology company with a public safety mission. Its AI, machine learning, telematics, and cloud-connected systems help make the trip to and from school safer for students. The company is hiring a Sr Platform Security Engineer to make those platforms secure by default, resilient, and easier for engineering teams to operate safely.
This is a hands-on role focused on the platform layer: AWS identity and access, multi-account guardrails, network security, secrets and encryption, infrastructure-as-code, CI/CD security, vulnerability management, and security telemetry. You will partner with DevOps, application engineering, architecture, MLOps, IT, and Cyber Security to turn requirements into reusable controls and paved road patterns. This is not an application security or general SRE role. Its primary mandate is platform and cloud security engineering.
Must Have
• 8-10+ years in cloud, platform, or infrastructure security or DevSecOps
• AWS multi-account security (IAM, IAM Identity Center, Organizations, SCPs, Control Tower)
• KMS, Secrets Manager, Parameter Store
• GuardDuty, Security Hub, CloudTrail, AWS Config
• Terraform, AWS CDK, or CloudFormation
• Least-privilege and cross-account access
• CI/CD security (GitHub Actions, containers, artifacts)
• VPC, WAF, VPN, and network segmentation
• Vulnerability management and findings remediation
• Policy-as-code
• Linux, scripting, and Git
• Incident response experience
• Clear communication and written documentation
What You'll Do
• Design, implement, and improve security controls across AWS multi-account environments
• Build least-privilege identity patterns using AWS IAM, IAM Identity Center, Entra ID, permission sets, cross-account roles, and time-bound elevated access
• Build and maintain reusable Terraform modules and AWS CDK constructs for security controls, logging, encryption, networking, and guardrails
• Evolve AWS Organizations, Control Tower, service control policies, and account boundaries to reduce blast radius and improve governance
• Secure cloud networking, including VPCs, routing, security groups, network ACLs, WAF, private connectivity, site-to-site VPNs, and Direct Connect
• Operate secrets-management and encryption patterns with AWS KMS, Secrets Manager, Parameter Store, TLS, and automated credential rotation
• Integrate security checks into GitHub Actions and other pipelines, including infrastructure validation, dependency and container scanning, SBOMs, signing, and policy enforcement
• Develop policy-as-code and preventive guardrails with tools like AWS Config, SCPs, CloudFormation Guard, OPA, Conftest, Checkov, or tfsec
• Define secure golden paths and platform templates that make the safest approach the easiest one
• Operate cloud security telemetry across GuardDuty, Security Hub, CloudTrail, AWS Config, CloudWatch, and Datadog
• Triage and remediate findings from CNAPP, CSPM, vulnerability-management, and penetration-testing tools such as Wiz
• Support incident response, containment, root-cause analysis, and post-incident improvements
• Write concise architecture decisions, control designs, runbooks, and documentation
• Work with Cyber Security and GRC on SOC 2, ISO 27001, CIS, NIST, and audit readiness
• Mentor engineers through design reviews, infrastructure pull requests, and office hours
• Help secure AI-enabled engineering workflows, including sensitive data, non-human identities, secrets, and production change controls
Required Qualifications
• 8-10+ years of professional experience in cloud security, platform security, DevSecOps, infrastructure security, or a related discipline
• Deep hands-on experience securing production AWS environments, preferably across multiple accounts
• Strong knowledge of AWS IAM, IAM Identity Center, KMS, Secrets Manager, Parameter Store, CloudTrail, GuardDuty, Security Hub, AWS Config, Organizations, SCPs, and VPC security
• Demonstrated infrastructure security implementation with Terraform, AWS CDK, CloudFormation, or comparable tooling
• Experience designing and enforcing least-privilege, role-based, group-based, cross-account, and privileged-access controls
• Experience securing CI/CD pipelines, source-control workflows, build runners, artifacts, containers, and deployments
• Practical understanding of cloud network security, including segmentation, routing, security groups, WAF, private connectivity, site-to-site VPNs, and Direct Connect
• Experience with vulnerability management, risk prioritization, remediation tracking, and verifying control effectiveness
• Working knowledge of policy-as-code, preventive and detective controls, security automation, and compliance evidence collection
• Strong Linux, networking, scripting, Git, and troubleshooting skills
• Experience responding to or supporting production security incidents
• Ability to communicate clearly with engineers, architects, security professionals, auditors, and leadership
• Strong documentation habits and a pragmatic, automation-first mindset
• Able to work hybrid in Austin, TX
Preferred Qualifications
• AWS Control Tower, landing zones, account vending, or large-scale AWS governance
• Wiz, Qualys, Prisma Cloud, Lacework, or similar CNAPP/CSPM platforms
• GitHub Actions, OIDC federation, artifact registries, image signing, SBOM tooling, and supply-chain security
• Kubernetes or ECS security, container hardening, runtime controls, and workload identity
• Zero Trust, data protection, PII tokenization or redaction, DLP, or secure production-data access
• Experience supporting SOC 2, ISO 27001, CIS, NIST, or similar frameworks
• Familiarity with Backstage, internal developer platforms, or security self-service tooling
• Experience securing AI products, AI agents, model-serving infrastructure, or non-human identities
• Site-to-site VPNs, Direct Connect, Transit Gateway, private endpoints, and hybrid-cloud connectivity
• AWS Security, AWS Solutions Architect, AWS DevOps Engineer, CISSP, CCSP, or equivalent certification
Similar jobs
- HS
Lab IT Security Engineer / Endpoint Security Engineer
NewHS Solutions
CA🇺🇸Hybrid23 hours agoActive DirectoryPowerShellTechnology - AG
Ping Identity Security Analyst
NewASCII Group LLC
Dallas, TX🇺🇸$60/hrHybrid23 hours agoTechnology - MA
Principal Network Evaluator with Security Clearance
NewMarkon
Annapolis Junction, MD🇺🇸$120k - $225k/yrHybrid23 hours agoAdministrative - MA
Cyber Ops Hardware Engineer with Security Clearance
NewMarkon
Chantilly, VA🇺🇸$160k - $190k/yrHybrid23 hours agoTechnology - LE
Security Architect
NewLeidos
Bedford, MA🇺🇸$131.3k - $237.3k/yrHybrid23 hours agoOracleAWSAzure+12Technology - SA
Computer Systems Security Specialist with Security Clearance
NewSavvee Inc
Norfolk, VA🇺🇸On-site23 hours agoAdministrative - RE
Cryptologic Cyber Planner 3 with Security Clearance
NewRealmOne
central maryland, MD🇺🇸Hybrid23 hours agoTechnology - MA
Digital Network Exploitation Analyst with Security Clearance
NewMarkon
Chantilly, VA🇺🇸$120k - $150k/yrHybrid23 hours agoTechnology - SD
Cyber Defense Operator (CDO) with Security Clearance
NewSMS Data Products Group, Inc
Lackland AFB, TX🇺🇸On-site23 hours agoTCP/IPAssemblyDNSTechnology - MA
Information Systems Security Officer (ISSO) with Security Clearance
NewMarkon
Annapolis Junction, MD🇺🇸$120k - $200k/yrHybridYesterdayTechnology - II
Information System Security Engineer (ISSE) – ISSD with Security Clearance
NewIDS International
Annapolis Junction, MD🇺🇸Hybrid23 hours agoLESSMicrosoft OfficeTechnology - II
Cyber Virtualization Engineer with Security Clearance
NewIDS International
Arlington, VA🇺🇸On-site23 hours agoDockerOpenStackPacker+16Technology