Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Phantom

Staff Platform Security Engineer, Security

Phantom

. Own and improve security across Phantom’s multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails .

Posted 9/16/2026full-timeRemote • United StatesLead💰 $200,000 - $250,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive expertise in securing AWS environments and Kubernetes, with a focus on implementing least-privilege access models and robust security controls. Proven ability to lead security design initiatives and collaborate effectively with cross-functional teams to enhance platform security.

Highest-signal resume keywords
AWS SecurityKubernetes SecurityInfrastructure as CodeCI/CD SecurityIdentity and Access Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Platform SecurityCloud SecuritySecurity EngineeringRBACSecrets ManagementNetwork SecurityTypeScriptPythonGoRust
Soft Skills
Clear CommunicationHigh AgencyOwnership
Tools & Technologies
PulumiTerraformGitHub ActionsAmazon EKSCloudFormation
Industry Keywords
Production SystemsLeast Privilege AccessContainer SecurityWorkload IdentityAdmission Controls

Tech Stack

Tools & technologies
AWSCloudKubernetesPythonRustTerraformTypeScriptGo

About the role

Key responsibilities & impact
  • Own and improve security across Phantom’s multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails
  • Secure production Kubernetes environments running on Amazon EKS, including cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation
  • Design least-privilege access models for engineers, services, and automation
  • Build scoped, auditable, and time-bound access paths for sensitive production systems
  • Protect infrastructure supporting products and services that handle sensitive data and high-value operations
  • Lead security design for new infrastructure, platform services, and major architectural changes
  • Build reusable security controls using Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation
  • Harden CI/CD and release systems, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and access to production environments
  • Build tools that identify and remediate cloud and Kubernetes risks at scale
  • Apply AI-assisted workflows where they improve analysis, coverage, or response speed
  • Partner with Infrastructure, SRE, Developer Experience, and product engineering teams
  • Establish platform-security standards and help teams adopt them

Requirements

What you’ll need
  • 7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering role
  • Deep, hands-on experience securing production AWS environments
  • Understanding of IAM and resource policies, workload identity, network security, secrets management, logging, and organization-level controls
  • Deep experience securing Kubernetes in production, preferably Amazon EKS
  • Experience with RBAC, workload identity, admission policy, network policy, pod security, secrets, and cluster hardening
  • Experience designing or securing mission-critical systems
  • Strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction
  • Experience securing CI/CD and software supply chains, including GitHub Actions or similar systems, build runners, workload federation, artifacts, and production deployment paths
  • Experience writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar tools
  • Ability to write production-quality code or automation in TypeScript, Python, Go, or Rust
  • High agency and ownership
  • Clear communication and a strong track record of partnering with infrastructure and engineering teams
  • Candidates must be based in the US or Canada

Benefits

Comp & perks
  • Equity
  • Eligibility to participate in the company’s performance bonus program
  • Comprehensive medical, dental, and vision insurance with 100% coverage
  • Stipend for your ideal remote setup
  • Flexible hours and a supportive remote environment
  • Unlimited vacation—take time when you need it
  • 401(k) retirement plan
  • Monthly wellness benefit
  • Weekly meal benefit
  • Global off-sites