Staff Security Engineer, PEG Security Engineering (Information Security, Architecture and Engineering)
Core
Own and operate the platform's security posture end-to-end for a PE platform handling sensitive deal data, embedding security into the development lifecycle via controls as code and zero-trust architecture.
Role type
Staff Security Engineer (Platform Security & Operations)
Builds
Secure-by-default templates, guardrails, policy-as-code libraries, and reusable CI checks for Platform Engineering squads.
Domain
Consulting / Platform Engineering / Cloud Security (Azure/AKS)
Deliverable
production ML models | product features | infrastructure
Required skills
Kubernetes security hardening, secrets management (Vault/Azure Key Vault), identity and access control (OIDC/SAML), supply chain security (SBOM/signing), threat modelling (STRIDE), incident response, runtime detection (Falco), data classification and masking, AI security (prompt injection/egress controls), policy enforcement (OPA/Gatekeeper/Cilium)
Preferred skills
Experience with HashiCorp Vault, Azure Key Vault, Istio mTLS, Falco, OPA/Gatekeeper, CI/CD pipeline integration
Technologies
Microsoft Azure, Azure Kubernetes Service (AKS), HashiCorp Vault, Azure Key Vault, Istio, Cilium, OPA, Gatekeeper, Falco, SAML, OIDC, JWT, Okta, Entra
Responsibilities
Design and implement zero-trust security architecture; manage supply chain security controls; define and enforce identity and access controls; conduct lightweight threat modelling; lead security incident response; run regular security reviews of the AI layer; embed in squad ceremonies to catch security concerns early; partner on secure-by-default templates; collaborate on PII classification and regulatory compliance.
Seniority
Staff, hands-on IC with strategic partnership