CareerPlanGet AI match score →
💼 Full-time🗓 2026-06-25

Core

Owns the security posture for a platform while contributing to reliability, implementing technical controls, and building security processes from scratch.

Role type

Platform Security Engineer

Builds

Security event monitoring, alerting, and compliance frameworks for a platform serving enterprise customers.

Domain

Cloud infrastructure security and platform reliability

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Kubernetes security, cloud security, infrastructure-as-code, vulnerability management, compliance frameworks, security incident response

Preferred skills

GCP, CNCF security tooling, Rust or Go

Technologies

Kubernetes, PostgreSQL, Cilium, Kyverno, Trivy, Renovate, Falco, Terraform, ArgoCD, Vanta

Responsibilities

Implement principle of least privilege across the stack, manage vulnerabilities systematically, build security event monitoring and alerting, prepare for and pass security audits, participate in on-call rotation alongside SRE team

Seniority

Mid-to-Senior, hands-on IC

Rewrite
## About the role The Platform Security Engineer will own Partly's security posture while contributing to platform reliability, reporting to Platform Lead. This role combines infrastructure security with platform reliability - someone who can harden our systems while keeping them running. Not a pure "checkbox compliance" role; we need someone who can implement technical controls and work hands-on with infrastructure. You'll be the first dedicated security hire at Partly, building processes from scratch while partnering closely with our SRE team. ## Responsibilities - Keep Partly reliable and secure. Participate in on-call rotation alongside the SRE team. Own security incident response planning and testing. Lead post-incident reviews for security-related incidents and participate in availability incidents. - Build security event monitoring and alerting. - Own our security posture and compliance. Prepare for and pass security audits (ISO 27001, future SOC 2). Maintain continuous compliance via Vanta - ensuring controls are implemented, not just documented. Respond to enterprise customer security questionnaires. Maintain and communicate the risk register to engineering and leadership. - Harden our infrastructure. Implement principle of least privilege across the stack - PostgreSQL roles for applications, Kubernetes RBAC refinement, ensuring applications only get the secrets they need. Drive network segmentation and zero-trust progress using Cilium network policies and Kyverno admission policies. Make production access read-only by default for developers. - Manage vulnerabilities systematically. Implement and operate our vulnerability scanning pipeline using Trivy, Renovate, and Falco. Own the vulnerability triage process - severity assessment, prioritization, tracking to resolution. Coordinate remediation with service owners and report on metrics and trends. ## Requirements - (Preferred) 5+ years in security engineering, platform engineering, or SRE with strong security focus. You've done this before and can hit the ground running with minimal hand-holding. - (Preferred) Hands-on Kubernetes security experience. You understand RBAC, network policies, and admission controllers. You've implemented security controls in production K8s environments. - Compliance framework experience. You've worked with at least one of ISO 27001, SOC 2, or PCI-DSS. You understand the difference between checkbox compliance and actually being secure. - Cloud security expertise. Strong understanding of cloud security principles. GCP experience preferred. You know how to secure cloud infrastructure. - Infrastructure-as-code practitioner. Experience with Terraform, ArgoCD, GitOps workflows. You believe infrastructure changes should go through code review. - Clear communicator. Ability to communicate security risk to non-technical stakeholders. You can translate technical vulnerabilities into business risk. ## Nice to have - (Bonus) CNCF security tooling experience. Cilium, Kyverno, Falco, or similar tools. Container security and supply chain security (SBOM, image signing). - (Bonus) Rust or Go experience. Our backend languages - helpful for understanding the systems you're securing and reviewing security-sensitive code. ## What we offer - Healthy, Catered Lunches - Enjoy fresh, healthy lunches every workday in our Auckland, Christchurch, London and San Francisco offices. With no meal prep needed, you can eat, connect, and refuel with your team. (And yes, snacks and drinks are always on hand.) - Healthy Body, Healthy Mind - We care about performing at our peak. Every team member gets a $1,500 annual wellness allowance (or local equivalent) on a Partly-branded card. Use it on things such gym memberships, rock climbing, physio, massage, GP visits, prescriptions; anything that you or your family, need! - Family Comes First - Primary caregivers receive 3 months of fully paid parental leave, plus a flexible return-to-work (four days on full
Sourced via wellfound · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Wellfound ↗