Phantom logo
    P

    Staff Platform Security Engineer (Security)

    Phantom
    Remote
    Remote
    Senior
    Full Time
    💰$200,000 - $250,000
    remotesecurityAWSKubernetescloud_securityplatform_securitysenior

    Requirements

    • •7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering role
    • •Deep, hands-on experience securing production AWS environments including IAM, resource policies, workload identity, network security, secrets management, logging, and organization-level controls
    • •Deep experience securing Kubernetes in production, preferably Amazon EKS, including RBAC, workload identity, admission policy, network policy, pod security, secrets, and cluster hardening
    • •Experience designing or securing mission-critical systems with significant customer or business impact
    • •Strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction across human and machine access
    • •Experience securing CI/CD and software supply chains including GitHub Actions or similar systems
    • •Experience writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar tools
    • •Ability to write production-quality code or automation in TypeScript, Python, Go, or Rust
    • •High agency and ownership from investigation through implementation and verified remediation
    • •Clear communication and strong track record of partnering with infrastructure and engineering teams while maintaining a high security bar

    What You'll Do

    • •Own and improve security across Phantom’s multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails
    • •Secure production Kubernetes environments running on Amazon EKS, including cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation
    • •Design least-privilege access models for engineers, services, and automation
    • •Protect the infrastructure supporting products and services that handle sensitive data and high-value operations
    • •Lead security design for new infrastructure, platform services, and major architectural changes
    • •Build reusable security controls using tools such as Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation
    • •Harden build, deployment, and release systems, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and access to production environments
    • •Build tools that identify and remediate cloud and Kubernetes risks at scale
    • •Apply AI-assisted workflows where they materially improve analysis, coverage, or response speed
    • •Partner closely with Infrastructure, SRE, Developer Experience, and product engineering teams
    • •Establish practical platform-security standards and help teams adopt them

    Nice to Have

    • •Experience with AWS Nitro Enclaves or other trusted execution environments including attestation, isolation boundaries, secure key handling, and operational lifecycle management
    • •Experience securing financial, payments, wallet, custody, or other high-value transaction systems
    • •Familiarity with key-management infrastructure, AWS KMS, CloudHSM, cryptographic signing systems, or secrets-management platforms
    • •Experience operating or securing multi-region Kubernetes and AWS environments at significant scale
    • •Familiarity with service meshes and cloud-native networking technologies such as Istio, PrivateLink, Transit Gateway, or eBPF-based controls
    • •Experience with GitHub OIDC, Argo CD, Helm, Crossplane, or Kubernetes-based infrastructure delivery
    • •Experience using cloud-security and observability platforms such as Wiz, Datadog, GuardDuty, Security Hub, or CloudTrail
    • •Experience building policy-as-code, automated remediation, or security tooling used by a large engineering organization
    • •Familiarity with blockchain infrastructure or self-custodial wallet architecture

    Benefits

    • •Competitive salary and equity
    • •Eligibility to participate in the company’s performance bonus program
    • •Comprehensive medical, dental, and vision insurance with 100% coverage
    • •Stipend for your ideal remote setup
    • •Flexible hours and a supportive remote environment
    • •Unlimited vacation—take time when you need it
    • •401(k) retirement plan
    • •Monthly wellness benefit
    • •Weekly meal benefit
    • •Global off-sites

    About Phantom

    Phantom is a crypto wallet that facilitates the buying, trading, and storing of cryptocurrencies, including NFTs and tokens.

    San Francisco, CA
    100 - 250
    Blockchain & Cryptocurrency