← Back to results

Staff Platform Security Engineer (Security)

Join Phantom as a Staff Platform Security Engineer to enhance security across AWS and Kubernetes environments in a fully remote role.

Location
United States
Compensation
$200k–$250k/yr
Level
staff
Type
full time · Remote

Posted by employer 2 days ago

First seen on Joblaze 1 day ago

Last verified on the company career page 1 day ago

Apply at Phantom → Save job Scanned from phantom.app

What you'll build

  • Own and improve security across AWS environment
  • Secure production Kubernetes environments
  • Design least-privilege access models
  • Lead security design for new infrastructure
  • Build reusable security controls

Must have

  • 7+ years of experience in platform security
  • Deep experience securing production AWS environments
  • Deep experience securing Kubernetes in production
  • Experience designing or securing mission-critical systems
  • Experience securing CI/CD and software supply chains
  • Ability to write production-quality code

Nice to have

  • Experience with AWS Nitro Enclaves
  • Experience securing financial transaction systems
  • Familiarity with key-management infrastructure
  • Experience operating multi-region Kubernetes environments
  • Familiarity with service meshes
  • Experience using cloud-security platforms

Practical constraints

  • Candidates must be based in the US and Canada

Role intensity

70% hands-on coding

AI in the day-to-day

We're building an AI-native security team that aggressively uses AI to expand the speed, depth, and reach of our work.

Requirements

Experience
7+ years
Visa
No sponsorship (stated in posting)

Benefits

401k Match Unlimited PTO Equity/Stock Options Remote Work Wellness Benefit Health Insurance Meal Benefit

Joblaze summary

The Staff Platform Security Engineer at Phantom is responsible for enhancing security across AWS and Kubernetes environments, focusing on protecting critical infrastructure and sensitive data. This role requires extensive experience in cloud and platform security, particularly with AWS and Kubernetes, along with strong coding skills for automation. Ideal candidates are seasoned security engineers who can navigate complex security challenges and collaborate effectively with engineering teams. Phantom's commitment to building an AI-native security team adds a unique dimension to this role.

Joblaze insights

  • Listed yesterday — first seen on Joblaze September 17, 2026. Last confirmed on Phantom's careers page September 17, 2026.
  • Salary band is above the typical range for Security roles (median ~$168,500).
  • Starts above 44% of 36 comparable staff security roles in United States that list Python we track (median $200,000 across 19 companies). See Python salary trends
  • Python appears in 49.4% of 87 comparable staff security roles in United States; Pulumi appears in 3.4% of 87 comparable staff security roles in United States.

Quick facts

Is the Staff Platform Security Engineer (Security) role remote?
Yes — Phantom lists this as a fully remote position.
What's the salary range?
Phantom lists $200,000–$250,000 for this role.
How much experience is required?
At least 7 years of relevant experience for this Staff Platform Security Engineer (Security) role.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, Go, Kubernetes, Pulumi, Python, Rust.
What seniority level is this role?
Phantom targets staff-level candidates for this position.
Is this full-time or contract?
Full-time for this Staff Platform Security Engineer (Security) role at Phantom.

From the original posting

Platform security is foundational to protecting Phantom and the systems our users rely on. We’re hiring a Senior Platform Security Engineer to own and improve security across our AWS and Kubernetes environments. You’ll work directly with infrastructure and engineering teams to secure the control planes, identities, workloads, and deployment systems behind our most critical products.

We’re building an AI-native security team that aggressively uses AI to expand the speed, depth, and reach of our work. We’re looking for a strong security engineer with high agency who can identify the risks that matter, build practical controls, and own problems through verified remediation. This is a hands-on role for someone who is comfortable working in production systems, writing code and infrastructure, responding to incidents, and making security improvements without slowing down the teams building on the platform.

This role is fully remote; however, we’re only open to candidates based in the US and Canada.

Responsibilities

  • AWS Security: Own and improve security across Phantom’s multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails.

  • Kubernetes Security: Secure production Kubernetes environments running on Amazon EKS, including cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation.

  • Identity and Access: Design least-privilege access models for engineers, services, and automation. Build scoped, auditable, and time-bound access paths for sensitive production systems.

  • Mission-Critical Systems: Protect the infrastructure supporting products and services that handle sensitive data and high-value operations.

  • Cloud Security Architecture: Lead security design for new infrastructure, platform services, and major architectural changes.

  • Infrastructure and Policy as Code: Build reusable security controls using tools such as Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation.

  • CI/CD and Supply Chain Security: Harden build, deployment, and release systems, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and access to production environments.

  • Security Automation: Build tools that identify and remediate cloud and Kubernetes risks at scale. Apply AI-assisted workflows where they materially improve analysis, coverage, or response speed.

  • Cross-Functional Leadership: Partner closely with Infrastructure, SRE, Developer Experience, and product engineering teams. Establish practical platform-security standards and help teams adopt them.

Qualifications

  • 7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering role.

  • Deep, hands-on experience securing production AWS environments. You understand IAM and resource policies, workload identity, network security, secrets management, logging, organization-level controls, and the ways these systems fail in practice.

  • Deep experience securing Kubernetes in production, preferably Amazon EKS, including RBAC, workload identity, admission policy, network policy, pod security, secrets, and cluster hardening.

  • Experience designing or securing mission-critical systems where compromise, excessive privilege, or loss of availability could have significant customer or business impact.

  • Strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction across both human and machine access.

  • Experience securing CI/CD and software supply chains, including GitHub Actions or similar systems, build runners, workload federation, artifacts, and production deployment paths.

  • Experience writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar tools.

  • Ability to write production-quality code or automation in a language such as TypeScript, Python, Go, or Rust.

  • High agency and ownership. You can take an ambiguous platform-security problem from initial investigation through implementation and verified remediation.

  • Clear communication and a strong track record of partnering with infrastructure and engineering teams while maintaining a high security bar.

Nice To Haves

  • Experience with AWS Nitro Enclaves or other trusted execution environments, including attestation, isolation boundaries, secure key handling, and operational lifecycle management.

  • Experience securing financial, payments, wallet, custody, or other high-value transaction systems.

  • Familiarity with key-management infrastructure, AWS KMS, CloudHSM, cryptographic signing systems, or secrets-management platforms.

  • Experience operating or securing multi-region Kubernetes and AWS environments at significant scale.

  • Familiarity with service meshes and cloud-native networking technologies such as Istio, PrivateLink, Transit Gateway, or eBPF-based controls.

  • Experience with GitHub OIDC, Argo CD, Helm, Crossplane, or Kubernetes-based infrastructure delivery.

  • Experience using cloud-security and observability platforms such as Wiz, Datadog, GuardDuty, Security Hub, or CloudTrail.

  • Experience building policy-as-code, automated remediation, or security tooling used by a large engineering organization.

  • Familiarity with blockchain infrastructure or self-custodial wallet architecture.

Why Work with Us

Phantom is built by a team of experienced product and engineering leaders working to make crypto-powered finance safer and easier to use. Our platform supports products used by tens of millions of people, making infrastructure security both technically challenging and directly consequential.

This role offers the opportunity to:

  • Secure AWS and Kubernetes systems supporting products used by millions of people.

  • Work on high-impact problems spanning cloud identity, production access, workload isolation, software supply chains, and mission-critical infrastructure.

  • Build controls directly in the platform rather than operating as an advisory or review-only security function.

  • Influence architecture early and own improvements through implementation and production verification.

  • Help shape an AI-native security team with a strong engineering and automation culture.

Benefits

  • Competitive salary and equity

  • Eligibility to participate in the company’s performance bonus program

  • Comprehensive medical, dental, and vision insurance with 100% coverage

  • Stipend for your ideal remote setup

  • Flexible hours and a supportive remote environment

  • Unlimited vacation—take time when you need it

  • 401(k) retirement plan

  • Monthly wellness benefit

  • Weekly meal benefit

  • Global off-sites

The target base salary for this role will range between $200,000 to $250,000 with the addition of equity and benefits. This is determined by a few factors including your skillset, prior relevant experience, quality of interviews and market factors (such as location) at the point in time of offer.

Standard company text repeated across Phantom's postings is omitted here.

Similar positions

Profound
Member of Technical Staff, Security
Profound · New York, New York
Decagon
Horizon3.ai