Security Platform Engineer

Remote: 
Full Remote
Contract: 
Work from: 

Offer summary

Qualifications:

Associate degree in Computer Science, Information Security, or related field, or equivalent self-directed study., Three years of relevant experience in cloud infrastructure, platform engineering, or security engineering., Experience with Kubernetes, Terraform, Git-based workflows, and scripting languages like Python or Bash., Knowledge of cloud security best practices and compliance frameworks such as SOC 2 and PCI DSS..

Key responsibilities:

  • Build and maintain security-focused telemetry and observability infrastructure.
  • Develop CI/CD pipeline integrations for vulnerability scanning and secure artifact handling.
  • Secure Kubernetes workloads and participate in on-call rotations for security incidents.
  • Collaborate with engineering teams to embed security into system architecture and operational practices.

Lumin Digital logo
Lumin Digital SME https://lumindigital.com/
51 - 200 Employees
See all jobs

Job description

The Security Platform Engineer is a member of the Security Engineering team focused on building and operating infrastructure to support the detection, analysis, and mitigation of security threats across Lumin Digital’s cloud-native platform. This role blends principles of site reliability engineering with a strong security mindset — designing specialized security systems that are resilient, observable, and defensible at scale.

Security Platform Engineers contribute to our platform’s integrity by designing, deploying, and maintaining security solutions, including telemetry pipelines, CI/CD workflows, and secure-by-default patterns for teams to build upon.


Essential Functions
Build and maintain infrastructure for security-focused telemetry and observability, including logging clusters, ingest pipelines, and alerting tools that enable effective detection and response capabilities.
Develop and maintain CI/CD pipeline integrations that automatically scan for vulnerabilities, enforce policy guardrails, and promote secure artifact handling across environments.
Use infrastructure-as-code tools (e.g., Terraform) to codify cloud environments and security services, enforcing consistency, auditability, and separation of duties.
Secure Kubernetes workloads by configuring RBAC, network policies, and deployment safeguards to reduce lateral movement and minimize blast radius.
Participate in an on-call rotation for security-related services, triaging incidents and contributing to post-incident reviews and durable improvements to runbooks and monitoring.
Implement and continuously improve index management, performance tuning, and role-based access controls for logging environments supporting security use cases.
Design and advocate for secure cross-account and multi-region infrastructure patterns, including the use of KMS, IAM roles, and VPC configurations to protect sensitive data in motion and at rest.
Collaborate with platform and product engineering teams to embed security into system architecture, deployment processes, and operational practices from the start.
Support internal security audits and incident response activities by maintaining logs, ensuring data fidelity, and automating evidence collection where feasible.


Position Specifications

Education:
Associate degree in Computer Science, Information Security, or related field; or equivalent self-directed study with demonstrated competency in security operations, cloud engineering, or platform reliability required.

Experience:
Three (3) years of relevant experience in cloud infrastructure, platform engineering, or security engineering.
Two (2) years of experience designing and operating cloud-native services (preferably AWS), including experience with CI/CD automation, monitoring, and infrastructure-as-code.
Experience with Kubernetes, Terraform, Git-based workflows, OpenSearch (or similar platforms), and scripting (e.g., Python or Bash) required.

Knowledge, Skills, and Abilities:
Working knowledge of cloud security best practices, including the requirements and guidance from security and compliance frameworks, such as SOC 2 Trust Services Criteria, PCI Data Security Standard, the CIS Benchmarks, and the AWS Well-Architected Framework.
Technical proficiency with cloud security principles, including IAM, encryption, network segmentation, and secure telemetry collection.
Familiarity with operational practices such as capacity planning, SLO development, and incident management.
Demonstrated ability to build and support complex distributed systems using automation and configuration management.
Calm under pressure, with the ability to triage incidents and collaborate across technical and non-technical stakeholders.
Strong communication and documentation skills; able to teach and influence secure engineering practices across teams.
Ability to work independently and remotely while maintaining high levels of productivity and collaboration.
Must be able to pass requisite background checks to access sensitive information.

Required profile

Experience

Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Time Management
  • Collaboration
  • Communication
  • Problem Solving

Security Engineer Related jobs