Phantom·Remote·5 дн назад
Staff Platform Security Engineer (Security)
200 000 – 250 000 $ в год
на 10% выше медианы рынка
≈ 1,4 млн–1,7 млн ₽
🌍 УдалённоSeniorПолная занятость🌐 Глобал
Вилки нет, про деньги придётся договариваться с нуля.
Вакансия на английскомПереведёт заголовок и описание вакансии на русский
Наша компания
Phantom is on a mission to connect the world to the freedom of open markets. Tens of millions of people all over the world use Phantom to access global markets that never close, including perpetuals, prediction markets, tokenized assets, stablecoins and memes. Phantom users are able to discover the markets that matter and the cultural moments that shape them, building conviction through real-time data and the verified performance of top traders. With self-custody and access to open networks at its core, Phantom lets them control their financial moves in the same app they use to safely store or
О роли
We are around 180 people, fully remote, backed by a $150M Series C investment from a16z, Sequoia Capital and Paradigm. Platform security is foundational to protecting Phantom and the systems our users rely on. We’re hiring a Senior Platform Security Engineer to own and improve security across our AWS and Kubernetes environments. You’ll work directly with infrastructure and engineering teams to sec
Чем предстоит заниматься
AWS Security: Own and improve security across Phantom’s multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails
Kubernetes Security: Secure production Kubernetes environments running on Amazon EKS, including cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation
Identity and Access: Design least-privilege access models for engineers, services, and automation. Build scoped, auditable, and time-bound access paths for sensitive production systems
Mission-Critical Systems: Protect the infrastructure supporting products and services that handle sensitive data and high-value operations
Cloud Security Architecture: Lead security design for new infrastructure, platform services, and major architectural changes
Infrastructure and Policy as Code: Build reusable security controls using tools such as Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation
CI/CD and Supply Chain Security: Harden build, deployment, and release systems, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and access to production environments
Security Automation: Build tools that identify and remediate cloud and Kubernetes risks at scale. Apply AI-assisted workflows where they materially improve analysis, coverage, or response speed
Cross-Functional Leadership: Partner closely with Infrastructure, SRE, Developer Experience, and product engineering teams. Establish practical platform-security standards and help teams adopt them
Наши требования
7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering role
Deep, hands-on experience securing production AWS environments. You understand IAM and resource policies, workload identity, network security, secrets management, logging, organization-level controls, and the ways these systems fail in practice
Deep experience securing Kubernetes in production, preferably Amazon EKS, including RBAC, workload identity, admission policy, network policy, pod security, secrets, and cluster hardening
Experience designing or securing mission-critical systems where compromise, excessive privilege, or loss of availability could have significant customer or business impact
Strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction across both human and machine access
Experience securing CI/CD and software supply chains, including GitHub Actions or similar systems, build runners, workload federation, artifacts, and production deployment paths
Experience writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar tools
Ability to write production-quality code or automation in a language such as TypeScript, Python, Go, or Rust
High agency and ownership. You can take an ambiguous platform-security problem from initial investigation through implementation and verified remediation
Clear communication and a strong track record of partnering with infrastructure and engineering teams while maintaining a high security bar
Experience with AWS Nitro Enclaves or other trusted execution environments, including attestation, isolation boundaries, secure key handling, and operational lifecycle management
Experience securing financial, payments, wallet, custody, or other high-value transaction systems
Familiarity with key-management infrastructure, AWS KMS, CloudHSM, cryptographic signing systems, or secrets-management platforms
Experience operating or securing multi-region Kubernetes and AWS environments at significant scale
Familiarity with service meshes and cloud-native networking technologies such as Istio, PrivateLink, Transit Gateway, or eBPF-based controls
Experience with GitHub OIDC, Argo CD, Helm, Crossplane, or Kubernetes-based infrastructure delivery
Experience using cloud-security and observability platforms such as Wiz, Datadog, GuardDuty, Security Hub, or CloudTrail
Experience building policy-as-code, automated remediation, or security tooling used by a large engineering organization
Familiarity with blockchain infrastructure or self-custodial wallet architecture
WHY WORK WITH US
Phantom is built by a team of experienced product and engineering leaders working to make crypto-powered finance safer and easier to use. Our platform supports products used by tens of millions of people, making infrastructure security both technically challenging and directly consequential
Мы предлагаем
Competitive salary and equity
Eligibility to participate in the company’s performance bonus program
Comprehensive medical, dental, and vision insurance with 100% coverage
Stipend for your ideal remote setup
Flexible hours and a supportive remote environment
Unlimited vacation—take time when you need it
401(k) retirement plan
Monthly wellness benefit
Weekly meal benefit
Global off-sites
The target base salary for this role will range between $200,000 to $250,000 with the addition of equity and benefits. This is determined by a few factors including your skillset, prior relevant experience, quality of interviews and market factors (such as location) at the point in time of offer
We strongly encourage candidates of all backgrounds to apply. We believe that our work is stronger with a variety of perspectives, and we’re eager to further diversify our company. If you have a background that you feel would make an impact at Phantom, please consider applying. We’re committed to building an inclusive, supportive place for you to do the best work of your career
By submitting your resume and application materials, you acknowledge and agree that Phantom Technologies, Inc. ("Phantom") collects and processes your personal information (including application materials, interview records, and related data) to evaluate your candidacy. Phantom may use AI-powered tools and third-party service providers for transcription, note-taking, scheduling, and other administrative tasks. Phantom does not sell your information and your materials will be handled securely and in accordance with applicable data protection laws
Secure AWS and Kubernetes systems supporting products used by millions of people
Work on high-impact problems spanning cloud identity, production access, workload isolation, software supply chains, and mission-critical infrastructure
Build controls directly in the platform rather than operating as an advisory or review-only security function
Influence architecture early and own improvements through implementation and production verification
Help shape an AI-native security team with a strong engineering and automation culture