Staff Security Platform Engineer (GCP)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Staff Security Platform Engineer (GCP/Kubernetes): Designing and implementing a secure-by-default cloud infrastructure for an AI-driven conversational commerce platform with an accent on Kubernetes hardening, zero-trust networking, and automated compliance. Focus on building scalable security guardrails, enhancing threat detection and response, and maturing identity management for enterprise-grade security.
Location: Hybrid in Buenos Aires, Argentina
Company
is building a unified AI agent platform to transform conversational commerce for ecommerce brands.
What you will do
- Own cloud and Kubernetes security, including IAM, RBAC, and GKE hardening across global clusters.
- Design secure-by-default platforms using policy-as-code (OPA, Kyverno) to provide guardrails for engineering teams.
- Harden CI/CD and IaC pipelines, specifically GitHub Actions, ArgoCD, and Terraform workflows.
- Implement a decoupled secrets management architecture and strengthen zero-trust networking.
- Build security-focused logging, runtime detection, and evolve the SIEM to improve signal-to-noise ratios.
- Manage compliance for SOC 2 Type II, ISO 27001, and GDPR/PII data protection.
Requirements
- 5+ years of experience in infrastructure, cloud, or security engineering in high-growth SaaS.
- Deep expertise in GCP and Kubernetes (GKE, workload identity, network policies).
- Strong networking fundamentals, including VPC design and firewall architecture.
- Hands-on experience with CI/CD hardening (GitHub Actions, ArgoCD, Terraform).
- Proficiency in Auth standards (OAuth 2.0, OIDC, SAML) and Policy-as-code.
- Experience with compliance frameworks (SOC 2, ISO 27001, GDPR).
Nice to have
- Scripting fluency in Python, Go, or Bash for automation and incident response.
Culture & Benefits
- Access to premium AI tools (ChatGPT, Claude, Granola) and an annual L&D budget.
- Collaborative culture with an AI-focused knowledge-sharing environment via the #powerup Slack channel.
- Opportunity to work with a high-scale stack including multi-TB Postgres, Kafka, and Apache Flink.
- Inclusive work environment committed to diversity and inclusion.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →