Platform Security Engineer
Upload My Resume
Drop here or click to browse · PDF, DOCX, DOC, RTF, TXT
Requirements
• (Preferred) 5+ years in security engineering, platform engineering, or SRE with strong security focus. You've done this before and can hit the ground running with minimal hand-holding. • (Preferred) Hands-on Kubernetes security experience. You understand RBAC, network policies, and admission controllers. You've implemented security controls in production K8s environments. • Compliance framework experience. You've worked with at least one of ISO 27001, SOC 2, or PCI-DSS. You understand the difference between checkbox compliance and actually being secure. • Cloud security expertise. Strong understanding of cloud security principles. GCP experience preferred. You know how to secure cloud infrastructure. • Infrastructure-as-code practitioner. Experience with Terraform, ArgoCD, GitOps workflows. You believe infrastructure changes should go through code review. • Clear communicator. Ability to communicate security risk to non-technical stakeholders. You can translate technical vulnerabilities into business risk. • (Bonus) CNCF security tooling experience. Cilium, Kyverno, Falco, or similar tools. Container security and supply chain security (SBOM, image signing). • (Bonus) Rust or Go experience. Our backend languages - helpful for understanding the systems you're securing and reviewing security-sensitive code. • Please note: if you don't have all the skills/experience listed above but believe you could be outstanding in this role, please still consider applying. Many folks, especially those from underrepresented or marginalised groups, often count themselves out. Please allow us to learn more about you and why you're exceptional!
Responsibilities
• Own Partly's security posture and compliance. Prepare for and pass security audits such as ISO 27001 and SOC 2 certifications through Vanta platform maintenance. Respond to enterprise customer questionnas, maintain the risk register communicating it to engineering and leadership teams. • Own Partly's infrastructure hardening by implementing principle of least privilege across stack components like PostgreSQL roles for applications and Kubernetes RBAC refinement ensuring application only gets necessary secrets. Maintain continuous compliance via Vanta platform maintenance, responding to security questionnaires from enterprise customers. • Participate in on-call rotation alongside the SRE team during "Season Openers". Own security incident response planning and testing including leading post-incident reviews for both availability incidents as well as those related to security. Build event monitoring and alerting systems specifically tailored towards identifying potential threats or breaches in real time. • Work closely with the SRE team, building processes from scratch while ensuring platform reliability is maintained alongside infrastructure hardening efforts for Partly's digital solutions globally integrated across hundreds of companies worldwide.
Benefits
• High trust, low process and no bureaucracy. We hire exceptional people whose judgment we trust. This means we proactively remove any process or rules that slow us down (for example, our expense policy is simply the “red face test”). • Competitive base salary + equity. We offer competitive salaries and generous equity options for all full-time employees, ensuring everyone shares in the financial upside when we win. • Flexible working hours. Choose when to work based on what time you’re most effective (no mandatory or set hours). We combine flexibility with an office-first approach (in cities where we have critical mass, i.e. London, Christchurch, Auckland). **** • Focus Days. Two days per week, with zero meetings, dedicated solely to uninterrupted deep work • Take time when you need it. We don’t ask questions or care if people have a negative leave balance. We work extremely hard and trust our team to take the time they need to recharge. • Offices in Christchurch CBD and on Auckland’s Karangahape Road. We invest heavily in our offices (standing desks, healthy snacks, quality coffee, drinks on tap) to ensure they’re places people are excited by, where they build relationships and get their best work done.