Senior Platform Security Engineer / DevOps

New
F
FourthwallCloud security
Remote within Poland, Regular overlap with the European team; flexible hours with agreed overlap with the team.ContractSenior
Salary25,000–34,000 PLN net per month on B2B (invoice amount excluding VAT).
Apply NowOpens the employer's application page

Job Details

Languages
Clear English, written and spoken.
Required Skills
GCPKubernetesOAuthTerraform

Requirements

  • Have owned a production cloud platform at a senior level, including consequential changes, failures, and recovery.
  • Have performed hands-on security engineering end to end, such as platform hardening, vulnerability management, security design review, incident handling, or operating a VDP or bug bounty.
  • Have production experience with Terraform and GitOps; Flux should not be new.
  • Understand Kubernetes security, including RBAC, network policy, workload identity, and admission control.
  • Be able to explain how an operator or admission webhook works and name one you have operated.
  • Have identity experience with cloud IAM, OAuth, OIDC, service-to-service identity, and short-lived credentials.
  • Have enough application-security knowledge to assess and route VDP reports, including familiarity with the OWASP Top 10.
  • Have operated and tuned security checks in CI/CD, such as secret, dependency, image, or IaC scanning.
  • Use Codex or Claude heavily in daily work and take responsibility for the resulting changes.
  • Write automation in a general-purpose language or shell and review other engineers’ code.
  • Communicate clearly in spoken and written English.
  • Threat modelling or offensive-work experience, SRE practices such as SLOs, and SOC 2 or PCI DSS experience are useful but not required.

Responsibilities

  • Co-own the GCP/GKE platform, including networking, IAM, secrets, GitOps, CI/CD, observability, and PostgreSQL.
  • Build and maintain platform-security guardrails, policies, alerts, and automated security scans.
  • Triage, track, and verify infrastructure vulnerabilities and platform-security improvements.
  • Run the vulnerability disclosure programme, from intake and validation through routing, communication, tracking, and disclosure.
  • Route reports that appear to involve live exploitation to incident response.
  • Define recovery objectives and run restore, failover, and access exercises; maintain supporting runbooks and postmortems.
  • Improve on-call operations through automation and more actionable alerts.
  • Advise engineers on security risks in authentication, secrets, data storage, and external exposure.
View Full Description & ApplyYou'll be redirected to the employer's site
25,000–34,000 PLN net per month on B2B (invoice amount excluding VAT).
Apply Now