Senior Platform Security Engineer / DevOps
New
F
FourthwallCloud security
Remote within Poland, Regular overlap with the European team; flexible hours with agreed overlap with the team.ContractSenior
Salary25,000–34,000 PLN net per month on B2B (invoice amount excluding VAT).
Apply NowOpens the employer's application page
Job Details
- Languages
- Clear English, written and spoken.
- Required Skills
- GCPKubernetesOAuthTerraform
Requirements
- Have owned a production cloud platform at a senior level, including consequential changes, failures, and recovery.
- Have performed hands-on security engineering end to end, such as platform hardening, vulnerability management, security design review, incident handling, or operating a VDP or bug bounty.
- Have production experience with Terraform and GitOps; Flux should not be new.
- Understand Kubernetes security, including RBAC, network policy, workload identity, and admission control.
- Be able to explain how an operator or admission webhook works and name one you have operated.
- Have identity experience with cloud IAM, OAuth, OIDC, service-to-service identity, and short-lived credentials.
- Have enough application-security knowledge to assess and route VDP reports, including familiarity with the OWASP Top 10.
- Have operated and tuned security checks in CI/CD, such as secret, dependency, image, or IaC scanning.
- Use Codex or Claude heavily in daily work and take responsibility for the resulting changes.
- Write automation in a general-purpose language or shell and review other engineers’ code.
- Communicate clearly in spoken and written English.
- Threat modelling or offensive-work experience, SRE practices such as SLOs, and SOC 2 or PCI DSS experience are useful but not required.
Responsibilities
- Co-own the GCP/GKE platform, including networking, IAM, secrets, GitOps, CI/CD, observability, and PostgreSQL.
- Build and maintain platform-security guardrails, policies, alerts, and automated security scans.
- Triage, track, and verify infrastructure vulnerabilities and platform-security improvements.
- Run the vulnerability disclosure programme, from intake and validation through routing, communication, tracking, and disclosure.
- Route reports that appear to involve live exploitation to incident response.
- Define recovery objectives and run restore, failover, and access exercises; maintain supporting runbooks and postmortems.
- Improve on-call operations through automation and more actionable alerts.
- Advise engineers on security risks in authentication, secrets, data storage, and external exposure.
View Full Description & ApplyYou'll be redirected to the employer's site