Platform Security Architect

24 ore fa

Udine, Friuli Venezia Giulia, Italia Deel Tempo pieno

Overview

As Deel's platform security lead, you shape the security architecture across applications, services, and cloud environments with a focus on AWS. You drive secure design patterns, guardrails, and baseline configurations that teams default to. You manage security tooling, CI/CD integration, and threat modeling to reduce exploitable risk. You collaborate with Privacy/Compliance to meet regulatory standards and scale a security program across engineering. This role offers impact at a global scale within a fast-growing SaaS company.

Retribuzione / Benefits

  • Stock grant opportunities
  • Flexible working office membership (IWG)
  • Additional perks based on country
  • Inclusive workplace with disability accommodations
  • Competitive salary
  • Global remote-friendly role

Responsabilità

  • Define and own the platform security architecture strategy for applications, services, and cloud (AWS)
  • Operate security tooling program (Wiz, Aikido) and integrate findings with engineering workflows
  • Design identity and access management and multi-tenant/just-in-time access controls
  • Embed security into SDLC and CI/CD with guardrails for code and IaC
  • Secure containers/Kubernetes: image hardening, runtime security, pod security, network policies
  • Own software supply chain security and SBOMs from npm installs to runtime
  • Lead threat modeling and drive engineering remediations from findings
  • Manage vulnerability management and incident response across application and cloud layers
  • Partner with Privacy/Compliance to meet SOC 2 II, ISO 27001, PCI DSS, GDPR
  • Build Security Champions program and secure coding enablement across teams
  • Influence engineering and cloud strategy; leverage AI to improve security posture
  • Review high-risk designs and vendor decisions; align security with leadership goals
  • Apply AI to security workflows for triage and remediation

Requisiti fondamentali

  • 3+ years in cybersecurity with cloud and application security expertise
  • Deep AWS security knowledge: IAM, network controls, logging/monitoring, data protection
  • Strong application security experience: OWASP Top 10, API Security Top 10, auth design
  • Hands-on experience with Wiz/Orca/Prisma Cloud and Aikido/Snyk/Semgrep/GitHub Advanced Security
  • CI/CD security gates for code and IaC
  • Container/Kubernetes security: image hardening, runtime security, RBAC
  • Threat modeling experience (STRIDE, attack trees)
  • Production code reading/writing in TypeScript/Node.js, Python, Go, or Java
  • Secrets management and encryption patterns (HashiCorp Vault, AWS Secrets Manager)
  • Vulnerability management or bug bounty/pentest program leadership
  • Knowledge of SOC 2 II, ISO 27001, PCI DSS, GDPR
  • Clear technical guidance for engineers and risk-based exec briefings
  • Excellent English communication
  • excellent communication
  • cross-functional collaboration
  • leadership and sponsorship of security initiatives
  • Wiz (or Orca, Prisma Cloud)
  • Aikido (or Snyk, Semgrep, GitHub Advanced Security)
  • CI/CD security integration