Senior Platform Security Engineer

ASUS Computer International
Boston, MA, United States
2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$164,000.0 - $237,000.0
Working hours
Shift work
Languages
English
Job source

Tech stack

Application Programming Interfaces (APIs) Software System Penetration Testing Cloud Computing Cloud Computing Security Cyber Security Continuous Integration Data Security Identity and Access Management Key Management OAuth Next.js Secure Coding
+9 more
Web Applications Data Logging Cloud Platform System Amazon Virtual Private Cloud (VPC) Information Technology Terraform Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

  • Contribute to application and infrastructure security across the platform, supporting production launch and long-term scaling.
  • Help harden authentication (OAuth/session handling) and API authorization patterns, including multi-tenant access control.
  • Configure and maintain IAM policies, service accounts, and least-privilege access controls across cloud infrastructure.
  • Secure data flows including file uploads, signed URLs, database access, and secrets management.
  • Set up and maintain security monitoring, logging, and alerting systems.
  • Build and maintain security tooling integrated into CI/CD pipelines, including SAST, DAST, and dependency scanning.
  • Perform regular security assessments, dependency audits, and penetration testing.
  • Support incident response and contribute to root cause analysis.
  • Collaborate with the engineering team on secure development practices and help document security controls and incident response procedures.

Requirements

We are looking for an engineer with hands-on experience in application and cloud security, a proactive mindset for identifying and mitigating risk, and the ability to collaborate effectively across a multidisciplinary engineering team. The ideal candidate is a strong individual contributor who is eager to deepen their expertise in security architecture while working alongside experienced engineers across our Boston and Taipei offices., * Familiarity with cloud security on GCP or equivalent platforms, including IAM, VPC, IAP, Secret Manager, and Cloud Armor.

  • Solid understanding of OAuth, session security, and multi-tenant authorization patterns.
  • Experience with security scanning tools (SAST, DAST, dependency scanning) and integrating them into CI/CD workflows.
  • Ability to work confidently in a rapidly changing, fast-paced and results-oriented corporate environment where a high degree of flexibility is required
  • Excellent written and verbal communication skills in English

Required Qualifications:

Years of Education

  • Bachelor’s degree or higher in computer science, information security, or a related field.

Work Experience

  • 8+ years of experience in application or infrastructure security roles. Hands-on experience securing production web applications, preferably in Node.js/Next.js environments.

Preferred Qualifications:

  • Experience with Terraform security hardening is a plus.
  • Strong verbal and written communication skills, including the ability to document security controls clearly.
  • Penetration testing experience is a plus.
  • Flexibility to attend virtual meetings with the Taiwan-based team at least three nights per week.

Benefits & conditions

Pulled from the full job description

  • AD&D insurance
  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Life insurance, * Typically working in an office environment
  • This is an IN-OFFICE position in Boston, MA
  • Requires sitting, operating a computer keyboard, telephone and other office equipment for extended periods of time
  • Travel requirements 10% travel, domestic/international

$164,000 - $237,000 annually is the estimated pay range for this role working in Boston, Massachusetts office. The final amount will be determined based on qualifications & experience of the candidate relative to the role. Our comprehensive employee benefits include bonuses, medical, dental, vision, life insurance, AD&D insurance, Paid Time Off, EAP, & 401(k).

About the company

About the ASUS Robotics & AI Center The ASUS Robotics and AI Center is a world-class research and development laboratory that was established with the mission of developing ambitious technologies that will define the future. Our multidisciplinary team of the brightest engineers and scientists is dedicated to creating software-focused solutions that will solve some of the most enduring challenges in the fields of robotics and artificial intelligence. More About ASUS ASUS is a global technology leader that provides the world’s most innovative and intuitive devices, components, and solutions to deliver incredible experiences that enhance the lives of people everywhere. With its team of 5,000 in-house R&D experts, the company is world-renowned for continuously reimagining today’s technologies. Consistently ranked as one of Fortune’s World’s Most Admired Companies, ASUS is also committed to sustaining an incredible future. The goal is to create a net-zero enterprise that helps drive the shift towards a circular economy, with a responsible supply chain creating shared value for every one of us.

You must create an Indeed account before continuing to the company website to apply

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:30 min

Scaffolding pages and routing single-page applications with Next.js

Josh Goldberg · JS Congress

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

4:58 min

Scaling security teams through developer advocates

Tanya Janca · World Congress 2021

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all