> Markdown version of [/jobs/ext/1137934-senior-platform-security-engineer](https://www.wearedevelopers.com/jobs/ext/1137934-senior-platform-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Platform Security Engineer - **Company:** ASUS Computer International - **Location:** Boston, MA, United States - **Experience:** Expert - **Salary:** $164,000.0 - $237,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Software System Penetration Testing, Cloud Computing, Cloud Computing Security, Cyber Security, Continuous Integration, Data Security, Identity and Access Management, Key Management, OAuth, Next.js, Secure Coding, Web Applications, Data Logging, Cloud Platform System, Amazon Virtual Private Cloud (VPC), Information Technology, Terraform, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b44022963e4f297d ## About the Role We are looking for an engineer with hands-on experience in application and cloud security, a proactive mindset for identifying and mitigating risk, and the ability to collaborate effectively across a multidisciplinary engineering team. The ideal candidate is a strong individual contributor who is eager to deepen their expertise in security architecture while working alongside experienced engineers across our Boston and Taipei offices., * Familiarity with cloud security on GCP or equivalent platforms, including IAM, VPC, IAP, Secret Manager, and Cloud Armor. * Solid understanding of OAuth, session security, and multi-tenant authorization patterns. * Experience with security scanning tools (SAST, DAST, dependency scanning) and integrating them into CI/CD workflows. * Ability to work confidently in a rapidly changing, fast-paced and results-oriented corporate environment where a high degree of flexibility is required * Excellent written and verbal communication skills in English Required Qualifications: Years of Education * Bachelor's degree or higher in computer science, information security, or a related field. Work Experience * 8+ years of experience in application or infrastructure security roles. Hands-on experience securing production web applications, preferably in Node.js/Next.js environments. Preferred Qualifications: * Experience with Terraform security hardening is a plus. * Strong verbal and written communication skills, including the ability to document security controls clearly. * Penetration testing experience is a plus. * Flexibility to attend virtual meetings with the Taiwan-based team at least three nights per week. ## Description * Contribute to application and infrastructure security across the platform, supporting production launch and long-term scaling. * Help harden authentication (OAuth/session handling) and API authorization patterns, including multi-tenant access control. * Configure and maintain IAM policies, service accounts, and least-privilege access controls across cloud infrastructure. * Secure data flows including file uploads, signed URLs, database access, and secrets management. * Set up and maintain security monitoring, logging, and alerting systems. * Build and maintain security tooling integrated into CI/CD pipelines, including SAST, DAST, and dependency scanning. * Perform regular security assessments, dependency audits, and penetration testing. * Support incident response and contribute to root cause analysis. * Collaborate with the engineering team on secure development practices and help document security controls and incident response procedures. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [GraphQL + Apollo + Next.js: A Lovely Trio](https://www.wearedevelopers.com/videos/311-graphql-apollo-next-js-a-lovely-trio) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)