> Markdown version of [/jobs/ext/1181399-platform-security-engineer](https://www.wearedevelopers.com/jobs/ext/1181399-platform-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Platform Security Engineer - **Company:** Future plc - **Location:** Austin, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Code Review, Continuous Integration, Python (Programming Language), Software Engineering, TypeScript, Cloud Platform System, Large Language Models, Software Security, Cloudformation, Build Management, Kubernetes, Github Enterprise, Hashicorp, Machine Learning Operations, Virtual Agents, Terraform, Security Orchestration, Automation & Response, Artifactory, Golang, Microservices - **Published:** July 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3c56a013908b6c7c ## About the Role * 5+ years in product/application security or security-focused software engineering * Proficiency in at least one general-purpose language (e.g., Python, Go, TypeScript) and a real build-vs-buy mindset * Hands-on experience securing modern cloud environments (AWS) and containerized/microservice architectures (Kubernetes) * Working knowledge of SDLC security: threat modeling, code review, and CI/CD pipeline security * Ability to translate security requirements into developer-friendly workflows and influence engineering teams you don't own, * Experience securing AI/ML systems, LLM applications, or agentic AI * IaC security (Terraform, CDK, CloudFormation) and security automation * Supply-chain security depth (SLSA, sigstore/Cosign, dependency firewalls) * Bug bounty or offensive-security experience ## Description We are hiring a Platform Security Engineer to own the security of how we build and ship software: the product and its AI systems, the cloud it runs on, and the supply chain and CI/CD that get it there. This is a hands-on engineering role, not an advisory one. You'll work alongside our platform engineer and partner directly with product and platform engineering to design security in early and build the guardrails that make secure the default. Security is core to the product and the company, and we are engineering-led: we buy managed protection where it makes sense and spend headcount on engineers who automate and extend the stack. You'll be one of the first hires on this team, owning a domain rather than a slice of someone else's., * Run security design reviews, threat models, and code reviews for new features and AI/agentic systems, designing out vulnerability classes rather than chasing them one at a time * Help scope and act on penetration tests against the product * Design and build security controls for our AWS and Kubernetes (EKS) environment, including IaC guardrails (e.g., Terraform), secrets management (e.g., HashiCorp Vault), and tooling to detect and prevent cloud misconfiguration * Harden the path from commit to production, including source and pipeline security (e.g., GitHub Enterprise, Actions and self-hosted runners) and the artifact and build chain * Build security tooling and workflows that integrate into the IDE and pipeline so engineers make secure decisions quickly * Stand up and run dependency and SCA controls and a dependency firewall (e.g., Socket, Snyk) and artifact management (e.g., JFrog Artifactory) * Drive SBOM, code signing, and admission control (e.g., Cosign, Kyverno) * Drive secure-development practices and AI-assisted-development governance across engineering * Participate in the shared incident-response and on-call rotation as an incident handler, with leadership-level incident command for major incidents ## Related Videos - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Securing Secrets in the GitOps era](https://www.wearedevelopers.com/videos/546-securing-secrets-in-the-gitops-era) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Terraform for Developers](https://www.wearedevelopers.com/videos/3-terraform-for-developers) - [Retooling and refactoring - an investment in people.](https://www.wearedevelopers.com/videos/371-retooling-and-refactoring-an-investment-in-people) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix)