> Markdown version of [/jobs/ext/2640282-product-security-engineer-platform](https://www.wearedevelopers.com/jobs/ext/2640282-product-security-engineer-platform). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Product Security Engineer (Platform) - **Company:** Profile Plastics, Inc. - **Location:** United States - **Experience:** Expert - **Salary:** $192,000.0 - $230,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Command-Line Interface, Cloud Computing, Code Review, Computer Networks, Continuous Integration, Identity and Access Management, Open Web Application Security, Role-Based Access Control, Google Cloud, Cloud Platform System, Software Security, Kubernetes, Deployment Automation, Terraform, Devsecops - **Published:** August 28, 2026 - **Apply:** https://www.dice.com/job-detail/abb0fb07-53c5-4030-ae0d-7275bd55dd0c ## About the Role 5-8 years running or securing cloud infrastructure, ideally having built and operated production platforms on Google Cloud Platform or AWS before moving into security. Deep, hands-on Google Cloud Platform knowledge, including its security services, plus a good working knowledge of AWS; equivalent AWS IAM depth is a bonus. Strong grasp of Google Cloud Platform IAM: resource hierarchy (organization, folders, projects), IAM roles and conditions, service accounts and workload identity federation, organization policy constraints, and least privilege design. Practical Kubernetes and container experience, primarily GKE: cluster hardening (private clusters, Autopilot), RBAC, admission control, workload identity, network policy, and secure container images. EKS experience is also welcome. Comfort with infrastructure as code (for example Terraform) and automated deployment: CI/CD pipelines and GitOps. Solid DevSecOps practice: threat modeling, early shift-left testing, and continuous monitoring, plus the judgment to turn that into concrete infrastructure changes. Confidence using AI coding agents (for example Claude Code) day to day, including writing the guidance and prompts that keep their output reliable at scale. A critical eye for AI-generated infrastructure output: able to spot invented resources, unsafe defaults, and overly broad IAM permissions before anything ships. Comfort working consultatively: influencing and negotiating changes with teams who own and run the infrastructure, rather than owning it yourself. Nice to have: application security knowledge (for example code review, OWASP Top 10), or experience with Snyk's products or similar security testing tools. ## Description Snyk's Product Security team works consultatively with the engineering teams that build and run our cloud platform: we identify the security requirements, agree together on what needs to change, and the owning teams implement it. As a Senior Product Security Engineer (Platform), you'll pair deep Google Cloud Platform and AWS infrastructure experience with AI coding agents to turn threat models into concrete Terraform, Kubernetes, and pipeline fixes, then work directly with platform teams to get those fixes merged. The goal is simple to state and hard to do well: make the secure option the easy option for the engineers building Snyk's platform. About the Team You'll join Snyk's Product Security team, which operates as an advisor rather than an owner: the cloud infrastructure teams retain ownership and operation of their systems, and Product Security's job is to find what needs to change and make that change easy to ship. The team sits close to Snyk's platform and infrastructure organization and is increasingly built around AI agents doing real infrastructure work, not just reviewing someone else's. What You'll Do Threat model Snyk's cloud infrastructure across Google Cloud Platform and AWS to identify the security requirements platform teams need to meet, then negotiate the resulting changes directly with the teams that own the systems. Use AI coding agents (for example Claude Code) to draft the Terraform, Kubernetes, and pipeline changes that fix identified security gaps, and raise them for the owning team to review and merge. Run agent-driven fixes at scale across many repositories, scoping every change so the owning platform team can review and merge it with confidence. Write and maintain the guidance AI agents rely on (skills, prompts, instruction files, security baselines) so agent output consistently matches Snyk's standards. Connect agents to live cloud, CSPM, and ticketing data through MCP servers, command-line tools, and provider APIs so their fixes are grounded in the real environment. Review AI-generated infrastructure changes critically: catch invented resources, unsafe defaults, and IAM permissions scoped wider than they need to be. Harden Google Cloud Platform identity and access management, including the resource hierarchy, IAM roles and conditions, service accounts and workload identity federation, and organization policy constraints, plus the AWS IAM equivalent. Improve Kubernetes and container security, primarily on GKE: cluster hardening (private clusters, Autopilot), RBAC, admission control, workload identity, network policy, and secure container image pipelines (Artifact Registry, Binary Authorization). Add automated security testing and CSPM tooling to CI/CD and GitOps pipelines, then help teams triage and fix what those tools surface. Benchmark infrastructure against secure configuration baselines such as the CIS Google Cloud Foundation Benchmark, and against the infrastructure controls in frameworks like ISO 27001 and NIST 800-53. Limit the risks AI agents themselves introduce: prompt injection, over-broad permissions, leaked secrets, and changes made without review. Measure whether agent-driven fixing is actually working across teams, and improve the approach as you learn what does and doesn't land. ## Related Videos - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)