> Markdown version of [/jobs/ext/2709325-staff-platform-security-engineer](https://www.wearedevelopers.com/jobs/ext/2709325-staff-platform-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Platform Security Engineer - **Company:** Gemini, Inc. - **Location:** Washington, DC, United States (Remote available) - **Experience:** Expert - **Salary:** $168,000.0 - $240,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cloud Engineering, Computer Networks, Continuous Integration, Distributed Systems, Identity and Access Management, Python (Programming Language), Open Source Technology, Role-Based Access Control, Zero Trust Network Access, Software Engineering, Policy as Code, Google Cloud, Software Modules, Cloud Platform System, Istio, Software Security, Multi-Cloud, Amazon Virtual Private Cloud (VPC), Build Management, Kubernetes, Production Code, Terraform - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/staff-platform-security-engineer-gemini-7976527 ## About the Role * 8+ years of experience in the field * Strong software development skills in Python or Go with experience building production services * Strong experience securing AWS environments including IAM, VPC, KMS, and native security services * Deep Terraform expertise including module development, CI/CD gates, policy testing, remote state management, and zero-downtime deployments * Proven expertise with Kubernetes security including admission controls, RBAC, network policies, and runtime protection * Experience with distributed systems, cloud-native architectures, and SRE principles * Demonstrated ability to build, deploy, and maintain security tools and services in production Preferred Qualifications: * Experience with GCP security services and multi-cloud environments including Azure * Knowledge of policy-as-code tools such as Open Policy Agent, Sentinel, or similar * Experience with container security scanning, image signing, and supply chain security * Background in incident response for cloud and container environments * Experience with service mesh technologies and zero-trust networking * Contributions to open source security tools or cloud security communities ## Description The Role: Staff Platform Security Engineer The Platform Security team builds and delivers zero-trust foundations and paved paths so every Gemini team can ship safely on supported cloud platforms. As a Staff Security Engineer, you will build security services, tools, and automation while hardening our cloud environments (primarily AWS), securing container orchestration platforms, and implementing infrastructure-as-code security guardrails. This is a hands-on engineering role where you'll write production code daily, not just infrastructure-as-code. You'll design and build security platforms that scale across our engineering organization. This role requires deep technical expertise in cloud security, strong Terraform proficiency, and strong software development skills to build production services. You will partner closely with engineering teams to enable rapid, secure delivery while maintaining zero standing privilege and least-privilege access models., * Build and maintain security services, tools, and automation using Python or Go * Design and implement security controls for AWS and Kubernetes environments using infrastructure-as-code * Create reusable libraries, frameworks, and platforms that enable secure-by-default patterns * Develop automated security monitoring, scanning, and remediation services * Build CI/CD security gates and policy-as-code validation tools * Partner with engineering teams on architecture decisions and provide security consultation * Participate in on-call rotation for critical security incidents and infrastructure issues ## Related Videos - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Building a Cloud Platform Where Everything is Just Another Kubernetes Resource](https://www.wearedevelopers.com/videos/100137-building-a-cloud-platform-where-everything-is-just-another-kubernetes-resource) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 161: Gemini 2.5, AI killing search, EU A11Y Act](https://www.wearedevelopers.com/magazine/569-dev-digest-161-gemini-2-5-ai-killing-search-eu-a11y-act) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The Overflow: 5 Security and Privacy Tools for Developers](https://www.wearedevelopers.com/magazine/710-the-overflow-5-security-and-privacy-tools-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)