> Markdown version of [/jobs/ext/3515158-principal-security-platform-engineer](https://www.wearedevelopers.com/jobs/ext/3515158-principal-security-platform-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Platform Engineer - **Company:** EPAM Systems, Inc. - **Location:** Málaga, Spain - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Computer Programming, Continuous Integration, DevOps, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Key Management, Network Security, Linux System Administration, Windows PowerShell, Software Tools, Ansible, Trusted Systems, Windows Desktop, Policy as Code, Pulumi, Google Cloud, System Availability, Delivery Pipeline, Firewalls (Computer Science), Infrastructure as Code (IaC), Containerization, Information Technology, Terraform - **Published:** September 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=06897a02b8f18021 ## About the Role * Bachelor's or Master's degree in Computer Science, Engineering or related field, or equivalent experience * 5+ years in security engineering, platform engineering or related cloud-focused roles * Hands-on experience with cloud security (AWS, Azure, GCP) and CSPM/CNAPP platforms * Strong understanding of networking, secure systems design and infrastructure security principles * Proficiency in scripts or programming with Python and/or PowerShell * Familiarity with Windows and Linux environments for operational security management * Knowledge of CI/CD security, IaC and PaC practices using Terraform or similar tools * Strong operational mindset with skills in monitoring, alerting and incident response * Comfort working with AI-driven development and security analysis tools * Excellent communication with ability to document and present technical solutions effectively Nice to have * Deep expertise in Terraform, Pulumi, Ansible or OPA (Open Policy Agent) frameworks * Experience implementing software supply chain security measures: SBOMs, artifact signing, dependency risk checks * Familiarity with containerization and Kubernetes security controls * Knowledge of cloud-native security services and platform tools (e.g., Wiz, Checkov) * Exposure to network security technologies: IDS, IPS, DLP, EDR, firewalls and file integrity monitoring * Strong Python development background with focus on automation and orchestration * Experience creating self-service security solutions for engineering enablement * Demonstrated use of AI-assisted engineering tools to streamline workflows and security testing ## Description The position combines technical security expertise with a DevOps-driven approach, focusing on automation, Infrastructure as Code (IaC), Policy as Code (PaC) and CI/CD security. You will leverage AI-assisted engineering tools to boost speed, efficiency, and resiliency while reducing risk in a scalable manner., * Architect, implement and operate security platforms and controls ensuring high availability and measurable outcomes * Enhance and integrate security solutions across AWS, Azure and GCP environments * Continuously improve existing controls through automation, IaC/PaC, and self-service capabilities * Implement and manage CSPM/CNAPP solutions (e.g., Wiz) to monitor and reduce cloud risk * Support secure software delivery pipelines, including dependency scanning, artifact validation and secrets management * Develop Infrastructure as Code using Terraform, Pulumi or Ansible for automated provisioning * Apply Policy as Code frameworks (e.g., OPA, Sentinel) for enforcement and compliance automation * Build and manage observability components for threat detection, alerting and incident response * Collaborate with Security Operations, DevOps and engineering teams to maintain a robust security posture * Use AI-assisted tools to accelerate automation, security analysis and operational documentation ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Why segmenting your infrastructure into tiers makes your infrastructure design better](https://www.wearedevelopers.com/videos/1960-why-segmenting-your-infrastructure-into-tiers-makes-your-infrastructure-design-better) - [Shifting Stress to Progress— Understanding DevOps to do DevOps Better](https://www.wearedevelopers.com/videos/268-shifting-stress-to-progress-understanding-devops-to-do-devops-better) - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [Terraform for Developers](https://www.wearedevelopers.com/videos/3-terraform-for-developers) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)