> Markdown version of [/jobs/ext/3611329-platform-security-architect](https://www.wearedevelopers.com/jobs/ext/3611329-platform-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Platform Security Architect - **Company:** Iwgat Deel - **Location:** Wien, Austria - **Salary:** €70,000.0 - €120,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Business Logic, Software System Penetration Testing, User Authentication, Microsoft Azure, Software as a Service, Cloud Computing Security, Cyber Security, Information Leak Prevention, Github, Identity and Access Management, Python (Programming Language), Key Management, Node.Js, Open Web Application Security, PCI Data Security Standards, Performance Tuning, Secure Coding, Software Engineering, TypeScript, Software Vulnerability Management, Data Logging, Cloud Platform System, Large Language Models, Software Security, Multi-Cloud, Kubernetes, Production Code, Hashicorp, Prisma Cloud Platform, Devsecops, Golang - **Published:** October 8, 2026 - **Apply:** https://www.studentjob.at/stellenangebote/8883290-platform-security-architect ## About the Role Qualifications5+ years of hands-on experience in cybersecurity, with real depth in both cloud security and application security engineering or architecture. Deep AWS security expertise: IAM design, network controls, logging and monitoring (CloudTrail, Security Hub, GuardDuty), and data protection. Deep application security expertise: OWASP Top 10 and API Security Top 10, authentication and authorization design, injection and deserialization, SSRF, business logic flaws, and secure session handling. Proven hands-on experience operating security platforms such as Wiz (or Orca, Prisma Cloud) and Aikido (or Snyk, Semgrep, GitHub Advanced Security), including rollout, tuning, false-positive reduction, and integration with engineering workflows. Strong experience building security gates into CI/CD pipelines for both application code and Infrastructure as Code. Strong experience securing containers and Kubernetes: image hardening, runtime security, pod security standards, and Kubernetes RBAC.Hands-on threat modeling experience (STRIDE, attack trees, or equivalent) applied to real systems, with findings turned into concrete engineering work. Ability to read, reason about, and write production code in at least one modern language (TypeScript/Node.js, Python, Go, or Java).Experience with secrets management (HashiCorp Vault, AWS Secrets Manager) and encryption patterns for data at rest and in transit. Experience running vulnerability management or a bug bounty/pentest program, and driving remediation across teams you don't manage. Strong working knowledge of SOC 2 Type II, ISO 27001, PCI DSS, and GDPR.Ability to turn complex security concepts into clear guidance for engineers and risk-based recommendations for executives. Excellent English, written and verbal. Advantageous ExperienceBackground in software engineering, DevSecOps, or platform engineering before moving into security. Credibility with engineers and the ability to ship fixes, not just file tickets. Offensive security background (web/API or cloud penetration testing, exploit development, CTFs) used to inform defensive design. Experience securing multi-tenant SaaS at scale, including tenant isolation and EU data residency requirements. Experience securing AI/LLM-powered features (prompt injection, agent and tool abuse, data leakage) or applying AI to security workflows such as triage and automated remediation. Multi-cloud experience (GCP or Azure alongside AWS).Familiarity with eBPF-based runtime tooling (Wiz, Cilium, Falco, or similar).Experience building a Security Champions program or secure coding curriculum. Experience in high-growth fintech or global HR technology with complex regulatory requirements. ## Description Partner with Privacy/Compliance so platform controls satisfy SOC 2 Type II, ISO 27001, PCI DSS, and GDPR, and design decisions stay defensible and auditable. Scale security through people. Build a Security Champions program and secure coding enablement so security knowledge spreads across engineering instead of pooling in the security team. Act as the technical authority on platform security, reviewing high-risk designs, evaluating vendors, and influencing engineering and cloud strategy at the leadership level. Use Artificial Intelligence as an enabler to find new insights, learn from past mistakes, and continuously improve Deel's security posture, including securing the AI features Deel ships.