> Markdown version of [/jobs/ext/3618139-platform-security-architect](https://www.wearedevelopers.com/jobs/ext/3618139-platform-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Platform Security Architect - **Company:** Deel - **Location:** Barcelona, Spain - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Cloud Computing, Cyber Security, Computer Networks, Continuous Integration, Identity and Access Management, Python (Programming Language), Node.Js, Open Web Application Security, PCI Data Security Standards, Performance Tuning, Systems Development Life Cycle, Role-Based Access Control, Secure Coding, TypeScript, Software Vulnerability Management, Data Logging, Cloud Platform System, Software Security, Kubernetes, Production Code, Hashicorp, Prisma Cloud Platform, Static Application Security Testing, Golang - **Published:** October 8, 2026 - **Apply:** https://www.buscojobs.com.es/platform-security-architect-en-barcelona-ID-375248361 ## About the Role OverviewAs Platform Security Architect you own the security of Deel's platform across applications and cloud infrastructure, focused on AWS. You design secure patterns, lead tooling, and embed security into the SDLC to enable fast-moving teams. You influence engineering and leadership, shaping the defender role across code and cloud. You work with Privacy/Compliance to meet standards and drive secure-by-default systems at scale. This role combines hands-on security with strategic architecture.Compensaciones / BeneficiosStock grant opportunitiesOptional flexible working office membershipAdditional country-based perksCompetitive salary within USD rangeSupportive, inclusive cultureCareer growth opportunitiesResponsabilidadesOwn platform security architecture across applications, services, and cloud environments (AWS-focused)Define secure design patterns, reference architectures, guardrails, and default baselines for teamsLead security tooling program (Wiz, Aikido) for CSPM, SAST, SCA, secrets detection, containers, IaC, DASTDesign identity and access controls at all layers (IAM, just-in-time access, multi-tenant auth)Embed security in SDLC and CI/CD pipelines with guardrails that block or warn buildsSecure containers and Kubernetes (image hardening, runtime protection, network policies)Own software supply chain security (dependencies, SBOMs, build integrity, provenance)Lead threat modeling and vulnerability management, coordinating with engineering for remediationLead platform security incident response and post-incident hardeningPartner with Privacy/Compliance to satisfy SOC 2 II, ISO *****, PCI DSS, GDPR, ensuring auditable decisionsScale security through a Security Champions program and secure coding enablementAct as technical authority on platform security, influence leadership on security-forward strategyLeverage AI to improve security posture and secure AI featuresRequisitos principales5+ years in cybersecurity with cloud and application security depthDeep AWS security expertise (IAM, network controls, logging, data protection)Deep application security expertise (OWASP Top 10, API security)Hands-on experience with Wiz, Aikido or alternatives (rollout, tuning, integration)CI/CD gates for application code and IaCSecurity for containers and Kubernetes (image hardening, RBAC)Threat modeling experience (STRIDE etc)Production code capability in TypeScript/Node.Js, Python, Go, or JavaSecrets management (HashiCorp Vault, AWS Secrets Manager) and encryption patternsExperience with vulnerability management or bug bounty programsKnowledge of SOC 2 II, ISO *****, PCI DSS, GDPRAbility to translate security concepts into engineer-facing guidanceExcellent English communicationstrong collaboration with cross-functional teamsclear written and verbal communicationrisk-based decision makingAWS IAM designCloudTrail, Security Hub, GuardDutyWiz, Orca, Prisma Cloud ## Description OverviewAs Platform Security Architect you own the security of Deel's platform across applications and cloud infrastructure, focused on AWS.You design secure patterns, lead tooling, and embed security into the SDLC to enable fast-moving teams.You influence engineering and leadership, shaping the defender role across code and cloud.You work with Privacy/Compliance to meet standards and drive secure-by-default systems at scale.This role combines hands-on security with strategic architecture.Compensaciones / BeneficiosStock grant opportunitiesOptional flexible working office membershipAdditional country-based perksCompetitive salary within USD rangeSupportive, inclusive cultureCareer growth opportunitiesResponsabilidadesOwn platform security architecture across applications, services, and cloud environments (AWS-focused)Define secure design patterns, reference architectures, guardrails, and default baselines for teamsLead security tooling program (Wiz, Aikido) for CSPM, SAST, SCA, secrets detection, containers, IaC, DASTDesign identity and access controls at all layers (IAM, just-in-time access, multi-tenant auth)Embed security in SDLC and CI/CD pipelines with guardrails that block or warn buildsSecure containers and Kubernetes (image hardening, runtime protection, network policies)Own software supply chain security (dependencies, SBOMs, build integrity, provenance)Lead threat modeling and vulnerability management, coordinating with engineering for remediationLead platform security incident response and post-incident hardeningPartner with Privacy/Compliance to satisfy SOC 2 II, ISO *****, PCI DSS, GDPR, ensuring auditable decisionsScale security through a Security Champions program and secure coding enablementAct as technical authority on platform security, influence leadership on security-forward strategyLeverage AI to improve security posture and secure AI featuresRequisitos principales5+ years in cybersecurity with cloud and application security depthDeep AWS security expertise (IAM, network controls, logging, data protection)Deep application security expertise (OWASP Top 10, API security)Hands-on experience with Wiz, Aikido or alternatives (rollout, tuning, integration)CI/CD gates for application code and IaCSecurity for containers and Kubernetes (image hardening, RBAC)Threat modeling experience (STRIDE etc)Production code capability in TypeScript/Node.Js, Python, Go, or JavaSecrets management (HashiCorp Vault, AWS Secrets Manager) and encryption patternsExperience with vulnerability management or bug bounty programsKnowledge of SOC 2 II, ISO *****, PCI DSS, GDPRAbility to translate security concepts into engineer-facing guidanceExcellent English communicationstrong collaboration with cross-functional teamsclear written and verbal communicationrisk-based decision makingAWS IAM designCloudTrail, Security Hub, GuardDutyWiz, Orca, Prisma Cloud