> Markdown version of [/jobs/ext/468406-platform-security-engineer](https://www.wearedevelopers.com/jobs/ext/468406-platform-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Platform Security Engineer - **Company:** CTECH NY INC - **Location:** Dallas, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Microsoft Azure, Bash Shell, Linux, DevOps, Python (Programming Language), Key Management, OpenStack, Cloud Services, Software Vulnerability Management, Scripting, Cloud Platform System, Software Security, GWAPT, Kubernetes, Prisma Cloud Platform, Vulnerability Analysis - **Published:** June 2, 2026 - **Apply:** https://career-techniques.com/job/senior-platform-security-engineer/ ## About the Role * 6+ years of experience in security engineering, with a strong focus on platform, infrastructure, or application security * Hands-on experience with vulnerability management tooling and real-time security monitoring platforms (e.g. Qualys, Tenable, Wiz, Lacework, Prisma Cloud, or similar) * Strong understanding of software and infrastructure security, including container security, supply chain risk, secrets management, and secure configuration * Experience securing container orchestration platforms such as Kubernetes and OpenStack, and cloud environments including AWS and/or Azure * Proficiency in Linux and familiarity with how platform engineering teams build and operate infrastructure * Experience integrating security tooling into CI/CD pipelines and IaC workflows, with scripting ability in Python, Bash, or similar * Good knowledge of vulnerability scoring frameworks (CVSS), exploit maturity, and risk-based prioritization * A strong interest in the security domain and a collaborative approach to working with engineering teams to solve complex technical problems Nice to Have * Experience with runtime threat detection tools such as Falco or eBPF-based security tooling * Familiarity with software supply chain security frameworks (e.g. SLSA, SBOM generation, Sigstore) * Background working within or alongside a SOC or threat intelligence function * Relevant certifications such as OSCP, GIAC (GPEN/GWAPT/GCSA), AWS Security Specialty, or equivalent ## Description As a Senior Platform Security Engineer, you will play a pivotal role in detecting, assessing, and remediating vulnerabilities across the platform engineering stack - from bare-metal infrastructure and container orchestration through to cloud services and software supply chains. You will collaborate closely with Platform Engineering and DevOps teams to embed real-time threat detection and vulnerability management into the development lifecycle, ensuring our infrastructure is resilient, continuously monitored, and hardened against emerging threats., * Own the design and operation of vulnerability management program across the platform engineering stack, including infrastructure, containers, and cloud services * Implement and tune real-time security monitoring and threat detection tooling, ensuring high-fidelity signal across our HPC and cloud environments * Partner with Platform Engineering and DevOps teams to integrate security scanning and vulnerability assessment into CI/CD pipelines and Infrastructure-as-Code workflows * Lead vulnerability triage and prioritization, working with engineering teams to drive timely and effective remediation of identified risks * Conduct platform-level security assessments, contributing to threat modelling and attack surface analysis across our infrastructure and software supply chain * Develop automation to continuously assess the security posture of our platforms, reducing manual effort and improving detection coverage * Contribute to the continuous improvement of platform security practices, tooling, and processes, helping foster a security-first culture across engineering ## Related Videos - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)