Senior Platform Engineer - Security

Rumble Inc.
Washington, DC, United States
2 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$122,000.0 - $205,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Bash Shell Cloud Computing Cloud Engineering CompTIA Security+ Cyber Security Linux Python (Programming Language) Key Management Linux Distribution Linux Security Modules Network Control
+21 more
OAuth OpenID OpenStack Package Management Systems PCI Data Security Standards Reliability Engineering Ansible Security Information and Event Management Software Vulnerability Management Ceph (Software) Data Logging Scripting Openstack Neutron Selinux Kubernetes Infrastructure Automation Frameworks Cinder (Software) CIS Benchmarks Terraform Splunk Devsecops

Job description

Rumble Cloud is seeking a Senior Platform Engineer (Security) to help operate, secure, and continuously harden the infrastructure that powers our public cloud, built on OpenStack and Ceph. This role sits at the intersection of platform engineering and security operations: you’ll apply and maintain security hardening across our Linux fleet and cloud control plane, track vulnerabilities through to remediation, and serve as a key engineering partner for internal and external audits.

Strong Linux fundamentals are essential, and demonstrated security expertise, ideally backed by certification, is a significant differentiator. You’ll work across operating systems, OpenStack and Ceph components, and Kubernetes, using automation to keep baselines consistent and auditable. You’ll partner closely with cloud engineering, DevSecOps, and compliance stakeholders to ensure the platform meets both reliability and security expectations as it grows.

If you enjoy hardening Linux at scale, working directly with vulnerability and control frameworks such as CIS Benchmarks and ISO 27001, and contributing to the security posture of mission-critical cloud infrastructure, this role offers substantial impact and technical depth., * Assess, implement, and maintain security hardening (CIS Benchmarks, STIGs, or equivalent) across Linux hosts, hypervisors, and the cloud control plane, using automated baselines with tools such as Ansible and Terraform.

  • Track and remediate vulnerabilities at the infrastructure layer, including operating systems and platform components such as OpenStack, Ceph, and Kubernetes, maintaining accurate inventory, patch SLAs, and risk-based prioritization.

  • Coordinate with the DevSecOps Engineer on application- and pipeline-layer remediation, ensuring alignment between platform hardening and SSDLC practices.

  • Serve as a primary technical contributor to internal and external audits, including evidence collection, control narratives, and responses to auditor questions, mapping work to ISO 27001 and other relevant frameworks.

  • Operate and improve core platform services on Linux infrastructure, contributing to automation, capacity planning, incident response, and reliability engineering.

  • Help design logging, monitoring, and alerting that support both operational and security use cases, in collaboration with platform, security, and SRE teams.

  • Document hardening baselines, security controls, and operational procedures clearly so that they are repeatable, testable, and auditable.

Requirements

Do you have experience in Vulnerability management?, * Strong Linux systems engineering background (systemd, networking, storage, package management) on major Linux distributions.

  • Hands-on experience applying security hardening standards such as CIS Benchmarks, STIGs, or equivalent at production scale.

  • Solid understanding of vulnerability management (CVSS scoring, risk-based prioritization) and Linux security controls (SELinux or AppArmor, auditd, PAM, host firewalling).

  • Experience with infrastructure automation using Ansible, Terraform, and scripting in Bash and/or Python.

  • Experience supporting compliance or audit activities, including evidence collection, control documentation, and working directly with auditors or security teams.

  • Strong understanding of identity and authentication concepts (SSO, OAuth2/OIDC, privileged access) and excellent documentation skills.

Preferred Qualifications

  • Security certifications such as CISSP, CISM, CCSP, GSEC, GCIH, Security+, or equivalent; more senior certifications are a significant plus.

  • Experience supporting ISO 27001, SOC 2, PCI DSS, or FedRAMP audits in a hands-on capacity.

  • Familiarity with OpenStack services (Nova, Neutron, Keystone, Cinder) and/or Ceph.

  • Experience with Kubernetes security and hardening, including CIS Kubernetes Benchmarks and Pod Security Standards.

  • Background with SIEM, EDR, or log aggregation tools (Elastic, Splunk, Wazuh, Falco), secrets management (Vault), and disk encryption (LUKS/dm-crypt).

Benefits & conditions

$165,000 - $205,000 USD base + benefits + equity (If based in the United States)

$122,000 - $158,000 CAD base + benefits + equity (If based in Canada)

Note: The salary range listed for this position is a good faith estimate based on experience, qualifications, and internal compensation structure. The actual salary offered varies depending on the candidate’s skill level and experience. This posting refers to an active vacancy within the organization.

Why Our Team Loves Working Here:

  • We are making a significant financial impact for our video creator community; we’re proud of their success stories
  • We enjoy challenging the status quo and going head-to-head against Big Tech
  • We aren’t afraid to try new things; we act fast and want to win
  • We pay competitive salaries and provide great benefits

About the company

While performing the duties of this job, the employee is regularly required to sit for prolonged periods of time while using a computer and/or keyboard. The employee is required to communicate verbally and hear. The employee may be required to walk, reach with hands and arms, balance, and stoop or kneel. The employee may occasionally be required to lift and/or move up to 15 pounds. Specific vision abilities required by this job include clarity of vision at approximately 20 inches or less (i.e., working with small objects or reading small print), including the use of computers.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

4:40 min

Assessing common Kubernetes security incidents and misconfigurations

Rico Komenda Rico Komenda · World Congress 2025

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all