Platform Security Engineer
Indexed description
Job Title
Senior Engineer
Team
Platform Security
Service Line Information
Technology services the broader Firm through delivery of core technology and managed services capabilities, collaboration and innovation development services and building our Alliances network.
Job Description
The Team
Cloud Engineering supports the firm by delivering modern platform capabilities, observability services, and engineering enablement across distributed systems. The Platform Security team safeguards cloud platforms by implementing secure‑by‑default patterns, enforcing guardrails, and supporting threat detection, response, and continuous security improvement across digital services.
Key Responsibilities
Technical Leadership
- Provide guidance to engineers on secure cloud configurations, secret management, identity governance, and platform guardrails.
- Lead security onboarding for new services, ensuring alignment with secure‑by‑default patterns.
- Develop and refine security policies, baseline configurations, and platform governance controls.
- Manage and review access control models including RBAC, privileged access, automation identities, and workload identities.
- Oversee automated policy checks and compliance monitoring.
- Embed security scanning, image validation, dependency checks, IaC scanning, and code signing into CI/CD workflows.
- Create reusable DevSecOps templates for teams to adopt (pipeline templates, scanning configs, signing steps).
- Lead reviews of Terraform modules to ensure secure configurations and alignment with guardrails.
- Contribute to secure architecture patterns for networking, identity, and workload isolation.
- Enhance detections, rule sets, and response playbooks for cloud threat intelligence signals.
- Participate in incident response activities, supporting containment and root cause analysis.
- Build automation to support access reviews, remediation workflows, and compliance reporting.
- Work closely with product, observability, SRE, and platform engineering teams to embed security early in design.
- Deliver training, guidance, and best‑practice documentation.
- Manage relationships with stakeholders to become a trusted partner.
- Lead by example by living by Our Values and embracing our culture
- Work in rotational shifts as required.
- Participate in on‑call rotations to respond to and resolve high‑severity incidents in a timely manner.
- Strong hands‑on experience in cloud security engineering and DevSecOps.
- Skilled in IaC assessment, policy‑as‑code, scanning tools, and secure architecture.
- Extensive knowledge of CI/CD pipelining skills using Azure DevOps or equivalent.
- Proficient in scripting/automation languages (PowerShell, Python, Bash).
- Familiar with threat detection, cloud forensics, and incident response processes.
- Effective communicator able to influence engineering teams to adopt secure‑by‑default practices.
- Strong sense of ownership and problem‑solving abilities and commitment to raising engineering standards.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search