Staff Platform Security Engineer
Indexed description
This is a remote position
Join one of the Philippines' fastest-growing tech companies! Open to Philippine-based candidates only.
About Us
Full Scale is a fully remote-first company that helps businesses build dedicated teams of skilled software engineers. We make it easier for growing companies to find, onboard, and retain high-performing software talent.
About the Role
We are seeking a hands-on Senior / Staff Platform Security Engineer who can build, implement, and validate security controls across Azure, AKS/Kubernetes, identity, CI/CD, cloud networking, and production environments.
This role is best suited to a security engineer who has personally built and improved production controls. Candidates whose experience is primarily compliance, audit, SOC monitoring, architecture advisory, or people management without implementation ownership will not be a strong fit.
Requirements:
- 6+ years of experience in cloud security, platform security, security engineering, infrastructure security, DevSecOps, SRE, DevOps, or related technical infrastructure roles.
- At least 4 years of security-focused experience in cloud, platform, application, DevSecOps, or production security engineering.
- Strong hands-on Azure security experience, including Entra ID, managed and workload identities, RBAC, PIM, Key Vault, Defender for Cloud, Sentinel or comparable tools, private networking, and least-privilege architecture.
- Strong AKS/Kubernetes and container-security experience, including Kubernetes RBAC, workload identity, secrets, network policies, ingress controls, admission and policy controls, runtime protection, and workload isolation.
- Practical experience implementing secure-SDLC controls: SAST, DAST, SCA/dependency scanning, secret scanning, IaC scanning, container scanning, vulnerability management, CVEs/CVSS, and CI/CD security gates.
- Experience securing software and container supply chains, including image scanning, registries, image provenance or signing, base-image and dependency vulnerabilities, and secure deployment controls.
- Strong network-security knowledge across WAFs, firewalls, segmentation, private endpoints, ingress and egress controls, attack-surface reduction, and zero-trust principles.
- Experience with security monitoring, detection, and incident response using SIEM telemetry, identity events, cloud audit logs, investigation, and containment workflows.
- Experience conducting threat modeling and security architecture reviews, and translating findings into a prioritized technical security roadmap.
- Strong infrastructure-as-code experience using Terraform, Bicep, ARM, or comparable tools, including policy and security automation.
- Strong communication skills and the ability to partner with engineering teams, explain security findings clearly, and drive remediation through completion.
- Must be hands-on at the keyboard and able to describe security controls personally configured or implemented, including the tools used, architecture decisions made, problems encountered, and how the control was validated.
Preferred Qualifications
- Experience operating in a regulated or high-assurance environment and producing audit-ready technical evidence; HIPAA, SOC 2, ISO 27001, healthcare SaaS, fintech, or similar experience is valuable.
- Experience with Microsoft Defender for Cloud, Microsoft Sentinel, Azure Policy, Log Analytics, CrowdStrike, Aikido, Vanta, New Relic, or comparable security platforms.
- Experience with GitHub Actions, Azure DevOps, or comparable CI/CD platforms.
- Familiarity with SAML, OIDC, SCIM, SSO, MFA, Conditional Access, and privileged-access management.
- Experience in multi-tenant SaaS, .NET, Angular, or security automation using Python, Go, Bash, or PowerShell.
- Certifications such as Azure Security Engineer Associate, CKS, CCSP, or CISSP, paired with demonstrated implementation experience.
Why join us:
- 100% remote work setup
- Work from anywhere in the Philippines
- Direct visibility and collaboration with the
- High-impact role with significant technical ownership and autonomy
- Opportunity to work on a cloud-native healthcare/SaMD platform
- Exposure to modern Azure, AKS, Kubernetes, and cloud security technologies
- Opportunity to work in a regulated, high-assurance environment
- Collaboration with Engineering, Product, IT, Quality, and Compliance teams
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search