Platform Security Architect

Hace 2 días

Madrid, Area Metropolitana (comarca); Comunidad de Madrid, España Deel Jornada completa

Who We Are

Is What We Do.
Deel is the all-in-one payroll and HR platform for global teams. Our vision is to unlock global opportunity for every person, team, and business. Built for the way the world works today, Deel combines HRIS, payroll, compliance, benefits, performance, and equipment management into one seamless platform. With AI-powered tools and a fully owned payroll infrastructure, Deel supports every worker type in 150+ countries—helping businesses scale smarter, faster, and more compliantly.
Deel is the all-in-one payroll and HR platform for global teams. Our vision is to unlock global opportunity for every person, team, and business. Built for the way the world works today, Deel combines HRIS, payroll, compliance, benefits, performance, and equipment management into one seamless platform. With AI-powered tools and a fully owned payroll infrastructure, Deel supports every worker type in 150+ countries—helping businesses scale smarter, faster, and more compliantly.
Why should you be part of our success story?
As the fastest-growing Software as a Service (SaaS) company in history, Deel is transforming how global talent connects with world‐class companies – breaking down borders that have traditionally limited both hiring and career opportunities. We're not just building software; we're creating the infrastructure for the future of work, enabling a more diverse and inclusive global economy. In 2024 alone, we paid $11.2 billion to workers in nearly 100 currencies and provided healthcare and benefits to workers in 109 countries—ensuring people get paid and protected, no matter where they are.
Our momentum is reflected in our achievements and customer satisfaction: CNBC Disruptor 50, Forbes Cloud 100, Deloitte Fast 500, and repeated recognition on Y Combinator's top companies list – all while maintaining a 4.83 average rating from 15,000 reviews across G2, Trustpilot, Captera, Apple and Google.
Your experience at Deel will be a career accelerator. At the forefront of the global work revolution, you'll tackle complex challenges that impact millions of people's working lives. With our momentum—backed by a $17.3 billion valuation and $1 B in Annual Recurring Revenue (ARR) in just over five years—you'll drive meaningful impact while building expertise that makes you a sought‐after leader in the transformation of global work.
Deel is seeking a Platform Security Architect to own the security of our platform from the code our engineers write to the cloud it runs on. In this role, you'll design, build, and evolve the security architecture across two layers that can't be secured in isolation: our applications and services, and the AWS and Kubernetes infrastructure beneath them. This is a hands‐on, high‐impact position at the core of Deel's security engineering function, not a governance or advisory seat.
We need one architect who sees the whole path. You'll partner closely with Engineering, Infrastructure, Product, and Privacy/Compliance to build systems that are secure by default, without becoming a bottleneck to the fast‐moving teams that depend on you.
Responsibilities

Own the platform security architecture strategy across Deel's applications, services, and cloud environments, with a primary focus on AWS. Define secure design patterns, reference architectures, guardrails, and baseline configurations that teams build against by default.
Run Deel's security tooling as one program. Operate and tune Wiz for cloud posture (CSPM) and runtime visibility, and Aikido for SAST, SCA, secrets detection, container, IaC, and DAST scanning. Connect findings across code and cloud so the team fixes what is actually exploitable, not what is merely noisy.
Design identity and access at every layer. Own least‐privilege cloud IAM (cross‐account roles, permission boundaries, SCPs, just‐in‐time access) and application authentication and authorization (session and token handling, multi‐tenant isolation, object‐level access control).
Embed security into the SDLC and CI/CD pipelines. Build the guardrails for application code and Infrastructure as Code alike, with a clear model for what blocks a build and what warns.
Secure containers and Kubernetes. Set the standards for image hardening and signing, admission control, pod security, network policies, secrets management, and runtime protection.
Own software supply chain security. Cover dependency and transitive risk, malicious package detection, SBOMs, build integrity, and artifact provenance, from the first npm install to the running workload.
Lead threat modeling for new and existing systems, and make it part of how engineering designs software rather than a security‐team ritual.
Run vulnerability management for findings from scanners, pentests, and bug bounty: triage, exploitability assessment, SLAs, remediation partnership with engineering, and reporting on risk reduction over time.
L