Security Architect
Hace 1 día
España
Deel
Jornada completa
Gratis con email o Google
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Gratis con email o Google
Al continuar, aceptas nuestros Términos & Política de Privacidad.
Deel is the all-in-one payroll and HR platform for global teams. Our vision is to unlock global opportunity for every person, team, and business. Built for the way the world works today, Deel combines HRIS, payroll, compliance, benefits, performance, and equipment management into one seamless platform. Deel is the all-in-one payroll and HR platform for global teams. Our vision is to unlock global opportunity for every person, team, and business. Built for the way the world works today, Deel combines HRIS, payroll, compliance, benefits, performance, and equipment management into one seamless platform. As the fastest-growing Software as a Service (SaaS) company in history, Deel is transforming how global talent connects with world‐class companies
- breaking down borders that have traditionally limited both hiring and career opportunities. We're not just building software; we're creating the infrastructure for the future of work, enabling a more diverse and inclusive global economy. CNBC Disruptor 50, Forbes Cloud 100, Deloitte Fast 500, and repeated recognition on Y Combinator's top companies list
- all while maintaining a 4.83 average rating from 15,000 reviews across G2, Trustpilot, Captera, Apple and Google. At the forefront of the global work revolution, you'll tackle complex challenges that impact millions of people's working lives. With our momentum—backed by a $17.3 billion valuation and $1 B in Annual Recurring Revenue (ARR) in just over five years—you'll drive meaningful impact while building expertise that makes you a sought‐after leader in the transformation of global work. Deel is seeking a Platform Security Architect to own the security of our platform from the code our engineers write to the cloud it runs on. In this role, you'll design, build, and evolve the security architecture across two layers that can't be secured in isolation: our applications and services, and the AWS and Kubernetes infrastructure beneath them. This is a hands‐on, high‐impact position at the core of Deel's security engineering function, not a governance or advisory seat. Own the platform security architecture strategy across Deel's applications, services, and cloud environments, with a primary focus on AWS. Define secure design patterns, reference architectures, guardrails, and baseline configurations that teams build against by default. Run Deel's security tooling as one program. Operate and tune Wiz for cloud posture (CSPM) and runtime visibility, and Aikido for SAST, SCA, secrets detection, container, IaC, and DAST scanning. Connect findings across code and cloud so the team fixes what is actually exploitable, not what is merely noisy. Own least‐privilege cloud IAM (cross‐account roles, permission boundaries, SCPs, just‐in‐time access) and application authentication and authorization (session and token handling, multi‐tenant isolation, object‐level access control). Embed security into the SDLC and CI/CD pipelines. Secure containers and Kubernetes. Set the standards for image hardening and signing, admission control, pod security, network policies, secrets management, and runtime protection. Own software supply chain security. Lead threat modeling for new and existing systems, and make it part of how engineering designs software rather than a security‐team ritual. Lead platform security incident response across application and cloud layers: triage, containment, forensics, root cause analysis, and post‐incident hardening. Scale security through people. Build a Security Champions program and secure coding enablement so security knowledge spreads across engineering instead of pooling in the security team. Act as the technical authority on platform security, reviewing high‐risk designs, evaluating vendors, and influencing engineering and cloud strategy at the leadership level. Use Artificial Intelligence as an enabler to find new insights, learn from past mistakes, and continuously improve Deel's security posture, including securing the AI features Deel ships. 5+ years of hands‐on experience in cybersecurity, with real depth in both cloud security and application security engineering or architecture. Deep AWS security expertise: IAM design, network controls, logging and monitoring (CloudTrail, Security Hub, GuardDuty), and data protection. Deep application security expertise: OWASP Top 10 and API Security Top 10, authentication and authorization design, injection and deserialization, SSRF, business logic flaws, and secure session handling. Proven hands‐on experience operating security platforms such as Wiz (or Orca, Prisma Cloud) and Aikido (or Snyk, Semgrep, GitHub Advanced Security), including rollout, tuning, false‐positive reduction, and integration with engineering workflows. Strong experience building security gates into CI/CD pipelines for both application code and Infrastructure as Code. Strong experience securing containers and Kubernetes: image hardening, runtime security, pod se
- breaking down borders that have traditionally limited both hiring and career opportunities. We're not just building software; we're creating the infrastructure for the future of work, enabling a more diverse and inclusive global economy. CNBC Disruptor 50, Forbes Cloud 100, Deloitte Fast 500, and repeated recognition on Y Combinator's top companies list
- all while maintaining a 4.83 average rating from 15,000 reviews across G2, Trustpilot, Captera, Apple and Google. At the forefront of the global work revolution, you'll tackle complex challenges that impact millions of people's working lives. With our momentum—backed by a $17.3 billion valuation and $1 B in Annual Recurring Revenue (ARR) in just over five years—you'll drive meaningful impact while building expertise that makes you a sought‐after leader in the transformation of global work. Deel is seeking a Platform Security Architect to own the security of our platform from the code our engineers write to the cloud it runs on. In this role, you'll design, build, and evolve the security architecture across two layers that can't be secured in isolation: our applications and services, and the AWS and Kubernetes infrastructure beneath them. This is a hands‐on, high‐impact position at the core of Deel's security engineering function, not a governance or advisory seat. Own the platform security architecture strategy across Deel's applications, services, and cloud environments, with a primary focus on AWS. Define secure design patterns, reference architectures, guardrails, and baseline configurations that teams build against by default. Run Deel's security tooling as one program. Operate and tune Wiz for cloud posture (CSPM) and runtime visibility, and Aikido for SAST, SCA, secrets detection, container, IaC, and DAST scanning. Connect findings across code and cloud so the team fixes what is actually exploitable, not what is merely noisy. Own least‐privilege cloud IAM (cross‐account roles, permission boundaries, SCPs, just‐in‐time access) and application authentication and authorization (session and token handling, multi‐tenant isolation, object‐level access control). Embed security into the SDLC and CI/CD pipelines. Secure containers and Kubernetes. Set the standards for image hardening and signing, admission control, pod security, network policies, secrets management, and runtime protection. Own software supply chain security. Lead threat modeling for new and existing systems, and make it part of how engineering designs software rather than a security‐team ritual. Lead platform security incident response across application and cloud layers: triage, containment, forensics, root cause analysis, and post‐incident hardening. Scale security through people. Build a Security Champions program and secure coding enablement so security knowledge spreads across engineering instead of pooling in the security team. Act as the technical authority on platform security, reviewing high‐risk designs, evaluating vendors, and influencing engineering and cloud strategy at the leadership level. Use Artificial Intelligence as an enabler to find new insights, learn from past mistakes, and continuously improve Deel's security posture, including securing the AI features Deel ships. 5+ years of hands‐on experience in cybersecurity, with real depth in both cloud security and application security engineering or architecture. Deep AWS security expertise: IAM design, network controls, logging and monitoring (CloudTrail, Security Hub, GuardDuty), and data protection. Deep application security expertise: OWASP Top 10 and API Security Top 10, authentication and authorization design, injection and deserialization, SSRF, business logic flaws, and secure session handling. Proven hands‐on experience operating security platforms such as Wiz (or Orca, Prisma Cloud) and Aikido (or Snyk, Semgrep, GitHub Advanced Security), including rollout, tuning, false‐positive reduction, and integration with engineering workflows. Strong experience building security gates into CI/CD pipelines for both application code and Infrastructure as Code. Strong experience securing containers and Kubernetes: image hardening, runtime security, pod se