Submer logo
Submer

Datacenters that make sense

Senior Platform Security Engineer

Platform EngineerPlatform EngineerFull TimeRemoteSeniorTeam 51-200Since 2015H1B No SponsorCompany SiteLinkedIn

Location

Europe

Posted

3 days ago

Salary

0

Seniority

Senior

Job Description

Senior Platform Security Engineer

Submer

Role Description Design and implement key security capabilities for the GPU cloud platform, ensuring that infrastructure, control planes, and multi-tenant workloads operate within a robust zero-trust security model. This role focuses on securing the platform across identity, networking, infrastructure, platform, and automation layers while enabling high-performance AI workloads to run safely in multi-tenant environments. As a Senior Platform Security Engineer, you will build security capabilities that integrate deeply with the platform, infrastructure stack, and operational tooling, enabling secure-by-design infrastructure at scale. You will also leverage automation and AI-assisted tooling to improve detection, triage, and response across the platform security stack. What you’ll do - Zero Trust Architecture - Design and implement zero-trust security architecture across the platform. - Implement identity-aware access controls for infrastructure, services, and operators. - Enforce least-privilege access models for both internal teams and customers. - Secure access paths to infrastructure components including: - Control planes, - Orchestration systems, - Management networks, - Operational tooling. - Identity & Access Management - Design and operate secure authentication and authorization systems. - Implement IAM capabilities for multi-tenant environments in collaboration with platform and infrastructure teams. - Integrate identity systems with infrastructure and platform components. - Manage cryptographic infrastructure including: - PKI systems, - Key management, - Certificate lifecycle automation. - Infrastructure & Platform Security - Secure the underlying infrastructure used by the GPU cloud platform, including: - Kubernetes clusters, - Virtualization layers, - Storage systems, - Networking fabrics. - Collaborate with infrastructure teams to ensure security is embedded in platform architecture and deployment practices. - Contribute to security guardrails and secure deployment patterns for new infrastructure. - Network Security - Design and implement security controls for large-scale distributed infrastructure networks. - Implement secure segmentation and tenant isolation mechanisms using technologies such as: - EVPN / VXLAN, - VRF isolation, - Encrypted transport, - Zero-trust networking. - Work with networking teams to secure high-performance fabrics including RDMA and InfiniBand environments. - Security Automation - Develop automation workflows that improve detection, response, and remediation. - Build integrations between security systems and operational tooling. - Automate vulnerability triage, remediation workflows, and incident response processes. - Contribute to SOAR-style automation systems that coordinate security operations across the platform. - Threat Detection & Incident Response - Support security monitoring and detection systems. - Investigate and triage security alerts and potential vulnerabilities. - Participate in incident response and post-incident analysis. - Improve detection coverage and response automation across the platform. - Vulnerability & Patch Management - Design and maintain patch management strategies across the platform infrastructure, including: - Operating systems, - Container runtimes, - Kernel updates, - Infrastructure components. - Build automation pipelines that validate and deploy security updates across large infrastructure fleets. - Track vulnerabilities and coordinate remediation across engineering teams. - Maintain vulnerability remediation workflows and reporting for security posture visibility. - Security Telemetry & Detection - Build and maintain security monitoring pipelines that ingest signals from infrastructure, networking, and platform components. - Improve signal quality from SIEM platforms by developing correlation rules, enrichment pipelines, and automated triage workflows. - Integrate security telemetry with platform observability systems to provide a unified view of infrastructure health and security posture. - AI-Assisted Security Operations - Design and implement AI-assisted security workflows that analyze security telemetry and incident signals. - Develop AI agents that help: - Summarize security alerts, - Correlate events across systems, - Detect anomaly patterns, - Assist operators during incident investigations. - Use machine learning or LLM-based tooling to reduce alert fatigue and accelerate incident triage. - Compliance & Security Governance - Help ensure platform security controls meet customer and regulatory requirements. - Contribute to security policies and operational procedures. - Help define measurable security metrics and compliance validation processes. Technical Stack - Security Monitoring & Detection - Wazuh. - Snort IDS/IPS. - TheHive. - Cortex. - Security Infrastructure - Wazuh SIEM. - HashiCorp Vault. - HashiCorp Boundary. - Tailscale. - Identity & Access - PKI infrastructure. - IAM systems such as Authentik/KeyCloak. - Certificate lifecycle management. - Identity federation. - Secure Networking - Zero-trust networking models. - Encrypted network transport. - Network segmentation technologies. - Citrix NetScaler. - Platform Security - Kubernetes security. - Container runtime security. - Infrastructure hardening. - Security Automation - Python / Go. - Security automation frameworks. - Incident response automation. Qualifications - 7+ years of experience in cloud security or infrastructure security engineering. - Experience securing large-scale distributed infrastructure platforms. Requirements - Strong understanding of security architecture in cloud environments. - Experience securing Kubernetes and containerized platforms. - Familiarity with multi-tenant infrastructure security models. - Experience implementing identity and access management systems. - Strong understanding of PKI, key management, and secure authentication systems. - Understanding of datacenter networking security concepts. - Familiarity with segmentation, tenant isolation, and zero-trust networking. - Experience with SIEM platforms and security telemetry. - Ability to triage vulnerabilities and investigate incidents. - Experience building security automation workflows. Benefits - Attractive compensation package reflecting your expertise and experience. - A great work environment characterised by friendliness, international diversity, flexibility, and a hybrid-friendly approach. - You'll be part of a fast-growing scale-up with a mission to make a positive impact, offering an exciting career evolution. - Our job titles may span more than one job level. The actual base pay is dependent on a number of factors, such as transferable skills, work experience, business needs and market demands. Company Description Radian Arc, now part of InferX, Submer's AI cloud and GPU infrastructure platform, provides an infrastructure-as-a-service (IaaS) platform for running cloud gaming, artificial intelligence and machine learning applications inside telecommunication carrier networks. Our teams across the USA, Australia, Central Europe, Malaysia, Singapore and Japan offer telecom operators a GPU-based edge computing platform without the need for capital expenditure, facilitating low latency and improved economics for value-added services and the monetization of 5G investments.

Related Categories

Related Job Pages

More Platform Engineer Jobs

Platform Networking Engineer

Bright Vision Technologies

Bright Vision Technologies is a forward-thinking software development company dedicated to building innovative solutions that help businesses automate and optimize their operations. We leverage cutting-edge technologies to create scalable, secure, and user-friendly applications.

Role Description This is a fantastic opportunity to join an established and well-respected organization offering tremendous career growth potential. We are looking for a Service Mesh Engineer to design, deploy, and operate service mesh platforms — primarily Istio and Linkerd — that provide secure, observable, and reliable service-to-service communication across our Kubernetes estate. The role focuses on platform engineering, mesh adoption, mTLS, traffic policy, and helping application teams reap the benefits of a mesh without paying for unnecessary complexity. The ideal candidate has operated service mesh in production, deeply understands Envoy and the data plane, and brings both platform engineering discipline and pragmatic adoption strategies. Key Responsibilities - Design and operate service mesh platforms — primarily Istio and Linkerd — across multi-cluster Kubernetes environments. - Implement and operate mTLS, certificate rotation, and identity propagation across the mesh. - Define traffic management policies including routing, retries, circuit breaking, and fault injection. - Integrate the mesh with ingress, egress, and API gateway tiers for unified traffic management. - Build observability for mesh traffic including distributed tracing, golden signals, and topology visualization. - Design multi-cluster and cross-cluster mesh topologies for high availability and tenant isolation. - Profile and optimize mesh performance, sidecar resource usage, and control-plane footprint. - Develop paved-road adoption patterns and onboarding guides that make mesh adoption easy for app teams. - Implement authorization policies and zero-trust patterns at the service mesh layer. - Operate service mesh upgrades, control-plane lifecycle management, and configuration governance. - Partner with SRE, platform, and security teams on mesh policy and incident response. - Troubleshoot complex networking, mTLS, and traffic issues spanning sidecar and gateway tiers. - Maintain runbooks, architecture diagrams, and onboarding materials for the service mesh platform. - Stay current with Istio, Linkerd, Cilium, and broader service mesh ecosystem developments. Qualifications - Bachelor’s degree in Computer Science or a related field. - Five or more years of experience in platform engineering, SRE, or networking roles. - Hands-on experience operating Istio or Linkerd in production. - Strong understanding of Envoy proxy internals and configuration. - Deep Kubernetes expertise including networking, CNI, and ingress. - Strong understanding of mTLS, PKI, and certificate lifecycle management. - Experience with distributed tracing and observability for mesh traffic. - Proficiency in Go or Python for tooling and automation. - Strong troubleshooting skills across networking, application, and control plane layers. - Excellent communication and collaboration skills. Preferred Qualifications - Experience with multi-cluster Istio or Linkerd deployments. - Familiarity with Cilium service mesh and eBPF networking. - Open-source contributions to service mesh projects. - Experience with SPIFFE/SPIRE for workload identity. - Exposure to zero-trust networking initiatives at enterprise scale. How to Apply Would you like to know more about this opportunity? For immediate consideration, please send your resume to [email protected] or contact us at (908) 676-4399. Learn more about Bright Vision Technologies at www.bvteck.com . Equal Employment Opportunity (EEO) Statement Bright Vision Technologies (BV Teck) is committed to equal employment opportunity (EEO) for all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, veteran status, or any other protected status as defined by applicable federal, state, or local laws. This commitment extends to all aspects of employment, including recruitment, hiring, training, compensation, promotion, transfer, leaves of absence, termination, layoffs, and recall. BV Teck expressly prohibits any form of workplace harassment or discrimination. Any improper interference with employees' ability to perform their job duties may result in disciplinary action up to and including termination of employment.

United States
$100K - $150K / year
SentinelOne logo

Senior Staff AI Platform Engineer

SentinelOne

Secure your enterprise with the autonomous cybersecurity platform. Endpoint. Cloud. Identity. XDR. Now.

Full TimeRemoteTeam 1,001-5,000Since 2013H1B Sponsor

• Design, build, and operate components of the AI Gateway including centralized identity and authentication/authorization, token budgeting, DLP and content guardrails, multi-model routing and failover, MCP allow-listing, and request-level audit logging. • Build and maintain pieces of the Harness layer including agent orchestration (LangGraph or equivalent), prompt construction and context management, memory and state handling across multi-turn interactions, and model abstraction across providers such as AWS Bedrock and Google Vertex. • Develop and extend production services in Python (FastAPI) and pydantic.ai for LLM-powered components, and contribute to the React/TypeScript surfaces that expose platform capabilities to internal teams. • Implement MCP/tool wiring for internal and SaaS-embedded agents, ensuring every caller regardless of origin passes through the same policy controls. • Contribute to the Claude and Gemini Enterprise plugin framework by building, testing, and hardening role-based skills and agents, and help mature the pipeline for how plugins are authored, evaluated, and deployed. • Instrument the platform for observability including metrics, tracing, and audit trails, and participate in on-call and operational support for platform services. • Write clear technical documentation and participate in architecture and code reviews, holding a high bar for quality, security, and maintainability. • Partner with engineers across Enterprise Data, Enterprise Apps, Product Development, and Infosec to integrate the platform with governed data sources and shared architectural contracts. • Work with the Sr. Director and model evaluation tooling to help close the loop between evaluation results and model selection, prompt tuning, and routing decisions.

United States
$184K - $253K / year
Juniper Square logo

Principal Engineer – Platform

Juniper Square

Where partnerships drive potential.

Full TimeRemoteTeam 201-500H1B No Sponsor

• Operates as the Directly Responsible Individual (DRI) for high-impact initiatives; takes full ownership of project health, system design, and end-to-end delivery. • Partners closely with Product Management and cross-functional teams to clarify ambiguous requirements, map business goals to technical scopes, and manage dependencies. • architectural design, pragmatic task breakdown, and execution planning, driving a team of engineers toward incremental deliverables. • Establish reusable patterns, technical standards, and platform primitives that other teams can build on. • Improve engineering efficiency through better tooling, automation, documentation, observability, and developer workflows. • Mentor engineers, raise the quality of technical decision-making, and help the team execute with consistency. • Drives adoption of AI tooling across the SDLC — building internal capabilities that automate engineering workflows while ensuring security, compliance, and best-practice alignment.

India
Bydrec, Inc. logo

Senior Full Stack Engineer – Video Platform

Bydrec, Inc.

Your Nearshore Tech Augmentation Partner

ContractRemoteTeam 51-200Since 2016H1B No Sponsor

• Develop and maintain full-stack applications using JavaScript, TypeScript, Node.js, and React. • Design and build scalable backend services, APIs, and asynchronous workflows. • Work with browser-based technologies and complex frontend application flows. • Develop applications operating in cloud-native and containerized environments. • Troubleshoot and resolve production issues across frontend, backend, databases, and infrastructure. • Optimize application performance, scalability, reliability, and security. • Work with SQL databases, including schema design, migrations, indexing, and query optimization. • Participate in architecture discussions, code reviews, and technical design sessions. • Write clean, maintainable, and well-tested code. • Improve system observability through monitoring, logging, dashboards, and operational documentation. • Collaborate with globally distributed engineering teams. • Mentor other engineers and contribute to engineering best practices. • Leverage AI-assisted development tools responsibly to improve productivity and code quality.

Mexico