Senior Security Platform Engineer

Equinox•New York, NY
•$145,000 - $175,000•Hybrid

About The Position

We are looking for a senior engineer who can operate at the intersection of cloud infrastructure, platform engineering, and security operations. This is a hybrid role for an engineer who is equally comfortable debugging a Terraform module, tuning a SIEM detection rule, and leading an incident response investigation. You'll be a primary technical escalation point for both platform reliability and security incidents across all cloud environments.

Requirements

  • 5+ years of experience in infrastructure/platform engineering, with hands-on production ownership in multi-account cloud environments
  • Strong Terraform/IaC experience, including authoring and maintaining shared modules
  • Experience operating a SIEM platform (Elastic Security preferred) — log ingestion, detection engineering, and alerting
  • Solid networking fundamentals: load balancers, security groups, WAF, DNS, CDN
  • Experience with identity providers (Entra ID/Azure AD, Okta, or similar) and authentication/authorization concepts (SSO, SAML, MFA, conditional access)
  • Demonstrated experience leading or heavily contributing to security incident response
  • Comfortable being a hands-on technical escalation point across multiple teams simultaneously
  • Working familiarity with application security practices across modern web/mobile and backend stacks (e.g., React/React Native, Node.js, Java/Spring Boot, Python/Flask) — able to read code, understand architecture, and identify security risk even if not writing production application code day-to-day

Nice To Haves

  • Proven experience with AWS, GCP and Azure
  • Familiarity with payments security concepts (fraud scoring, PCI-adjacent systems, payment gateway risk tools such as Adyen)
  • Experience with container orchestration (ECS or similar)
  • Experience mentoring SOC analysts or junior engineers
  • Familiarity with CSPM/vulnerability management tooling (e.g., Wiz, CrowdStrike)
  • Hands-on development or code review experience in React Native, React Web, Node.js, Spring Boot/Java, or Python/Flask
  • Experience with SAST/SCA tooling (e.g., GitHub Advanced Security, Snyk, SonarQube) and integrating security scanning into CI/CD
  • Familiarity with AI/LLM security concepts (prompt injection, data leakage, model access control) and securing AI-powered product features or internal AI tooling

Responsibilities

  • Own and maintain infrastructure-as-code across (e.g., Terraform) cloud providers, including shared modules used by application teams org-wide
  • Manage IAM users, keys, and secrets lifecycle (rotation, storage in Parameter Store/Secrets Manager, cross-environment consistency)
  • Diagnose and resolve production networking and infrastructure issues: load balancer health checks, security groups, WAF rules, CDN and origin access, DNS, and container orchestration
  • Administer access across supported platforms (e.g., AWS, GCP, GitHub, etc.) and internal developer tooling
  • Evaluate and integrate third-party platform/security tooling (e.g., CSPM, code security scanners)
  • Support CI/CD pipelines and troubleshoot build/deploy failures
  • Own and operate the organization's Elastic Security (SIEM) platform end-to-end: cluster upgrades, agent/integration management, and log ingestion pipelines (cloud audit logs, identity provider logs, payment/fraud logs, WAF logs)
  • Design, build, and tune detection rules and alerting workflows, including integrating SIEM alerts into team communication channels (e.g., Slack)
  • Continuously improve signal quality by resolving log parsing errors, refining index patterns, and reducing false positives
  • Maintain technical documentation for logging architecture and detection rule logic
  • Provide technical leadership and day-to-day oversight for the SOC team, including prioritization, escalations, investigation quality and mentoring
  • Serve as a senior escalation point for the SOC, guiding and mentoring analysts through investigations
  • Lead investigations into anomalous authentication activity, account compromise, and suspicious network traffic, including coordinating remediation (session revocation, credential resets, user outreach)
  • Develop and maintain incident response runbooks and reference documentation
  • Build and maintain WAF-based detection and mitigation capabilities (e.g., fingerprint- and IP-based blocking of malicious/fraudulent traffic)
  • Drive identity governance initiatives, including cloud identity reconciliation (e.g., managed vs. unmanaged accounts) and license/access audits
  • Design and implement authentication hardening measures: conditional access policies, MFA/authentication strength requirements, and legacy protocol deprecation (e.g., legacy SMTP auth)
  • Partner with IT/security leadership on identity provider strategy and vendor licensing decisions
  • Hold end-to-end security ownership across the organization's core application stack, spanning front-end (React Native, React Web), back-end (Node.js, Spring Boot/Java, Python/Flask), and AI/ML systems
  • Review code and architecture for security vulnerabilities (e.g., dependency/supply-chain risk, secrets handling, authN/authZ flaws, insecure API design) across mobile, web, and service layers
  • Partner with application engineering teams to embed security requirements into the SDLC — secure coding standards, PR review gates, and CI/CD security scanning (SAST/SCA/secrets detection)
  • Triage and drive remediation of vulnerabilities surfaced by code scanning and vulnerability management tooling (e.g., Wiz, GitHub Advanced Security) across the full technology stack
  • Maintain visibility into third-party/open-source dependency risk (npm, Maven/Gradle, pip) and coordinate patching for critical CVEs
  • Serve as the security point of contact for engineering teams building on React Native, React Web, Node.js, Spring Boot, and Python/Flask, ensuring consistent security posture regardless of language/framework
  • Own the security posture of AI/ML systems and LLM-powered features: model access controls, data governance for training/prompt data, prompt injection and jailbreak risk, and secure integration with third-party AI APIs and vendors
  • Evaluate and vet AI coding assistants and internal AI tooling for data exposure, IP leakage, and supply-chain risk before organization-wide adoption
  • Define and maintain security guardrails/review processes for teams building AI-powered features or agents, including monitoring for anomalous or abusive usage patterns
  • Partner with risk and payments teams to investigate and mitigate payment fraud (e.g., card-testing/BIN attacks, risk-scoring anomalies in third-party payment platforms)
  • Analyze and recommend changes to fraud risk rules, allow-lists, and risk profiles
  • Track and help prioritize security remediation tickets related to payment endpoints

Benefits

  • Competitive salaries
  • Benefits
  • Industry leading commission opportunities for club employees
  • Complimentary Club membership
  • Perks and incentives with our products and services including Personal Training, Pilates, Spa and Shop
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service