SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Mondoo is building a platform that helps companies protect their users and data from security threats. The company combines strong user experience and visual design with powerful security capabilities.
As a Senior Platform Engineer, you will directly impact Mondoo's core platform, including the policy engine, resource management, scaling, and multi-region functionality. You'll help teams assess, scope, prioritize, triage, and remediate security findings across cloud and on-premises environments.
Key Responsibilities:
- Build, manage, and optimize cloud infrastructure using Infrastructure as Code (IaC) tools such as Terraform and CloudFormation
- Automate system configurations using Ansible, Puppet, or Chef
- Collaborate with cross-functional teams to integrate infrastructure seamlessly with CI/CD pipelines
- Translate high-level security requirements into practical policy-as-code implementations for cloud and on-premises environments
- Review vulnerability reports submitted by external users
- Gather evidence for compliance audits
- Support implementation and scaling of automated security controls in Kubernetes, AWS, Azure, GCP, and operating systems
- Stay current with infrastructure management and automation trends to maintain robust, scalable systems
You will work with cutting-edge technologies and gain hands-on experience in policy-as-code frameworks while contributing to a dynamic security-focused team.
Required Qualifications:
- Strong hands-on experience with IaC tools (Terraform or CloudFormation)
- Proficiency in configuration management tools (Ansible, Puppet, or Chef)
- Solid understanding of at least one major cloud platform (AWS, Azure, or GCP) and its core services
- Experience with container technologies (Docker) and orchestration tools (Kubernetes)
- Comfortable scripting in at least one language (Python, Bash, or similar)
- Knowledge of networking basics (TCP/IP, DNS, etc.)
- Experience with version control systems (Git)
- Strong problem-solving and analytical skills
- Willingness to learn and grow into a role focused on security policies and automation
- Excellent communication skills and ability to work effectively in collaborative team environments
- Ability to handle ad-hoc requests while maintaining other work priorities
Preferred Qualifications:
- Familiarity with security tools and policy-as-code frameworks (Open Policy Agent, Sentinel)
- Knowledge of compliance standards (CIS, SOC 2, ISO 27001)
- Previous exposure to cloud-native security tools and services
- Relevant certifications in cloud platforms (AWS, Azure, GCP)
- Keen interest in learning security best practices, frameworks, and tools
As part of the application, candidates should share GitHub/GitLab repositories or a portfolio demonstrating experience with security policy implementation, policy-as-code, and cloud security tools, particularly examples showing the ability to translate complex security requirements into executable code for cloud environments.