SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Platform Security Engineer (Security)

Phantom - Remote - Remote - posted 2026-09-16

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 200,000 - 250,000 / annual

Phantom is a fintech platform enabling tens of millions of users worldwide to access global markets including perpetuals, prediction markets, tokenized assets, stablecoins, and memes. The company has achieved #1 ranking in Google Play's finance category and partners with trusted names like Hyperliquid, Stripe, Kalshi, and Visa. Phantom is fully remote, ~180 people, backed by $150M Series C funding from a16z, Sequoia Capital, and Paradigm. You will own and improve security across Phantom's AWS and Kubernetes environments, working directly with infrastructure and engineering teams to secure control planes, identities, workloads, and deployment systems. This is a hands-on role requiring comfort with production systems, code writing, incident response, and security improvements that don't slow down product teams. Key responsibilities include: - AWS Security: Multi-account AWS environment security (IAM, Identity Center, networking, compute, storage, secrets, logging, organization-level guardrails) - Kubernetes Security: Production EKS cluster security (configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, tenant isolation) - Identity and Access: Design least-privilege access models for engineers, services, and automation with scoped, auditable, time-bound access paths - Mission-Critical Systems: Protect infrastructure handling sensitive data and high-value operations - Cloud Security Architecture: Lead security design for new infrastructure, platform services, and major architectural changes - Infrastructure and Policy as Code: Build reusable controls using Pulumi, Terraform, Kubernetes policy engines, and automated validation - CI/CD and Supply Chain Security: Harden build, deployment, and release systems including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, and provenance - Security Automation: Build tools identifying and remediating cloud and Kubernetes risks at scale; apply AI-assisted workflows for improved analysis, coverage, or response speed - Cross-Functional Leadership: Partner with Infrastructure, SRE, Developer Experience, and product engineering teams to establish and adopt platform-security standards Phantom is building an AI-native security team that aggressively uses AI to expand speed, depth, and reach of security work. The role emphasizes high agency, identifying risks that matter, building practical controls, and owning problems through verified remediation. REQUIREMENTS: - 7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or closely related engineering role - Deep, hands-on experience securing production AWS environments (IAM, resource policies, workload identity, network security, secrets management, logging, organization-level controls, failure modes) - Deep experience securing Kubernetes in production, preferably Amazon EKS (RBAC, workload identity, admission policy, network policy, pod security, secrets, cluster hardening) - Experience designing or securing mission-critical systems where compromise, excessive privilege, or loss of availability could have significant customer or business impact - Strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction across human and machine access - Experience securing CI/CD and software supply chains (GitHub Actions or similar, build runners, workload federation, artifacts, production deployment paths) - Experience writing and reviewing infrastructure as code (Pulumi, Terraform, CloudFormation, or similar) - Ability to write production-quality code or automation in TypeScript, Python, Go, or Rust - High agency and ownership; ability to take ambiguous platform-security problems from investigation through implementation and verified remediation - Clear communication and strong track record partnering with infrastructure and engineering teams while maintaining high security bar NICE TO HAVES: - AWS Nitro Enclaves or other trusted execution environments (attestation, isolation boundaries, secure key handling, operational lifecycle) - Experience securing financial, payments, wallet, custody, or high-value transaction systems - Key-management infrastructure, AWS KMS, CloudHSM, cryptographic signing systems, or secrets-management platforms - Multi-region Kubernetes and AWS environments at significant scale - Service meshes and cloud-native networking (Istio, PrivateLink, Transit Gateway, eBPF-based controls) - GitHub OIDC, Argo CD, Helm, Crossplane, or Kubernetes-based infrastructure delivery - Cloud-security and observability platforms (Wiz, Datadog, GuardDuty, Security Hub, CloudTrail) - Policy-as-code, automated remediation, or security tooling for large engineering organizations - Blockchain infrastructure or self-custodial wallet architecture

Similar roles