Staff Platform Security Engineer (Security)
What security roles in crypto pay
64 salaries · our own dataThis role pays $200k-$250k, above the $202k median for security roles in crypto on this board.
As a Staff Platform Security Engineer at Phantom, you own and improve security across AWS and Kubernetes environments that protect tens of millions of users accessing global markets. You work directly with infrastructure and engineering teams to secure control planes, identities, workloads, and deployment systems behind Phantom's most critical products. This is a hands-on role where you identify risks that matter, build practical controls, and own problems through verified remediation without slowing down the teams building on the platform.
What you'll do
- Own and improve security across Phantom's multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails.
- Secure production Kubernetes environments running on Amazon EKS, including cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation.
- Design least-privilege access models for engineers, services, and automation, building scoped, auditable, and time-bound access paths for sensitive production systems.
- Protect infrastructure supporting products and services that handle sensitive data and high-value operations.
- Lead security design for new infrastructure, platform services, and major architectural changes.
- Build reusable security controls using tools such as Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation.
- Harden build, deployment, and release systems, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and access to production environments.
- Build tools that identify and remediate cloud and Kubernetes risks at scale, applying AI-assisted workflows where they materially improve analysis, coverage, or response speed.
- Partner closely with Infrastructure, SRE, Developer Experience, and product engineering teams to establish practical platform-security standards and help teams adopt them.
What you bring
- 7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering role.
- Deep, hands-on experience securing production AWS environments, including IAM and resource policies, workload identity, network security, secrets management, logging, organization-level controls, and understanding how these systems fail in practice.
- Deep experience securing Kubernetes in production, preferably Amazon EKS, including RBAC, workload identity, admission policy, network policy, pod security, secrets, and cluster hardening.
- Experience designing or securing mission-critical systems where compromise, excessive privilege, or loss of availability could have significant customer or business impact.
- A strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction across both human and machine access.
- Experience securing CI/CD and software supply chains, including GitHub Actions or similar systems, build runners, workload federation, artifacts, and production deployment paths.
- Experience writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar tools.
- Ability to write production-quality code or automation in a language such as TypeScript, Python, Go, or Rust.
- High agency and ownership; you can take an ambiguous platform-security problem from initial investigation through implementation and verified remediation.
- Clear communication and a strong track record of partnering with infrastructure and engineering teams while maintaining a high security bar.
Nice to have
- Experience with AWS Nitro Enclaves or other trusted execution environments, including attestation, isolation boundaries, secure key handling, and operational lifecycle management.
- Experience securing financial, payments, wallet, custody, or other high-value transaction systems.
- Familiarity with key-management infrastructure, AWS KMS, CloudHSM, cryptographic signing systems, or secrets-management platforms.
- Experience operating or securing multi-region Kubernetes and AWS environments at significant scale.
- Familiarity with service meshes and cloud-native networking technologies such as Istio, PrivateLink, Transit Gateway, or eBPF-based controls.
- Experience with GitHub OIDC, Argo CD, Helm, Crossplane, or Kubernetes-based infrastructure delivery.
- Experience using cloud-security and observability platforms such as Wiz, Datadog, GuardDuty, Security Hub, or CloudTrail.
- Experience building policy-as-code, automated remediation, or security tooling used by a large engineering organization.
- Familiarity with blockchain infrastructure or self-custodial wallet architecture.
What we offer
- Base salary of $200,000 to $250,000 depending on skillset, experience, interview performance, and market factors such as location.
- Equity
- Eligibility to participate in the company's performance bonus program
- Comprehensive medical, dental, and vision insurance with 100% coverage
- Stipend for your ideal remote setup
- Flexible hours and a supportive remote environment
- Unlimited vacation
- 401(k) retirement plan
- Monthly wellness benefit
- Weekly meal benefit
- Global off-sites
About Phantom
Phantom is a financial app used by tens of millions of people worldwide to access global markets including perpetuals, prediction markets, tokenized assets, stablecoins and memes. Backed by a $150M Series C from a16z, Sequoia Capital and Paradigm, Phantom partners with trusted names like Hyperliquid, Stripe, Kalshi and Visa to make innovative financial products accessible to everyone. The company is fully remote with around 180 people.
