Описание вакансии
Коротко о ролиResponsibilities AWS Security: Own and improve security across Phantom’s multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails. Identity and Access: Design least-privilege access models for engineers, services, and automation.
Phantom is a fintech company developing the multichain crypto wallet Phantom, popular in the Web3 industry. The company operates fully remote with about 180 employees and is backed by a $150M Series C investment.
Responsibilities:
— Own and improve security across Phantom’s multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails.
— Secure production Kubernetes environments on Amazon EKS, including cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation.
— Design least-privilege access models for engineers, services, and automation.
— Build scoped, auditable, and time-bound access paths for sensitive production systems.
— Protect infrastructure supporting products handling sensitive data and high-value operations.
— Lead security design for new infrastructure, platform services, and major architectural changes.
— Build reusable security controls using Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation.
— Harden CI/CD and supply chain security including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and production environment access.
— Build security automation tools to identify and remediate cloud and Kubernetes risks at scale.
— Apply AI-assisted workflows to improve analysis, coverage, or response speed.
— Partner with Infrastructure, SRE, Developer Experience, and product engineering teams to establish practical platform-security standards.
Qualifications:
— 7+ years experience in platform security, cloud security, infrastructure security, security engineering, or related roles.
— Deep hands-on experience securing production AWS environments, including IAM, resource policies, workload identity, network security, secrets management, logging, and organization-level controls.
— Deep experience securing Kubernetes in production, preferably Amazon EKS, including RBAC, workload identity, admission policy, network policy, pod security, secrets, and cluster hardening.
— Experience designing or securing mission-critical systems with significant customer or business impact.
— Strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction.
— Experience securing CI/CD and software supply chains, including GitHub Actions or similar systems.
— Experience writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar tools.
— Ability to write production-quality code or automation in TypeScript, Python, Go, or Rust.
— High agency and ownership with ability to take ambiguous platform-security problems through to verified remediation.
— Clear communication and strong partnership skills with infrastructure and engineering teams.
Nice to Haves:
— Experience with AWS Nitro Enclaves or other trusted execution environments.
— Experience securing financial, payments, wallet, custody, or other high-value transaction systems.
— Familiarity with key-management infrastructure, AWS KMS, CloudHSM, cryptographic signing systems, or secrets-management platforms.
— Experience operating or securing multi-region Kubernetes and AWS environments at scale.
— Familiarity with service meshes and cloud-native networking technologies such as Istio, PrivateLink, Transit Gateway, or eBPF-based controls.
— Experience with GitHub OIDC, Argo CD, Helm, Crossplane, or Kubernetes-based infrastructure delivery.
— Experience using cloud-security and observability platforms such as Wiz, Datadog, GuardDuty, Security Hub, or CloudTrail.
— Experience building policy-as-code, automated remediation, or security tooling used by large engineering organizations.
— Familiarity with blockchain infrastructure or self-custodial wallet architecture.
Conditions:
— Fully remote role open only to candidates based in the US and Canada.
— Competitive salary range $200,000 to $250,000 per year plus equity and benefits.
— Benefits include performance bonus program, comprehensive medical/dental/vision insurance with 100% coverage, stipend for remote setup, flexible hours, unlimited vacation, 401(k) plan, monthly wellness and weekly meal benefits, and global off-sites.
Phantom encourages candidates of all backgrounds to apply and is committed to building an inclusive and supportive workplace.
Контакты работодателя доступны по кнопке «Откликнуться» после входа.