Website:
phinite.ai
Job details:
Platform Security Engineer (3+ years)
About Phinite.ai
Phinite.ai is an early-stage company building a platform for running AI agents in production, with evaluation, guardrails, governance and observability built in. We work with enterprise customers, so security is central to what we ship.
About the role
We're looking for a Security Engineer who enjoys owning security problems end to end and building security into the product and infrastructure instead of treating it as a checklist.
You'll work across our backend, cloud infrastructure, applications, identity systems, data and developer platform. This role goes beyond running scanners and writing reports. You'll identify real risks, design practical defenses, investigate incidents and work directly with engineers to make the whole system more secure, with meaningful ownership over security across the product and engineering stack.
What you'll do
• Own security initiatives from threat identification and design through implementation, monitoring and continuous improvement
• Run threat modeling for new products, services, APIs, infrastructure and major architectural changes
• Find and fix vulnerabilities across applications, infrastructure, cloud environments, dependencies, containers and CI/CD pipelines
• Work with backend and infrastructure engineers to build security in from the start
• Design and improve authentication, authorization, identity, session management, secrets management and access control
• Review APIs and distributed services for access control, data exposure, injection, abuse and other risks
• Secure cloud infrastructure, networking, containers, Kubernetes, databases, queues, storage and internal services
• Build controls that hold up in real conditions: compromised credentials, privilege escalation, exposed secrets, compromised dependencies and misconfiguration
• Run vulnerability management: prioritization, remediation, verification and tracking
• Improve security monitoring, detection, alerting and incident response
• Lead security incidents from detection through containment, root-cause analysis, remediation and prevention
• Automate security checks such as secrets detection, dependency scanning and access reviews
• Give engineers practical remediation guidance, not just a list of findings
• Establish secure engineering patterns and tooling that make the secure path the easy path
• Join architecture discussions and challenge designs when security matters
What we're looking for
• 3+ years of experience securing production applications and infrastructure
• Strong fundamentals in application, infrastructure and cloud security
• Strong understanding of authentication, authorization, identity, access control, sessions, secrets and cryptography
• Strong knowledge of common web and API vulnerabilities, including the OWASP Top 10
• Strong understanding of network security: TLS, DNS, firewalls, proxies, load balancers and service-to-service communication
• Ability to read an architecture, identify realistic attack paths and propose practical mitigations
• Experience determining the real impact and exploitability of vulnerabilities
• Strong grasp of least privilege, defense in depth and secure defaults
• Good understanding of distributed systems and the security problems they introduce
• Ability to tell meaningful risks from theoretical issues, and to explain risk clearly without security theater
• Comfort with ambiguity and making decisions on incomplete information
• Strong ownership mindset, following difficult problems through to resolution
Nice to have
• Cloud security on AWS, GCP, Azure or similar
• Kubernetes and container security
• IAM systems and identity platforms
• OAuth 2.0, OpenID Connect, JWT, API keys, service accounts and workload identity
• Application security testing, penetration testing or red-team experience
• SAST, DAST, SCA, container scanning, secrets detection and vulnerability-management platforms
• SIEM, security monitoring or detection engineering
• Incident response and digital forensics
• CI/CD and software supply-chain security
• Infrastructure-as-code security
• Key management and cryptographic systems
• Securing PostgreSQL, MongoDB, Redis and Kafka
• Building security tooling in Go, TypeScript, Python or similar
• Experience at an early-stage or high-growth startup
Tech stack
We believe most technologies can be learned when needed, but familiarity with these is a big plus: Go / TypeScript / Python, Linux, Docker / Kubernetes, AWS / GCP / Azure, PostgreSQL / Redis, Kafka, Terraform, GitHub Actions / GitLab CI / ArgoCD, OAuth 2.0 / OpenID Connect / JWT, Prometheus / Grafana / OpenTelemetry / SIEM tooling, and secrets management and KMS systems.
What we value
• Ownership over handoffs: you don't just report a vulnerability, you help drive it to resolution
• Real security over compliance theater: we care about actual attack paths and whether our controls work
• Secure by design: security belongs in the design, not just after deployment
• Practical security over unnecessary friction: not every theoretical issue deserves a six-week project
• Defense in depth and least privilege
• Detection and response: we don't assume prevention is perfect
• Engineering judgment over blindly following frameworks: standards are tools, not substitutes for understanding our architecture and threat model
This may not be the role for you if
• You want a narrow role that ends once vulnerability tickets are filed
• You see security mainly as a compliance or documentation exercise
• You rely on automated scanners without understanding what they detect
• You report vulnerabilities without understanding their exploitability, impact or fix
• You're uncomfortable reading backend code, infrastructure configuration or system architecture
• You're uncomfortable with Linux, networking, APIs, databases, containers or cloud infrastructure
• You believe adding a WAF or a security product makes an application secure
• You rely on AI-generated security configurations without understanding their implications
• You'd leave a known security issue open because it belongs to another team
How to apply
- Please send your resume and a short cover letter explaining why you're a strong fit for this role to careers@phinite.ai with the subject line "Application for Platform Security Engineer role - [Your Name]".
Click on Apply to know more.