Deel
Palermo / Global
Palermo / Global
Overview
As Platform Security Architect you own the security of Deel’s platform across applications and cloud infrastructure, focused on AWS. You design secure patterns, lead tooling, and embed security into the SDLC to enable fast-moving teams. You influence engineering and leadership, shaping the defender role across code and cloud. You work with Privacy/Compliance to meet standards and drive secure-by-default systems at scale. This role combines hands-on security with strategic architecture.
Retribuzione / Benefits Stock grant opportunities
Optional flexible working office membership
Additional country-based perks
Competitive salary within USD range
Supportive, inclusive culture
Career growth opportunities
Responsabilità Own platform security architecture across applications, services, and cloud environments (AWS-focused)
Define secure design patterns, reference architectures, guardrails, and default baselines for teams
Lead security tooling program (Wiz, Aikido) for CSPM, SAST, SCA, secrets detection, containers, IaC, DAST
Design identity and access controls at all layers (IAM, just-in-time access, multi-tenant auth)
Embed security in SDLC and CI/CD pipelines with guardrails that block or warn builds
Secure containers and Kubernetes (image hardening, runtime protection, network policies)
Own software supply chain security (dependencies, SBOMs, build integrity, provenance)
Lead threat modeling and vulnerability management, coordinating with engineering for remediation
Lead platform security incident response and post-incident hardening
Partner with Privacy/Compliance to satisfy SOC 2 II, ISO 27001, PCI DSS, GDPR, ensuring auditable decisions
Scale security through a Security Champions program and secure coding enablement
Act as technical authority on platform security, influence leadership on security-forward strategy
Leverage AI to improve security posture and secure AI features
Requisiti fondamentali 5+ years in cybersecurity with cloud and application security depth
Deep AWS security expertise (IAM, network controls, logging, data protection)
Deep application security expertise (OWASP Top 10, API security)
Hands-on experience with Wiz, Aikido or alternatives (rollout, tuning, integration)
CI/CD gates for application code and IaC
Security for containers and Kubernetes (image hardening, RBAC)
Threat modeling experience (STRIDE etc)
Production code capability in TypeScript/Node.js, Python, Go, or Java
Secrets management (HashiCorp Vault, AWS Secrets Manager) and encryption patterns
Experience with vulnerability management or bug bounty programs
Knowledge of SOC 2 II, ISO 27001, PCI DSS, GDPR
Ability to translate security concepts into engineer-facing guidance
Excellent English communication
strong collaboration with cross-functional teams
clear written and verbal communication
risk-based decision making
AWS IAM design
CloudTrail, Security Hub, GuardDuty
Wiz, Orca, Prisma Cloud
Palermo / Global
Palermo / Global
Palermo / Global
Palermo / Global
Palermo / Global
Palermo / Global