# Staff Platform Security Engineer (Security) at Phantom

- Company: Phantom
- What the company does: The self-custodial wallet for trading predictions, perps, and tokens across Solana, Ethereum, Bitcoin, Robinhood, HyperEVM, and more. Backed by Lightspeed and Sequoia.
- Company website: https://phantom.com/
- Type: Startups
- Level: Senior
- Location: Remote
- Work setup: Remote
- Pay: $200K to $250K base salary per year (USD)
- Posted: 2026-09-16
- Apply by: 2026-10-31
- Apply: https://jobs.ashbyhq.com/phantom/504baea1-48c7-458d-9f45-36e24dbf7035
- Page: https://www.1752.vc/careers/jobs/phantom-staff-platform-security-engineer-security/

## About the role

AWS Security: Own and improve security across Phantom’s multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails. Kubernetes Security: Secure production Kubernetes environments running on Amazon EKS, including cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation.

## What they're looking for

- 7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering role
- Deep, hands-on experience securing production AWS environments. You understand IAM and resource policies, workload identity, network security, secrets management, logging, organization-level controls, and the ways these systems fail in practice
- Deep experience securing Kubernetes in production, preferably Amazon EKS, including RBAC, workload identity, admission policy, network policy, pod security, secrets, and cluster hardening
- Experience designing or securing mission-critical systems where compromise, excessive privilege, or loss of availability could have significant customer or business impact
- Strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction across both human and machine access
- Experience securing CI/CD and software supply chains, including GitHub Actions or similar systems, build runners, workload federation, artifacts, and production deployment paths

Tags: Engineering
