Platform Security Architect
Deel
ph3Who We Are Is What We Do. /h3 pDeel is the all-in-one payroll and HR platform for global teams. Our vision is to unlock global opportunity for every person, team, and business. Built for the way the world works today, Deel combines HRIS, payroll, compliance, benefits, performance, and equipment management into one seamless platform. With AI-powered tools and a fully owned payroll infrastructure, Deel supports every worker type in 150+ countries—helping businesses scale smarter, faster, and more compliantly. /p h3Who We Are Is What We Do. /h3 pDeel is the all-in-one payroll and HR platform for global teams. Our vision is to unlock global opportunity for every person, team, and business. Built for the way the world works today, Deel combines HRIS, payroll, compliance, benefits, performance, and equipment management into one seamless platform. With AI-powered tools and a fully owned payroll infrastructure, Deel supports every worker type in 150+ countries—helping businesses scale smarter, faster, and more compliantly. /p h3Why should you be part of our success story? /h3 pAs the fastest-growing Software as a Service (SaaS) company in history, Deel is transforming how global talent connects with world-class companies – breaking down borders that have traditionally limited both hiring and career opportunities. We're not just building software; we're creating the infrastructure for the future of work, enabling a more diverse and inclusive global economy. In 2024 alone, we paid $11.2 billion to workers in nearly 100 currencies and provided healthcare and benefits to workers in 109 countries—ensuring people get paid and protected, no matter where they are. /p pOur momentum is reflected in our achievements and customer satisfaction: CNBC Disruptor 50, Forbes Cloud 100, Deloitte Fast 500, and repeated recognition on Y Combinator's top companies list – all while maintaining a 4.83 average rating from 15,000 reviews across G2, Trustpilot, Captera, Apple and Google. /p pYour experience at Deel will be a career accelerator. At the forefront of the global work revolution, you'll tackle complex challenges that impact millions of people's working lives. With our momentum—backed by a $17.3 billion valuation and $1 B in Annual Recurring Revenue (ARR) in just over five years—you'll drive meaningful impact while building expertise that makes you a sought-after leader in the transformation of global work. /p pDeel is seeking a Platform Security Architect to own the security of our platform from the code our engineers write to the cloud it runs on. In this role, you'll design, build, and evolve the security architecture across two layers that can't be secured in isolation: our applications and services, and the AWS and Kubernetes infrastructure beneath them. This is a hands‑on, high‑impact position at the core of Deel's security engineering function, not a governance or advisory seat. /p pD /p peel operates in over 100 countries, processes payroll for tens of thousands of companies, and handles sensitive employee and financial data at scale. Hundreds of engineers ship to that platform every day. Most real‑world breaches cross the line between application and infrastructure: a leaked secret in code opens a cloud account, an over‑permissioned workload turns a small bug into a data breach. We need one architect who sees the whole path. You'll partner closely with Engineering, Infrastructure, Product, and Privacy/Compliance to build systems that are secure by default, without becoming a bottleneck to the fast‑moving teams that depend on you. /p h3Responsibilities /h3 ul liOwn the platform security architecture strategy across Deel's applications, services, and cloud environments, with a primary focus on AWS. Define secure design patterns, reference architectures, guardrails, and baseline configurations that teams build against by default. /li liRun Deel's security tooling as one program. Operate and tune Wiz for cloud posture (CSPM) and runtime visibility, and Aikido for SAST, SCA, secrets detection, container, IaC, and DAST scanning. Connect findings across code and cloud so the team fixes what is actually exploitable, not what is merely noisy. /li liDesign identity and access at every layer. Own least‑privilege cloud IAM (cross‑account roles, permission boundaries, SCPs, just‑in‑time access) and application authentication and authorization (session and token handling, multi‑tenant isolation, object‑level access control). /li liEmbed security into the SDLC and CI/CD pipelines. Build the guardrails for application code and Infrastructure as Code alike, with a clear model for what blocks a build and what warns. /li liSecure containers and Kubernetes. Set the standards for image hardening and signing, admission control, pod security, network policies, secrets management, and runtime protection. /li liOwn software supply chain security. Cover dependency and transitive risk, malicious package detection, SBOMs, build integrity, and artifact provenance, from the first npm install to the running workload. /li liLead threat modeling for new and existing systems, and make it part of how engineering designs software rather than a security‑team ritual. /li liRun vulnerability management for findings from scanners, pentests, and bug bounty: triage, exploitability assessment, SLAs, remediation partnership with engineering, and reporting on risk reduction over time. /li liLead platform security incident response across application and cloud layers: triage, containment, forensics, root cause analysis, and post‑incident hardening. /li liPartner with Privacy/Compliance so platform controls satisfy SOC 2 Type II, ISO 27001, PCI DSS, and GDPR, and design decisions stay defensible and auditable. /li liScale security through people. Build a Security Champions program and secure coding enablement so security knowledge spreads across engineering instead of pooling in the security team. /li liAct as the technical authority on platform security, reviewing high‑risk designs, evaluating vendors, and influencing engineering and cloud strategy at the leadership level. /li liUse Artificial Intelligence as an enabler to find new insights, learn from past mistakes, and continuously improve Deel's security posture, including securing the AI features Deel ships. /li /ul h3Qualifications /h3 ul li5+ years of hands‑on experience in cybersecurity, with real depth in both cloud security and application security engineering or architecture. /li liDeep AWS security expertise: IAM design, network controls, logging and monitoring (CloudTrail, Security Hub, GuardDuty), and data protection. /li liDeep application security expertise: OWASP Top 10 and API Security Top 10, authentication and authorization design, injection and deserialization, SSRF, business logic flaws, and secure session handling. /li liProven hands‑on experience operating security platforms such as Wiz (or Orca, Prisma Cloud) and Aikido (or Snyk, Semgrep, GitHub Advanced Security), including rollout, tuning, false‑positive reduction, and integration with engineering workflows. /li liStrong experience building security gates into CI/CD pipelines for both application code and Infrastructure as Code. /li liStrong experience securing containers and Kubernetes: image hardening, runtime security, pod security standards, and Kubernetes RBAC. /li liHands‑on threat modeling experience (STRIDE, attack trees, or equivalent) applied to real systems, with findings turned into concrete engineering work. /li liAbility to read, reason about, and write production code in at least one modern language (TypeScript/Node.js, Python, Go, or Java). /li liExperience with secrets management (HashiCorp Vault, AWS Secrets Manager) and encryption patterns for data at rest and in transit. /li liExperience running vulnerability management or a bug bounty/pentest program, and driving remediation across teams you don't manage. /li liStrong working knowledge of SOC 2 Type II, ISO 27001, PCI DSS, and GDPR. /li liAbility to turn complex security concepts into clear guidance for engineers and risk‑based recommendations for executives. /li liExcellent English, written and verbal. /li /ul h3Advantageous Experience /h3 ul liBackground in software engineering, DevSecOps, or platform engineering before moving into security. Credibility with engineers and the ability to ship fixes, not just file tickets. /li liOffensive security background (web/API or cloud penetration testing, exploit development, CTFs) used to inform defensive design. /li liExperience securing multi‑tenant SaaS at scale, including tenant isolation and EU data residency requirements. /li liExperience securing AI/LLM‑powered features (prompt injection, agent and tool abuse, data leakage) or applying AI to security workflows such as triage and automated remediation. /li liMulti‑cloud experience (GCP or Azure alongside AWS). /li liFamiliarity with eBPF‑based runtime tooling (Wiz, Cilium, Falco, or similar). /li liExperience building a Security Champions program or secure coding curriculum. /li liExperience in high‑growth fintech or global HR technology with complex regulatory requirements. /li liOpen‑source contributions, CVE credits, published research, or conference talks (OWASP Global AppSec, fwd:cloudsec, re:Inforce, BSides, Black Hat, DEF CON). /li liRelevant certifications: AWS Certified Security Specialty, OSWE, OSCP, GWAPT, CSSLP, CCSP, or CISSP. /li /ul h3Total Rewards /h3 pOur workforce deserves fair and competitive pay that meets them where they are. With scalable benefits, rewards, and perks, our total rewards programs reflect our commitment to inclusivity and access for all. /p ul liOur salary range reflects gross base salary. For commercial roles with commission eligibility, this figure represents On‑Target Earnings (OTE), inclusive of base salary and target commission. /li liSalary ranges are quoted in USD as a consistent global reference. Your offer will be localized to your country's currency using a market‑aligned conversion. /li liFinal pay is based on objective, job‑related criteria including experience, skills, and location. /li liWe don't ask about salary history. Offers are based on the role and what you bring to it. /li /ul h3Some things you'll enjoy /h3 ul liStock grant opportunities dependent on your role, employment status and location /li liAdditional perks and benefits based on your employment status and country /li liOptional flexible working office membership, with IWG /li /ul pAt Deel, we’re an equal‑opportunity employer that values diversity and positively encourage applications from suitably qualified and eligible candidates regardless of race, religion, sex, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, pregnancy or maternity or other applicable legally protected characteristics. /p pUnless otherwise agreed, we will communicate with job applicants using Deel‑specific emails, which include @deel.com and other acquired company emails like @payspace.com and @paygroup.com. You can view the most up‑to‑date job listings at Deel by visiting our careers page. /p pDeel welcomes persons with disabilities to apply to any of our open roles. We will provide application and/or interview accommodations on request throughout the recruitment, selection and assessment process for applicants with disabilities or other needs. If you require application and/or interview accommodations, please inform our Talent Acquisition Team via email ( ) and a team member will be in touch to ensure your equal participation. /p pAs part of our hiring process, we primarily rely on interviews and role‑related assessments. In limited cases, we may also consider informal background information relevant to the role, in line with our privacy and fairness obligations. /p pThis application process may utilise Automated Employment Decision Tools (AEDT) and AI systems to assist in evaluating candidates based on experience level, technical skills and qualifications. This processing is conducted in compliance with applicable Data Protection, AI Governance and Labour Laws. We ensure human oversight is maintained in all final hiring decisions. Your personal data is not used to train AI models. For more information on how we process your personal data, please see our Recruitment Privacy Policy. /p pFor NYC Residents: In accordance with NYC Local Law 144, an independent bias audit has been conducted on AEDT. /p /p #J-18808-Ljbffr
- pDeel is seeking a Platform Security Architect to own the security of our platform across applications and cloud infrastructure (AWS). You will... ...expertise across cloud and application security, container security, and secure development lifecycle practices. /p #J-18808-LjbffrConsigliato
- pNordex SE is seeking an accomplished ServiceNow Platform Architect to define and govern the enterprise ServiceNow architecture, roadmap, and... ...ITSM, ITOM, CMDB, and related modules. /ppThe role emphasizes secure, scalable, and high-performing platforms, with...Consigliato
- ph3Servicenow Platform Architect /h3 pCompany: Nordex SE /p pJob Title: ServiceNow Platform Architect /p pContract: Full-time /p pCountry: Italy... ...roadmap, and platform standards. The role ensures scalable, secure, and high-performing solutions aligned with enterprise...ConsigliatoTempo pieno
- pKyndryl is seeking an experienced Network and Security Architect to design, validate, and oversee architectures across on-premises, hybrid, and multi-cloud environments. You will ensure high availability, security, and governance while leading transformation initiatives...ConsigliatoLavoro ibrido
- ...implementation of network and security architectures across... ..., collaborating with Architects, Consult Partners,... ...Network and Security Architect in large‑scale production... ...architectures, secure network design, and operational... ...network automation platforms such as Ansible, AWX,...ConsigliatoLavoro ibridoOrario flessibile
50.000 €
...laterale degli attaccanti nei data center e nel cloud /li liArchitettare la sicurezza perimetrale moderna adottando soluzioni SASE (Secure Access Service Edge) e SSE (Security Service Edge) per proteggere dipendenti remoti e branch office /li liDefinire gli standard di...Lavoro ibridoRemotoOrario flessibile- Una realtà leader nel digitale cerca un Senior Network Security Engineer a Milano. Il candidato sarà responsabile della gestione di infrastrutture di rete sicure, implementando politiche di sicurezza per prevenire interruzioni di servizio. È richiesta esperienza con firewall...
- ...their team. You will support pre-sales, professional services and customer success, helping customers leverage the Hydrolix data platform across cloud environments. /ppYou will work with customers and partners to become a trusted advisor, drive successful deployments,...Remoto
46.400 €
ph3Data Platform Architect /h3 pSalary: €46,400 monthly /p pAzienda: Volkswagen /p pTipo Lavoro: Full Time /p pLocation: Italy /p h3Descrizione... ...data solutions, ensuring data is structured, integrated, secure, and accessible to authorized users. You will be responsible...Tempo pienoLavoro ibrido37.000 €
pstrongAI Platform Architect /strong /ppbr / /ppstrongRole Overview /strong /ppThe strongAI Platform Architect /strong is responsible for designing... ...enterprise AI platforms, enabling the delivery of scalable, secure, and production-ready AI solutions across multiple business...Impiego permanente- pSma, Llc cerca un IT Architect Cyber Security esperto per definire e sviluppare architetture IT/OT sicure, scalabili e conformi a standard come ISO 27001 e NIST CSF 2.0. Il ruolo richiede esperienza nella progettazione di architetture complesse e una forte capacità di...
50.000 € - 70.000 €
...pLa risorsa sarà coinvolta in attività di progettazione, implementazione, configurazione e troubleshooting di soluzioni di bnetwork security /b, con particolare focus sull’ecosistema bFortinet /b. /p pIl profilo ideale possiede una solida esperienza nella gestione di...- pVolkswagen cerca un Data Platform Architect per la sede di Sant’Agata Bolognese (BO). Riporterai direttamente al Head of IT e collaborerai con la Coordination of Architecture, Data Services per progettare, costruire e mantenere l’infrastruttura dati aziendale, garantendo...Lavoro ibrido
- ...the intelligent orchestration platform for DevSecOps. GitLab enables... ...efficiency, reduce security and compliance risk, and accelerate... ...GitLab to ship better, more secure software faster. The same principles... ...a Staff Product Security Architect to join our Security Platforms...Tempo pienoRemoto
- pADENTIS Italia cerca un IAM Solution Architect con esperienza in Identity Access Management per definire architetture sicure, scalabili e resilienti. L’incarico prevede allineamento agli obiettivi di business e forte collaborazione con Product Owner, Technical Lead, Cybersecurity...Lavoro ibrido
35.000 € - 40.000 €
...mese su Londra) /b /ppSiamo alla ricerca di un/una bIAM Solution Architect /b con esperienza nella progettazione e nell’evoluzione di... ...bCybersecurity, controllo degli accessi, gestione del rischio e Security Architecture /b. /liliConoscenza dei principi di bZero Trust /...Contratto con partita IVALavoro ibrido- ...Kyndryl, our Cloud AI Security Architects are game-changers,... ...a Cloud AI Security Architect, you'll be the guardian... ...applications, ensuring they are secure by design from... ...enterprise security platforms (SIEM/SOAR, CNAPP/... ...client teams (SOC, cloud platform, app teams) to...Lavoro ibridoOrario flessibile
80.000 €
ph3Security Architect /h3 /brpAzienda : Sizewell C Tipo Lavoro : Full... .../p /brh3Descrizione Lavoro - Security Architect /h3 /brpSizewell C’... ...the design and governance of secure technology solutions across... ...systems, infrastructure, cloud platforms, applications, and...Tempo pienoImpiego permanenteLavoro ibrido- pKyndryl is seeking a Presales Security Architect to design and promote advanced cybersecurity solutions for enterprise clients. You will lead security architecture discussions, map customer needs to Zero Trust, SASE, and SSE implementations, and support the sales team...
50.000 €
...di sicurezza di riferimento per l'intero ciclo di vita dell'AI (Secure MLOps) /li liCondurre l'attività di Threat Modeling specifiche... .../p ul liAlmeno 5 anni di esperienza nel ruolo di Cybersecurity Architect /li liConoscenza approfondita delle vulnerabilità dei modelli LLM...Orario flessibile- pSizewell C Company cerca un Security Architect esperto per guidare la progettazione e la governance di soluzioni tecnologiche sicure in un ambiente regolato e critico per la sicurezza. Lavorerai con Cyber Security, Enterprise Architecture, Engineering e fornitori esterni...
33.200 € - 65.000 €
pReply Spa ricerca un Cyber Security Expert per definire e realizzare soluzioni di sicurezza avanzate in contesti aziendali italiani, collaborando con clienti leader di mercato. /ppLa posizione è Full Time con retribuzione annua lorda tra 33.200€ e 65.000€, e offre formazione...Tempo pieno- Un'azienda tecnologica internazionale cerca un Security Architect per le sedi di Roma, Genova e Chieti Scalo. La posizione richiede una laurea in discipline STEM e 2-5 anni di esperienza nella gestione di progetti Cyber. I candidati devono avere conoscenze in Enterprise...Impiego permanenteLavoro ibrido
40.000 € - 59.000 €
ph3Descrizione Lavoro - CYS_Security Architect _GCSC /h3pbLeonardo /b è un gruppo industriale internazionale, tra le principali realtà mondiali... ...Firewall (WAF), Reverse Proxy, ADC / Load Balancer, Secure Gateway; /liliEseguire tuning avanzato di regole, signature,...Impiego permanenteLavoro ibrido- ...ambito Elicotteri, Velivoli, Aerostrutture, Elettronica, Cyber Security e Spazio. /p pCon oltre 60.000 dipendenti nel mondo, l'azienda... ...bCyber Security Solutions /b /h3 pRicerchiamo un/a bSecurity Architect /b per le nostre sedi di bRoma Laurentina /b, con possibilità...Lavoro ibrido
- pUk Power Networks is seeking a Cyber Security Architect to lead security design and policies across cloud and on-premise environments. You will drive security standards, runbooks, and governance to protect data, networks, and systems from threats, while guiding teams...Lavoro ibrido
- pLeonardo cerca un Security Architect per l’area Cyber Security Solutions, con sede a Milano Nerviano e possibilità di assunzione a Roma Laurentina, Genova Fiumara o Chieti Scalo. La persona progetterà e gestirà soluzioni di pubblicazione sicura, WAF e integrazione con...
- ...cybersecurity professionals to design, deliver innovative digital security solutions for market-leading clients. You will transform... ...deployment, helping reduce attack surfaces and protect digital platforms. /ppYou will work with AI-enabled security tooling, collaborate...
50.000 € - 62.000 €
...coinvolge processi, architetture e standard globali. /ppbr / /ppstrongIl tuo nuovo ruolo /strong /ppEntrerai nel team come Cyber Security Architect, una figura fondamentale nella definizione delle strategie di sicurezza e nella progettazione delle soluzioni di cyber...82.000 €
ph3Cyber Security Architect /h3 pSalary: Up to €82,000 yearly /p pAzienda: Uk Power Networks /p pTipo Lavoro: Full Time /p pThis Cyber Security... ...on-prem OT Mission Critical Systems. It is necessary that a secure environment is developed for the hosting and management of...TemporaneoTempo pienoImpiego permanenteDisponibilità immediataRemotoLavoro da casa