Platform Security Engineer

Nintex Nintex · Enterprise · Johannesburg, South Africa · Engineering

Platform Security Engineer responsible for securing cloud-native infrastructure, container platforms, CI/CD pipelines, and product services. Implements and maintains security controls, builds standardized security processes, supports penetration testing and compliance, and embeds security practices into the developer experience.

What you'd actually do

  1. You implement and maintain security controls across the platform, including container orchestration security policies, network segmentation, role-based access controls, and admission control mechanisms.
  2. You manage container image scanning and enforce image policies in CI/CD pipelines and cluster admission, ensuring only vetted and signed images reach production environments.
  3. You support infrastructure-as-code security scanning using policy-as-code tooling, flagging and remediating misconfigurations in infrastructure definitions before they reach production.
  4. You maintain and improve secrets management workflows, ensuring rotation policies are enforced, access is audited, and no secrets are hardcoded or exposed in source code or configuration.
  5. You support cloud security posture management across cloud environments, monitoring for drift, misconfiguration, and compliance deviations against established baselines.

Skills

Required

  • security engineering
  • infrastructure security
  • DevSecOps
  • cloud-native infrastructure
  • container platforms
  • CI/CD pipelines
  • security controls
  • vulnerability management
  • production security checks
  • secure build pipelines
  • penetration testing
  • SOC operations
  • compliance-related activities
  • developer experience tooling
  • documentation
  • infrastructure security
  • application security
  • shift-left practices
  • container orchestration security policies
  • network segmentation
  • role-based access controls
  • admission control mechanisms
  • container image scanning
  • infrastructure-as-code security scanning
  • policy-as-code tooling
  • secrets management workflows
  • cloud security posture management
  • service mesh security configuration
  • mutual TLS enforcement
  • authorization policies
  • traffic policies
  • tenant isolation
  • access control configuration
  • vulnerability assessments
  • vulnerability tracking system
  • dependency scanning
  • static application security testing (SAST)
  • software composition analysis (SCA)
  • security incident response
  • evidence preservation
  • documentation
  • audit evidence
  • technical validation
  • security reviews
  • feedback on pull requests
  • architecture proposals

Nice to have

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or related field; or equivalent combination of education and experience.

What the JD emphasized

  • security controls
  • CI/CD pipelines
  • container orchestration security policies
  • cloud security posture management
  • vulnerability assessments
  • security incident response
  • compliance-related activities
  • security reviews