Senior Platform Engineer, Security

Decagon Decagon · Vertical AI · San Francisco, CA · Engineering

Senior Platform Engineer, Security at Decagon, a conversational AI platform company. This role focuses on designing, building, and operating the security infrastructure for the AI platform, ensuring secure handling of sensitive customer data and defending against AI-enabled threats. The role involves creating secure service creation paths, security tooling, and infrastructure-as-code, with a focus on automation, observability, and self-service. It requires experience with cloud platforms (GCP/AWS), IaC (Terraform), and systems programming, and partners with various teams to translate enterprise and compliance requirements into automated technical controls.

What you'd actually do

  1. Design and implement secure, multi-tenant infrastructure that isolates customer data while enabling efficient AI model serving across our platform
  2. Build "golden paths" for security including service templates, libraries, terraform policies, and automation, so new services are secure and production-ready by default
  3. Own infrastructure-as-code (Terraform) and GitOps best practices, including reusable modules and policy-as-code
  4. Expand and help operate the platforms behind alerting detection, secrets management, IAM, and automated remediation, integrating them cleanly into CI/CD and developer workflows
  5. Partner with Security, Infrastructure, and product engineering teams to translate enterprise and compliance requirements (SOC 2, ISO 27001, GDPR) into reliable, automated technical controls

Skills

Required

  • 5+ years building and operating production infrastructure
  • Meaningful exposure to security or a strong interest in moving deeper into security problems
  • Deep knowledge of Google Cloud Platform and/or AWS, including compute, networking, IAM, and security services
  • Proficiency with infrastructure-as-code (Terraform, Ansible, or similar)
  • Track record of building developer-facing tooling and automation
  • Strong coding ability in at least one systems language (eg. Python, Go, TypeScript)
  • Comfort building paved-path tooling teams actually adopt
  • Experience applying AI-assisted tooling (Cursor, Claude Code, and similar) to make engineers dramatically more effective
  • Experience with secure container deployment, service mesh, and Kubernetes security best practices
  • Observability and incident-response tooling experience (instrumentation, alerting, dashboards)
  • Clear written communication
  • Ability to turn ambiguous requirements into simple, reliable designs

Nice to have

  • Track record of being an early or founding platform/infrastructure/security engineer at another company
  • Experience building internal platforms: service templates, paved-road deployment, self-serve environments, or developer portals
  • A security-minded approach to the software supply chain (provenance, secrets, least privilege)
  • Familiarity with static analysis tooling (Semgrep, CodeQL)
  • Experience with detection and response data pipelines (Kafka/Pulsar, Splunk/Panther/RunReveal, or similar)
  • Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR) from an infrastructure and platform perspective

What the JD emphasized

  • security infrastructure
  • AI platform
  • enterprise customers
  • AI agents
  • customer data
  • AI-enabled threats
  • security infrastructure
  • infrastructure security program
  • security-conscious enterprises
  • financial-services institutions
  • security platform
  • security
  • infrastructure
  • platform engineering
  • secure, multi-tenant infrastructure
  • customer data
  • AI model serving
  • security
  • secure service creation
  • security tooling
  • infrastructure-as-code
  • security infrastructure
  • security
  • infrastructure
  • product engineering
  • enterprise and compliance requirements
  • security on-call
  • production infrastructure
  • security
  • security services
  • infrastructure-as-code
  • developer-facing tooling
  • security
  • security
  • security
  • security
  • enterprise compliance requirements