Full Scale

Senior / Staff Platform Security Engineer

Full Scale Cebu City, Central Visayas, Philippines

Outsourcing and Offshoring Consulting · 201-500 employees

Sep 10
Remote security Principal (10+ yrs) Full-time Philippines
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Staff Platform Security Engineer will own and strengthen security across cloud infrastructure, Kubernetes environments, and production access. They will partner with engineering and compliance teams to implement security controls, manage vulnerabilities, and drive security architecture reviews.

What they look for

Cloud security Platform security Azure Kubernetes AKS Infrastructure as code DevSecOps Vulnerability management IAM RBAC CI/CD Threat modeling Security architecture Network security Secrets management Compliance

Requirements

Candidates must have 8+ years of experience in cloud or platform security with deep hands-on expertise in Microsoft Azure and Kubernetes. Strong proficiency in infrastructure as code, CI/CD security, and identity access management is required.

Benefits

100% remote work setup Work from anywhere in the Philippines Direct visibility and collaboration with the CTO High-impact role with significant technical ownership and autonomy Opportunity to work on a cloud-native healthcare/SaMD platform Exposure to modern Azure, AKS, Kubernetes, and cloud security technologies Opportunity to work in a regulated, high-assurance environment Collaboration with Engineering, Product, IT, Quality, and Compliance teams

Full description

This is a remote position

Join one of the Philippines' fastest-growing tech companies! Open to Philippine-based candidates only.

About Us

Full Scale is a fully remote-first company that helps businesses build dedicated teams of skilled software engineers. We make it easier for growing companies to find, onboard, and retain high-performing software talent.

About the Role

We are seeking a hands-on Senior / Staff Platform Security Engineer who can build, implement, and validate security controls across Azure, AKS/Kubernetes, identity, CI/CD, cloud networking, and production environments.

This role is best suited to a security engineer who has personally built and improved production controls. Candidates whose experience is primarily compliance, audit, SOC monitoring, architecture advisory, or people management without implementation ownership will not be a strong fit.

Requirements

  • 6+ years of experience in cloud security, platform security, security engineering, infrastructure security, DevSecOps, SRE, DevOps, or related technical infrastructure roles.
  • At least 4 years of security-focused experience in cloud, platform, application, DevSecOps, or production security engineering.
  • Strong hands-on Azure security experience, including Entra ID, managed and workload identities, RBAC, PIM, Key Vault, Defender for Cloud, Sentinel or comparable tools, private networking, and least-privilege architecture.
  • Strong AKS/Kubernetes and container-security experience, including Kubernetes RBAC, workload identity, secrets, network policies, ingress controls, admission and policy controls, runtime protection, and workload isolation.
  • Practical experience implementing secure-SDLC controls: SAST, DAST, SCA/dependency scanning, secret scanning, IaC scanning, container scanning, vulnerability management, CVEs/CVSS, and CI/CD security gates.
  • Experience securing software and container supply chains, including image scanning, registries, image provenance or signing, base-image and dependency vulnerabilities, and secure deployment controls.
  • Strong network-security knowledge across WAFs, firewalls, segmentation, private endpoints, ingress and egress controls, attack-surface reduction, and zero-trust principles.
  • Experience with security monitoring, detection, and incident response using SIEM telemetry, identity events, cloud audit logs, investigation, and containment workflows.
  • Experience conducting threat modeling and security architecture reviews, and translating findings into a prioritized technical security roadmap.
  • Strong infrastructure-as-code experience using Terraform, Bicep, ARM, or comparable tools, including policy and security automation.
  • Strong communication skills and the ability to partner with engineering teams, explain security findings clearly, and drive remediation through completion.
  • Must be hands-on at the keyboard and able to describe security controls personally configured or implemented, including the tools used, architecture decisions made, problems encountered, and how the control was validated.

Preferred Qualifications

  • Experience operating in a regulated or high-assurance environment and producing audit-ready technical evidence; HIPAA, SOC 2, ISO 27001, healthcare SaaS, fintech, or similar experience is valuable.
  • Experience with Microsoft Defender for Cloud, Microsoft Sentinel, Azure Policy, Log Analytics, CrowdStrike, Aikido, Vanta, New Relic, or comparable security platforms.
  • Experience with GitHub Actions, Azure DevOps, or comparable CI/CD platforms.
  • Familiarity with SAML, OIDC, SCIM, SSO, MFA, Conditional Access, and privileged-access management.
  • Experience in multi-tenant SaaS, .NET, Angular, or security automation using Python, Go, Bash, or PowerShell.
  • Certifications such as Azure Security Engineer Associate, CKS, CCSP, or CISSP, paired with demonstrated implementation experience.

Benefits

Why join us:

  • 100% remote work setup
  • Work from anywhere in the Philippines
  • Direct visibility and collaboration with the
  • High-impact role with significant technical ownership and autonomy
  • Opportunity to work on a cloud-native healthcare/SaMD platform
  • Exposure to modern Azure, AKS, Kubernetes, and cloud security technologies
  • Opportunity to work in a regulated, high-assurance environment
  • Collaboration with Engineering, Product, IT, Quality, and Compliance teams

Similar roles