{"id":1969040,"url":"https://alion.io/job/fourthwall-senior-platform-security-engineer-devops","title":"Senior Platform Security Engineer / DevOps","company":{"id":170859,"name":"Fourthwall","domain":"fourthwall.com","url":"https://alion.io/company/wbw","size_band":"11-50","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Schema","truth_index":null},"role":"DevOps","role_family":"DevOps","seniority":"senior","employment_type":null,"work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":["PL"],"hiring_countries_total":1,"salary":{"min":25000,"max":34000,"currency":"PLN","period":"month","gross":null,"usd_annual":104280},"salary_estimate":null,"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"CI/CD","optional":true},{"name":"Claude","optional":true},{"name":"GCP","optional":true},{"name":"GitLab CI","optional":true},{"name":"GitOps","optional":true},{"name":"Google GKE","optional":true},{"name":"IAM","optional":true},{"name":"Kubernetes","optional":true},{"name":"Linux","optional":true},{"name":"OWASP Top 10","optional":true},{"name":"PagerDuty","optional":true},{"name":"PCI DSS","optional":true},{"name":"PostgreSQL","optional":true},{"name":"Prometheus","optional":true},{"name":"SOC 2","optional":true},{"name":"SOPS","optional":true},{"name":"Terraform","optional":true}],"status":"live","first_seen_at":"2026-10-05T13:14:31Z","employer_posted_date":"2026-10-05","last_verified_at":"2026-10-09T22:30:25Z","board_verified":true,"closed_at":null,"days_open":4,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":4},"description":"Level: Senior individual contributor\nLocation: Remote within Poland, with regular overlap with the European team. Our Polish HQ is in Poznań; being able to meet there from time to time is a plus for us, not a requirement.\nPay: 25,000-34,000 PLN net per month on B2B (invoice amount excluding VAT).\nOn-call: part of the role. You would join the rotation, paged through PagerDuty.\nStack: GCP, GKE, Terraform, GitLab CI/CD, Flux, SOPS, Linux, PostgreSQL\nProcess: two conversations and one paid exercise with about three hours of recommended effort and no hard cap. The recommended total commitment is about four and a half hours. We aim to finish within ten working days.\nThe job\nOur production platform has one dedicated owner today, with support from other engineers. That support stays. We want a second owner to work in partnership with the first, and we want that person to bring security.\nYou would co-own the GCP/GKE platform with the engineer who runs it now, and you would be the security partner for the engineers who build on it. Fourthwall is a small company with no security department. When something needs fixing, there is nobody to hand it to: you write the Terraform, the pipeline check or the policy yourself, or you get the owning team to, and you check that it landed.\nWe want teams to keep the freedom to build fast. Security should come from configuration, policies, alerting and automated scans, so that nobody waits for an approval.\nYou would also run our vulnerability disclosure programme (VDP).\nWe want infrastructure to lead the company in using AI, beyond read-only assistants.\nWhat you would own\nThe platform, jointly. GCP and GKE, networking, IAM, secrets, GitOps, CI/CD, observability and PostgreSQL. Both of you should be able to change, debug and recover any of it.\nThe platform-security backlog. Less standing privilege and fewer long-lived credentials; better workload identity and secret handling; infrastructure vulnerabilities triaged, tracked and verified.\nGuardrails. Platform configuration and policies that prevent leaks and misconfiguration, alerting for what gets through, and automated scanning in the pipeline (secrets, dependencies, images, Terraform, code), including AI-based security review. You decide what blocks a merge and keep the noise low enough that nobody routes around it.\nThe VDP. Intake, validation, severity, routing to the right team, communication with the reporter, tracking the fix, disclosure. A report that looks like live exploitation goes to incident response, not into the queue.\nRecovery. Agreed recovery objectives, and the restore, failover and access exercises that show whether we meet them. The runbooks, alert quality and postmortems that go with that.\nAI and automation in operations. One example: our on-call pages from Prometheus are hard to read today. A page should tell the responder what failed and what to do next, and whatever can be automated should be automated the following day.\nBeing the engineer people want to ask about security. Fast answers on risky designs and changes (authentication, secrets, data storage, external exposure), and the questions that keep coming back turned into guardrails or defaults.\nWhat you would not own\nYou would not be our CISO, our SOC, our pentester or a security-tool administrator. You would not sign off every change or fix every application bug either: teams ship and fix their own services.\nThe first 90 days\nMap the critical parts of the platform and their main risks.\nGet the VDP queue to a state where every report has a severity, an owner and an age.\nPut the first guardrails in place where the risk is highest: a policy, an alert or an automated scan.\nRun at least one restore or access exercise.\nShip a couple of improvements of your own to the production infrastructure.\nRequirements\nTwo things we check first:\nYou have owned a production cloud platform at a senior level: the consequential changes, the failures and the recovery afterwards.\nYou have done security engineering work yourself, end to end. Hardening a platform, running vulnerability management, reviewing designs for security, handling a security incident, or operating a VDP or bug bounty all count. This is a requirement, not a nice-to-have. Please do not apply on the strength of the infrastructure half alone.\nThen:\nTerraform and GitOps in production. Flux should not be new to you.\nKubernetes including its security side: RBAC, network policy, workload identity, admission control. You can explain how an operator or an admission webhook works and name one you have run. We are on GKE; depth on another cloud is fine if you can show it transfers.\nIdentity: cloud IAM, OAuth and OIDC, service-to-service identity (mTLS or workload identity) and short-lived credentials.\nEnough application-security knowledge to read a VDP report, decide whether it is real and how serious, and route it. The OWASP Top 10 lists are the right level.\nSecurity checks in CI/CD (secret, dependency, image or IaC scanning), tuned so that engineers leave them switched on.\nYou use Codex or Claude heavily in your daily work, and you answer for everything they help you ship.\nYou write automation in a general-purpose language or shell and review other engineers’ code.\nClear English, written and spoken. You will explain risk to engineers, to security researchers and to leadership, often on incomplete evidence.\nNo degree, certification or big-company security background required.\nUseful, not required: threat modelling or offensive work; SRE practice such as SLOs; SOC 2 or PCI DSS work.\nThe process\nThe same steps for everyone.\nCV or profile. Point us at one security improvement, review, vulnerability or incident you owned and the platform you did it on. A link to a write-up or repository beats a list of keywords.\nIntro call, 30 minutes. The role, your situation, questions both ways.\nPaid exercise, shortlisted candidates only. Run a local Kubernetes lab with an inherited preview service. We pay 500 PLN for a bona fide submission whether or not we make an offer. Use your normal tools and AI; you own the changes and evidence.\nExercise debrief, 60 minutes. Walk us through your diagnosis, changes, evidence and remaining risks. We introduce one changed condition related to your solution and discuss how you would respond. AI remains available.\nOffer.\nContract and perks\nB2B contract, band above. The offer depends on the scope you demonstrate, not on your previous salary.\nRemote within Poland, flexible hours, agreed overlap with the team.\nMacBook.\nPrivate healthcare, sports card and English lessons.\nEquity in the US-based company.\nFourthwall\nFourthwall is where online creators (YouTubers, streamers, podcasters and other independent brands) run shops, merchandise, donations and memberships. More than 500,000 creators use it. The platform you would co-own is the one that runs their businesses.","description_format":"text","description_chars":6893,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false}]},"benefits":["Apple Macbook","Equity"],"hiring_locations":[{"name":"Poland","iso":"PL","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Commerce"],"lifecycle":[{"event":"open","at":"2026-10-06T18:28:12Z"}],"visa":[],"liveness":{"score":81,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":0.945,"age_days":3,"expected_fill_days":7,"reasons":["conf:3","win:mid"],"computed_at":"2026-10-09T06:01:00Z"},"pay":{"stated_usd_annual":104280,"is_top_pay":false},"html_url":"https://alion.io/job/fourthwall-senior-platform-security-engineer-devops","json_url":"https://alion.io/job/fourthwall-senior-platform-security-engineer-devops.json","meta":{"generated_at":"2026-10-10T02:03:30Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3622,"day_limit":5000,"remaining_today":1378,"minute_limit":60,"resets_at":"2026-10-11T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":170859},"rest":"https://alion.io/mcp/rest/get_company?id=170859"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Ffourthwall-senior-platform-security-engineer-devops"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Ffourthwall-senior-platform-security-engineer-devops"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Ffourthwall-senior-platform-security-engineer-devops"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/fourthwall-senior-platform-security-engineer-devops\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Ffourthwall-senior-platform-security-engineer-devops"}]}