Skip to content

Open nowPosted 4 days ago

Sr Platform Security Engineer

BusPatrol13 open roles

Pay
$130,000 – $150,000 a year
Where
TX - Austin
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSr Platform Security EngineerBusPatrol · TX - Austin
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on BusPatrol's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. BusPatrol postings stay open a median of 23 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.1%30 days
This job: posted 4 days ago

BusPatrol median: 23 days open

The posting

JOB OVERVIEW

BusPatrol is transforming student transportation safety through AI-enabled, cloud-connected platforms and real-time operational systems. We are seeking a Sr Platform Security Engineer to make those platforms secure by default, resilient, and easier for engineering teams to operate safely.

This is a hands-on engineering role focused on securing the platform layer: AWS identity and access, multi-account guardrails, network security, secrets and encryption, infrastructure-as-code, CI/CD security controls, vulnerability management, and security telemetry. You will partner with DevOps, application engineering, architecture, MLOps, IT, and Cyber Security to turn security requirements into reusable controls and paved-road patterns.

The successful candidate will bring strong judgment, practical implementation skills, and the ability to improve security without creating unnecessary delivery friction. This role is not an application security specialist or a general SRE role; its primary mandate is platform and cloud security engineering.

Location: Austin, TX

KEY RESPONSIBILITIES

- Design, implement, and continuously improve security controls across BusPatrol’s AWS multi-account environments.

- Establish least-privilege identity patterns using AWS IAM, IAM Identity Center, Entra ID, permission sets, groups, cross-account roles, service roles, and time-bound elevated access where appropriate.

- Build and maintain secure, reusable Terraform modules and AWS CDK constructs for platform services, security controls, logging, encryption, networking, and account/environment guardrails.

- Help evolve AWS Organizations, Control Tower, service control policies, account boundaries, and shared-services patterns to reduce blast radius and improve governance.

- Secure cloud networking through practical controls for VPCs, routing, security groups, network ACLs, WAF, private connectivity, site-to-site VPNs, Direct Connect, and related network segmentation strategies.

- Implement and operate secrets-management and encryption patterns using AWS KMS, Secrets Manager, Parameter Store, TLS, and automated credential rotation.

- Integrate security checks into GitHub Actions and other delivery workflows, including infrastructure validation, dependency and vulnerability scanning, container/image security, SBOMs, signing, and policy enforcement.

- Develop policy-as-code and preventive guardrails using appropriate tools such as AWS Config, SCPs, CloudFormation Guard, OPA, Conftest, Checkov, tfsec, or equivalent technologies.

- Partner with engineering teams to define secure golden paths, platform templates, and documented patterns that make the safest implementation the easiest implementation.

- Operate and improve cloud security telemetry and findings across services such as GuardDuty, Security Hub, CloudTrail, AWS Config, CloudWatch, and Datadog.

- Triage, prioritize, and remediate platform security findings from CNAPP, CSPM, vulnerability-management, penetration-testing, and internal assessment tools, including Wiz or comparable platforms.

- Support incident response, containment, root-cause analysis, and post-incident improvement for cloud, infrastructure, identity, and platform security events.

- Produce concise architecture decisions, threat-informed control designs, runbooks, evidence, and operational documentation that engineering teams can use.

- Collaborate with Cyber Security and GRC on SOC 2, ISO 27001, CIS, NIST, customer assurance, and audit-readiness activities without turning compliance into a manual exercise.

- Mentor engineers through design reviews, infrastructure pull requests, office hours, and practical security enablement.

- Contribute to secure AI-enabled engineering and platform workflows by protecting sensitive data, non-human identities, secrets, tool permissions, logging, and production change controls.

QUALIFICATIONS

- 8–10+ years of professional experience in cloud security, platform security, DevSecOps, infrastructure security, or a related engineering discipline.

- Deep hands-on experience securing production AWS environments, preferably across multiple accounts and environments.

- Strong knowledge of AWS IAM, IAM Identity Center, KMS, Secrets Manager, Parameter Store, CloudTrail, GuardDuty, Security Hub, AWS Config, Organizations, SCPs, and VPC security.

- Demonstrated ability to implement infrastructure security through Terraform, AWS CDK, CloudFormation, or comparable infrastructure-as-code tooling.

- Experience designing and enforcing least-privilege access, role-based access, group-based permissions, cross-account access, and privileged-access controls.

- Experience securing CI/CD pipelines, source-control workflows, build runners, artifacts, containers, and deployment processes.

- Practical understanding of cloud network security, including segmentation, routing, security groups, WAF, private connectivity, site-to-site VPNs, and Direct Connect concepts.

- Experience with vulnerability management, security findings, risk prioritization, remediation tracking, and verification of control effectiveness.

- Working knowledge of policy-as-code, preventive and detective controls, security automation, and compliance evidence collection.

- Strong Linux, networking, scripting, Git, and troubleshooting skills.

- Experience responding to or supporting security incidents in production environments.

- Ability to communicate clearly with engineers, architects, security professionals, auditors, and technical leadership.

- Strong written documentation habits and a pragmatic, automation-first mindset.

PREFERRED QUALIFICATIONS

- Experience with AWS Control Tower, landing zones, account vending, shared services, or large-scale AWS governance.

- Experience with Wiz, Qualys, Prisma Cloud, Lacework, or comparable CNAPP/CSPM and vulnerability-management platforms.

- Experience with GitHub Actions, OIDC federation, artifact registries, image signing, SBOM tooling, and supply-chain security.

- Experience with Kubernetes or ECS security, container hardening, runtime controls, and workload identity.

- Experience with Zero Trust, data protection, PII tokenization or redaction, DLP, or secure production-data access patterns.

- Experience supporting SOC 2, ISO 27001, CIS, NIST, or similar security and compliance frameworks.

- Familiarity with Backstage, internal developer platforms, golden paths, or security self-service tooling.

- Experience securing AI products, AI agents, model-serving infrastructure, or non-human identities.

- Experience with site-to-site VPNs, Direct Connect, Transit Gateway, private endpoints, and hybrid-cloud connectivity.

- AWS Security, AWS Solutions Architect, AWS DevOps Engineer, CISSP, CCSP, or relevant equivalent certification.

CORE SKILLS

- AWS platform and cloud security

- IAM, identity governance, and privileged access

- Infrastructure as Code security

- Cloud networking and segmentation

- CI/CD and software supply-chain security

- Secrets management and encryption

- Policy-as-code and security guardrails

- Vulnerability and findings management

- Security automation and observability

- Incident response and root-cause analysis

- Technical documentation and enablement

- Cross-functional engineering leadership

WHY BUSPATROL?

WHO WE ARE

BusPatrol is a technology company with a public safety mission. Our AI, machine learning, telematics, and cloud-connected systems help communities make the journey to and from school safer for students.

WHAT WE OFFER

- Competitive salary and benefits package

- Unlimited PTO

- A purpose-driven career focused on protecting children and improving public safety

- The opportunity to work with modern cloud, automation, AI, and security technologies

- A culture of safety, learning, teamwork, and meaningful technical impact

BE PART OF SOMETHING BIGGER

This is an opportunity to build security capabilities for a mission-critical platform, work directly across cloud infrastructure and engineering, and establish durable controls that enable teams to move faster with confidence. You will join a pragmatic, collaborative culture that values safety, connection, excellence, impact, ownership, and continuous learning.

COMPENSATION NOTE

The US salary range for this position will be provided in the posting. Salary ranges are determined by role, level, location, and additional factors including job-related skills, experience, and relevant education or training. Compensation details in US postings reflect base salary only and do not include bonus, commission, or benefits where applicable.

EQUAL OPPORTUNITY

BusPatrol is an equal opportunity employer. EOE/AA Disability-Veteran.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against BusPatrol's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on BusPatrol's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    BusPatrol's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.