Skip to content

Open nowPosted 3 hours agoWe saw it 35 min after it went up

Senior Security Platform Engineer

Equinox727 open roles

Where
New York, NY, United States
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security Platform EngineerEquinox · New York, NY, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Equinox's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Equinox postings stay open a median of 25 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.0%30 days
This job: posted 3 hours ago

Equinox median: 25 days open

The posting

Company Description

WHO WE ARE

Equinox is a category of one, setting the global standard for luxury health, wellness, and hospitality. Our spaces are intentionally elevated, our standards uncompromising, and our expectations high. We attract people who take pride in excellence, care deeply about quality, and want to be part of something that feels different the moment you walk through the door.

We are builders, operators, and innovators who believe great environments and meaningful human connection change lives. Diversity, belonging, and ownership aren’t slogans here, they’re how we work. At Equinox, colleagues don’t just support the business; they shape the future of wellness. Because for us, it’s not fitness. It’s life.

WHAT WE DO

We create premium, immersive experiences where performance, hospitality, design, and human connection converge—and every detail matters. This is not a traditional fitness environment. It is a place where high standards, accountability, and pride in craft define the work.

Fueled by an entrepreneurial mindset, we trust our people with real responsibility and real impact. Growth is earned through action, learning is hands‑on, and careers are built by those who want to operate at the highest level. At Equinox, we don’t just offer opportunities—we offer long‑term pathways for people who want to do meaningful work in an environment that expects more and delivers more.

Job Description

We are looking for a senior engineer who can operate at the intersection of cloud infrastructure, platform engineering, and security operations. This is a hybrid role for an engineer who is equally comfortable debugging a Terraform module, tuning a SIEM detection rule, and leading an incident response investigation. You'll be a primary technical escalation point for both platform reliability and security incidents across all cloud environments.

What You'll Do

Cloud Infrastructure & Platform Engineering

  • Own and maintain infrastructure-as-code across (e.g., Terraform) cloud providers, including shared modules used by application teams org-wide
  • Manage IAM users, keys, and secrets lifecycle (rotation, storage in Parameter Store/Secrets Manager, cross-environment consistency)
  • Diagnose and resolve production networking and infrastructure issues: load balancer health checks, security groups, WAF rules, CDN and origin access, DNS, and container orchestration
  • Administer access across supported platforms (e.g., AWS, GCP, GitHub, etc.) and internal developer tooling
  • Evaluate and integrate third-party platform/security tooling (e.g., CSPM, code security scanners)
  • Support CI/CD pipelines and troubleshoot build/deploy failures

SIEM & Detection Engineering

  • Own and operate the organization's Elastic Security (SIEM) platform end-to-end: cluster upgrades, agent/integration management, and log ingestion pipelines (cloud audit logs, identity provider logs, payment/fraud logs, WAF logs)
  • Design, build, and tune detection rules and alerting workflows, including integrating SIEM alerts into team communication channels (e.g., Slack)
  • Continuously improve signal quality by resolving log parsing errors, refining index patterns, and reducing false positives
  • Maintain technical documentation for logging architecture and detection rule logic

Security Operations & Incident Response

  • Provide technical leadership and day-to-day oversight for the SOC team, including prioritization, escalations, investigation quality and mentoring
  • Serve as a senior escalation point for the SOC, guiding and mentoring analysts through investigations
  • Lead investigations into anomalous authentication activity, account compromise, and suspicious network traffic, including coordinating remediation (session revocation, credential resets, user outreach)
  • Develop and maintain incident response runbooks and reference documentation
  • Build and maintain WAF-based detection and mitigation capabilities (e.g., fingerprint- and IP-based blocking of malicious/fraudulent traffic)

Identity, Access & Compliance

  • Drive identity governance initiatives, including cloud identity reconciliation (e.g., managed vs. unmanaged accounts) and license/access audits
  • Design and implement authentication hardening measures: conditional access policies, MFA/authentication strength requirements, and legacy protocol deprecation (e.g., legacy SMTP auth)
  • Partner with IT/security leadership on identity provider strategy and vendor licensing decisions

Application, AI & Code Ownership

  • Hold end-to-end security ownership across the organization's core application stack, spanning front-end (React Native, React Web), back-end (Node.js, Spring Boot/Java, Python/Flask), and AI/ML systems
  • Review code and architecture for security vulnerabilities (e.g., dependency/supply-chain risk, secrets handling, authN/authZ flaws, insecure API design) across mobile, web, and service layers
  • Partner with application engineering teams to embed security requirements into the SDLC — secure coding standards, PR review gates, and CI/CD security scanning (SAST/SCA/secrets detection)
  • Triage and drive remediation of vulnerabilities surfaced by code scanning and vulnerability management tooling (e.g., Wiz, GitHub Advanced Security) across the full technology stack
  • Maintain visibility into third-party/open-source dependency risk (npm, Maven/Gradle, pip) and coordinate patching for critical CVEs
  • Serve as the security point of contact for engineering teams building on React Native, React Web, Node.js, Spring Boot, and Python/Flask, ensuring consistent security posture regardless of language/framework
  • Own the security posture of AI/ML systems and LLM-powered features: model access controls, data governance for training/prompt data, prompt injection and jailbreak risk, and secure integration with third-party AI APIs and vendors
  • Evaluate and vet AI coding assistants and internal AI tooling for data exposure, IP leakage, and supply-chain risk before organization-wide adoption
  • Define and maintain security guardrails/review processes for teams building AI-powered features or agents, including monitoring for anomalous or abusive usage patterns

Fraud & Payments Security

  • Partner with risk and payments teams to investigate and mitigate payment fraud (e.g., card-testing/BIN attacks, risk-scoring anomalies in third-party payment platforms)
  • Analyze and recommend changes to fraud risk rules, allow-lists, and risk profiles
  • Track and help prioritize security remediation tickets related to payment endpoints

Qualifications

Required:

  • 5+ years of experience in infrastructure/platform engineering, with hands-on production ownership in multi-account cloud environments
  • Strong Terraform/IaC experience, including authoring and maintaining shared modules
  • Experience operating a SIEM platform (Elastic Security preferred) — log ingestion, detection engineering, and alerting
  • Solid networking fundamentals: load balancers, security groups, WAF, DNS, CDN
  • Experience with identity providers (Entra ID/Azure AD, Okta, or similar) and authentication/authorization concepts (SSO, SAML, MFA, conditional access)
  • Demonstrated experience leading or heavily contributing to security incident response
  • Comfortable being a hands-on technical escalation point across multiple teams simultaneously
  • Working familiarity with application security practices across modern web/mobile and backend stacks (e.g., React/React Native, Node.js, Java/Spring Boot, Python/Flask) — able to read code, understand architecture, and identify security risk even if not writing production application code day-to-day

Preferred:

  • Proven experience with AWS, GCP and Azure
  • Familiarity with payments security concepts (fraud scoring, PCI-adjacent systems, payment gateway risk tools such as Adyen)
  • Experience with container orchestration (ECS or similar)
  • Experience mentoring SOC analysts or junior engineers
  • Familiarity with CSPM/vulnerability management tooling (e.g., Wiz, CrowdStrike)
  • Hands-on development or code review experience in React Native, React Web, Node.js, Spring Boot/Java, or Python/Flask
  • Experience with SAST/SCA tooling (e.g., GitHub Advanced Security, Snyk, SonarQube) and integrating security scanning into CI/CD
  • Familiarity with AI/LLM security concepts (prompt injection, data leakage, model access control) and securing AI-powered product features or internal AI tooling

What Success Looks Like

  • Production infrastructure incidents are diagnosed and resolved quickly, with root cause identified and preventive fixes (module/PR updates) shipped
  • SIEM coverage expands reliably with high-quality, low-noise detections
  • Security incidents are triaged and resolved with clear communication and documented runbooks
  • Identity and access posture continuously improves (reduced legacy auth, tighter conditional access, cleaner account governance)
  • Cross-functional partners (data, application, payments teams) see this role as a trusted, responsive technical partner

Pay Transparency: $145K - $175K

Additional Information

AS A MEMBER OF THE EQUINOX TEAM YOU WILL RECEIVE:

  • We offer competitive salaries, benefits, and industry leading commission opportunities for club employees
  • Complimentary Club membership
  • Perks and incentives with our products and services including Personal Training, Pilates, Spa and Shop

This job description is intended to describe the general requirements for the position. It is not a complete statement of duties, responsibilities, or requirements. Other duties not listed here may be assigned as necessary to ensure the proper operations of the department.

Equinox is an equal opportunity employer. For more information regarding our career opportunities, please visit one of our clubs or our website at https://careers.equinox.com/

All your information will be kept confidential according to EEO guidelines. Must have a legal right to work in the United States.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Equinox's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Equinox's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Equinox's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.