PB✓
PBridge
Full-timeNigeria, Ghana, Kenya, South Africa

Platform Security Engineer

at Flutterwave

Paystack is seeking a Platform Security Engineer to own the security of the company's AWS organisation end-to-end. This role will define and enforce cloud security architecture, access control systems, and organisation-wide controls that all engineering teams depend on across Nigeria, South Africa, Ghana, and Kenya.

Job Description

Responsibilities

  • Own the security of Paystack's AWS organisation as a whole - its architecture, account structure and the organisation-level controls that apply across every team, product, and environment at the company
  • Design, implement, and govern how access works across the entire organisation - defining the permission model from first principles, building the systems that enforce it, and ensuring it holds as the company scales
  • Build self-service permission services and horizontal access control systems that engineering teams can rely on without needing to involve security on every request
  • Define and enforce the cloud security baseline that all engineering teams build within - ensuring that what gets provisioned meets a consistently high standard by default, not by intervention
  • Act as the Security team's embedded partner to DevOps - present from the start of infrastructure decisions and the central point of contact for security questions from across the engineering organisation
  • Ensure that secrets management, identity and access boundaries, and the security of the supply chain at the infrastructure layer are robust, auditable, and well-maintained
  • Own the security observability pipeline up to the point of delivery - ensuring logs and signals are generated correctly, structured for consumption, and reliably delivered to Security Operations
  • Translate compliance requirements across multiple active regulatory frameworks and data protection regimes into concrete, automated infrastructure controls - encryption baselines, access governance, audit logging, and programmatic evidence generation
  • Anticipate where the platform's threat landscape is heading - building controls that are durable under future conditions
  • Write code that solves real infrastructure security problems with the same rigour you would apply to production engineering
  • Make security the path of least resistance for engineering - the controls you build should make the secure option the obvious option, with no trade-off in developer velocity
  • Define the technical direction and standards for Platform Security with enough clarity and rigour that they hold as the team grows and as the infrastructure evolves
  • Build the Platform Security function - shaping what it looks like, how it operates, and who it eventually comprises
  • Inherit a functioning platform and take full ownership of it - improving what exists, completing what was started, and defining what comes next
  • Identify what needs to be solved before it is articulated, set the technical direction for how platform security works at Paystack, and make architectural decisions with company-wide reach

Requirements

  • Deep, production-tested experience securing AWS environments at scale
  • Direct experience owning cloud infrastructure at the organisation level
  • Experience defining account structures, designing organisation-wide policy enforcement, and governing access across a multi-account AWS environment in a context where getting it wrong had real consequences
  • Ability to design and implement access control systems that work at company scale
  • Understanding of the failure modes of permission models that grow without governance, and ability to build the systems that prevent them
  • Ability to write defensive, high-quality code - build the infrastructure and tooling yourself, and build it well
  • Strong mental model of how the web works end to end, including the security controls and failure modes from client to server
  • Ability to reason about where failure modes intersect with cloud infrastructure
  • Genuine instinct for finding flaws in systems - spot what others miss, communicate it clearly, and drive resolution rather than generating reports
  • Ability to reduce risk in inherently insecure efforts without defaulting to industry norms
  • Track record of inheriting complex, live systems and improving them without breaking what works
  • Know when to rewrite and when to refine, and can defend either position
  • Ability to operate across the breadth of Platform Security - identity and access management, secrets management, infrastructure security, network controls, container security, and supply chain security at the infrastructure layer
  • Experience working in regulated environments where multiple compliance frameworks are simultaneously active and where audit evidence needs to be generated programmatically
  • Credibility to be the go-to security contact for an engineering organisation
  • Ability to engage technically with senior engineers, translate security requirements into decisions they can act on, and push back effectively without creating friction
  • Natural inclination to collaborate: work with engineering teams, not around them, and understand that a control nobody adopts is not a control
  • High agency: identify problems before they are raised, take ownership without being asked, and drive clarity in ambiguous situations
  • Clear, precise communication: explain a control decision to a senior engineer, a gap to an auditor, and a strategic priority to leadership
  • Calm and methodical under pressure: when something breaks at the infrastructure level, you are the person others orientate around
  • Collaborative by instinct: build trust with engineering through quality and reliability
  • Systems thinker who builds for scale: build something that will outlast your direct involvement

Skills

AWS

Ready to apply for this role?

PBridge connects skilled professionals with top employers worldwide.