Partly

Platform Security Engineer

Partly

Auckland, New Zealand · Full Time

Be the first to apply

Experience
5+ yrs
Salary
Openings
1
Posted
16 hours ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About Partly

Partly is a rapidly growing technology company focused on revolutionizing the global repair industry by developing AI infrastructure. Starting with the $2 trillion automotive market, their product "Interpreter" is an AI model designed specifically to understand vehicle damage and required parts. Founded by former Rocket Lab engineers, Partly has expanded significantly recently, backed by prominent investors. Headquartered in Austin, TX, they have offices in London and New Zealand (Christchurch and Auckland).

Role Overview

The Platform Security Engineer will be responsible for maintaining and enhancing Partly's security posture while ensuring platform reliability, reporting directly to the Platform Lead. This unique position requires hands-on technical expertise to implement security controls and infrastructure hardening without focusing solely on compliance checklists. This is the company's first dedicated security engineer role, involving building security processes from the ground up and close collaboration with the Site Reliability Engineering (SRE) team.

Key Responsibilities

  • Maintain platform security and reliability, participate in the on-call rotation with SREs.
  • Develop and manage security incident response plans, conduct testing and lead post-incident reviews for security events.
  • Establish and maintain security monitoring and alerting systems.
  • Oversee security compliance certifications such as ISO 27001 and upcoming SOC 2 audits, maintaining continuous compliance through tools like Vanta.
  • Manage enterprise security questionnaires and maintain the risk register, communicating risks to leadership and engineering teams.
  • Strengthen infrastructure security via principles like least privilege in PostgreSQL roles, Kubernetes RBAC settings, and controlled secret access for applications.
  • Drive network segmentation and zero-trust implementations using technologies such as Cilium network policies and Kyverno admission policies.
  • Set production access policies favoring read-only permissions for developers.
  • Implement and operate vulnerability scanning pipelines using tools like Trivy, Renovate, and Falco.
  • Conduct vulnerability triage, prioritize issues, track remediation efforts, and report relevant metrics and trends.

Required Qualifications and Skills

  • Preferably 5+ years experience in security engineering, platform engineering, or SRE with a focus on security.
  • Hands-on experience securing Kubernetes environments, including RBAC, network policies, and admission controllers.
  • Familiarity with compliance frameworks such as ISO 27001, SOC 2 or PCI-DSS, understanding the difference between actual security and compliance checklists.
  • Strong knowledge of cloud security principles; experience with Google Cloud Platform preferred.
  • Experience with infrastructure as code tools such as Terraform, ArgoCD, and GitOps workflows, emphasizing code review.
  • Excellent communication skills to convey security risks to both technical and non-technical stakeholders.
  • Bonus skills include familiarity with CNCF security tools (Cilium, Kyverno, Falco), container security, supply chain security concepts (SBOM, image signing), and programming experience in Rust or Go.

Benefits

  • Fresh and healthy catered lunches available daily in all offices.
  • $1,500 annual wellness allowance for health and wellness expenses.
  • Generous parental leave policy with three months fully paid leave and flexible gradual return to work.
  • Commuting support through parking provision or allowance.
  • Modern, inspiring office environments designed for collaboration and convenience.
  • Office-focused work model with flexibility and a culture emphasizing trust and work-life balance.
  • Regular social events including weekly happy hours, monthly lunches, quarterly global meetings, and an annual offsite.

Additional Information

  • Partly supports relocation with a generous allowance for candidates moving to the headquarters or offices.
  • Quarterly "Season Opener" events include trips to the main office with travel and accommodation covered by the company.

How they work

Communication Teamwork & Collaboration Problem Solving Initiative Work Ethic

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer