Jobs · Engineering

Sr. Software Engineer - Platform

VerifyYou · United States · 1 wk ago
RemoteRemoteEngineeringFull-time

About the role

We're hiring a senior platform engineer (5+ years, deep GCP, security-minded) to own the infrastructure underneath our identity-verification layer. This is the first dedicated platform role at the company. You'll own the deploy path, the access model, and the security posture from day one, as these areas currently have no dedicated owner.

Responsibilities

  • Own IAM and the access model. Transition from individually granted permissions to group-based access, using Google Workspace as the source of truth.
  • Implement a gated Terraform path with auditable apply flows using Workload Identity Federation, plan on PR, and require approval before production deployment.
  • Own secrets and the credential store, working toward eliminating long-lived human-held credentials.
  • Manage the edge, including WAF posture, rate limiting, and bot mitigation. Adversarial traffic is our product domain, so this work is closely tied to our core offering.
  • Build controls that produce their own evidence, enabling access reviews and change management to run as queries against real systems instead of manual spreadsheets.
  • Ensure reliability as pilot customers scale, helping us detect issues before customers do.
  • Establish Infrastructure as Code practices, including Terraform conventions, module structure, and CI apply paths.
  • Drive reliability through capacity planning, synthetic health checks, alerting, and proper on-call setup.
  • Enhance observability with structured logs, traces, and an audit trail in BigQuery.
  • Harden edge policies, moving from deployed-and-observable to actively enforcing without breaking live traffic.
  • Implement environment-scoped groups, human database IAM, API-key hashing, and rotation.
  • Develop backups and disaster recovery plans, including recovery objectives and restore drills.
  • Support our GRC program for SOC 2 compliance by building and operating the systems it measures.

Requirements

  • 5+ years running cloud infrastructure in production, with deep and current GCP and/or AWS experience.
  • Experience with Terraform in a team setting: modules, state management, review processes, and disciplined deployment practices.
  • A CI/CD path you’ve built and would defend, including gated applies and functional rollback.
  • Expertise in cloud IAM as a design problem: least privilege, group-based access, workload identity, and eliminating long-lived human credentials.
  • SRE or DevOps experience in production, including on-call and incident response.
  • Hands-on serverless experience (Cloud Run, Lambda, Azure Functions, or equivalent).
  • Experience instrumenting observability, including OpenTelemetry, and a pragmatic view on alerting.
  • Ability to read and write application code (Python in this role). This is not a pure ops role.
  • Effective use of AI tooling, understanding its limitations, and critically evaluating its outputs.

Nice to have

  • Experience inside a SOC 2 or ISO 27001 environment, understanding auditor requirements.
  • Abuse prevention at the edge: WAF, rate limiting, bot mitigation.
  • Database administration: connection pooling, read replicas, failover.
  • Cost engineering: attribution, unit economics, and sub-linear scaling with customers.
  • Experience operating without a dedicated platform team, as a solo or paired engineer.

Our stack

  • Cloud: GCP (Cloud Run, Secret Manager, Artifact Registry, Cloud Logging, Workload Identity Federation, Cloud Armor, Cloud CDN behind a shared HTTPS load balancer).
  • IaC and CI: Terraform with a shared internal module library; GitHub Actions with reusable workflows.
  • Services: Python 3.14 on FastAPI (primary backend on Cloud Run).
  • Data: Cloud SQL Postgres 18, Firestore in Native mode, Memorystore Valkey, BigQuery, Pub/Sub.
  • Frontends: Two React + TypeScript apps, served as static bundles from Cloud Storage.
  • AWS: Small footprint, integrated with GCP for parts of the architecture.
  • Local: Entire stack runs as one Docker Compose project with emulators.

You’ll write Python and Terraform, integrate with frontends (but won’t own them), and help decide what we adopt next.

How we work

Small team, high autonomy, low ceremony. You’ll have a real stake in technical direction, working on greenfield projects. We use Linear for execution, Figma for design, Notion for documentation, and GitHub with agentic code review. Developer experience is a priority—we fix workflows that get in the way of shipping.

Why VerifyYou

The internet has evolved into critical infrastructure, but its trust model hasn’t kept pace. AI has made synthetic participation trivial, and legacy solutions (KYC, CAPTCHAs, phone verification) are either fragile or invasive. We’re building verification infrastructure that proves humanness while keeping personal data private.

You’ll own real surface area, ship to production fast, and work directly with founders and senior technical leadership. The platform has gaps—this role exists to fix them, giving you the latitude to do it properly the first time.

Pay

Competitive base salary, plus meaningful early-stage equity.

Location: Remote. Type: Full-time.

Similar jobs