What You Will Do Ensure security is built into every aspect of the PhysicsX platform infrastructure Design cloud security controls (e.g. IAM, VPC, KMS, secrets management, etc.) as part of core architecture Design, Build and manage infrastructure security configurations Support the infrastructure team and security teams triaging and remediating security vulnerabilities Automate infrastructure provisioning, hardening, and compliance guardrails What You Bring To The Table 10+ years in cloud security architecture in large scale multi-cloud, multi-region platforms with strong isolation, governance, and reliability guarantees Ability to balance security risk, scalability, resilience, and developer velocity Deep expertise in Kubernetes security at scale (multi-cluster, multi-tenant, isolation models) Zero Trust architecture design and enforcement in Kubernetes-based platforms Hands-on experience with mTLS and Service Mesh (Istio, Linkerd, ambient mesh) Policy-as-code using OPA/Gatekeeper and/or Kyverno (admission control, secure defaults) Workload identity & IAM integration, including service-to-service authorization (SPIFFE/SPIRE a plus) Advanced Kubernetes network security using Cilium or Calico and NetworkPolicies, eBPF-based observability and Network Threat Detection & Layered Security (NTLS) Runtime and behavioural security with Falco or equivalent syscall based detection Infrastructure as Code with Crossplane (preferred) and/or Terraform GitOps driven platforms and secure-by-default provisioning wor...