À propos de ce poste Senior Platform & Security Engineer chez Flodesk
Flodesk is recognized in the Inc 5000 as one of the world's fastest-growing email marketing companies, built to help entrepreneurs sell online and design emails that people love to get. We're committed to giving small businesses simple and intuitive tools that help them grow, nurture, and monetize their email list.
We’re a remote-first company headquartered in San Francisco with a globally distributed team, including in-person hubs in Da Nang (Vietnam), Barcelona (Spain), and Menlo Park (California). Our team reflects the diversity and creativity of the people we serve. Join our mission to level the playing field for small business owners through good design.
About the Opportunity
You are the ultimate owner of our technological backbone — from the highly available AWS clusters serving our customers, to the security and compliance posture that keeps our data safe. You'll also partner with our Operations team to help cut down the internal IT friction that slows the rest of the company down.
We're expanding fast, building toward an AI-native product surface with an increasingly complex data and infrastructure footprint. That means the ground under this role won't stay still — what "platform" means here will keep evolving, and we need someone who evolves with it rather than waiting to be told what changed.
We don't believe in silos.
This is a Senior-level, high-autonomy role. You'll be trusted to make judgment calls with real consequences — security, uptime, cost — often without anyone above you double-checking the details.
What You Will Actually Do
- Cloud Infrastructure & DevOps (AWS): Build, monitor, and scale our AWS infrastructure. Manage containerized environments (Docker/Kubernetes) via Terraform/Serverless. "ClickOps" in the AWS console is banned here.
- Aggressive Monitoring: See everything. Use Grafana and AWS tools to monitor the platform. Ensure our autoscaling is ahead of traffic spikes. If it breaks, you know why before the customer does.
- Pragmatic Security: Manage WAF, IAM roles, and implement the technical controls that keep our infrastructure audit-ready for SOC2/ISO. Enforce "Least Privilege" to keep us secure without slowing down the engineering team.
- Zero-Downtime Deployments: Continuously improve our CI/CD pipelines to ensure safe, automated testing. Make deployments boring and routine.
- Keep Infrastructure Ready for What's Next: As we ship new AI-powered features, help make sure the platform underneath — cost, latency, data handling — can actually support them, not just survive them.
- Partner on Internal IT Automation: Work alongside our Operations team to build a more self-serve internal IT experience — API integrations, scripts (Python/JavaScript/etc.), and stronger SSO/IAM — so manual support requests become the exception, not the norm. This is about building the automation and tooling behind IT operations, not being the first point of contact for day-to-day IT support.
What You Need to Be Successful
The Hard Skills:
- Proven experience building high-traffic, Linux-based systems on AWS.
- Strong grasp of Docker, Kubernetes, and Terraform.
- Practical experience with network security and implementing technical controls for compliance frameworks (SOC2/ISO). MDM/IT automation experience is a plus, since you'll partner with our Operations team on this.
Software Engineering DNA: You didn't start your career just plugging in servers; you know how to write real code. Because you have a developer background, you deeply understand how backend applications work, which makes you infinitely better at deploying, securing, and debugging them.
Root Cause Obsession: You don't just reboot a struggling server; you dig deeply into the application logs, find the exact memory leak or database bottleneck, and work with the engineers to fix it permanently.
Question First, Build Second: Before you automate something or spin up new infrastructure, you ask why it's actually needed and what problem it really solves — not just how to build it fastest. You've said "we don't need to build this" before, and meant it.
The Automation Reflex: You hate repetitive work. If you have to do a task twice, you write a script (Python/JavaScript/etc.) to do it automatically next time. You write real automation, not just messy Bash glue-code.
Extreme Ownership (Startup DNA): You operate with high autonomy in a fast-paced environment. You don't wait for a ticket; you hunt for problems and build the solution.
Staying Sharp: Cloud, security, and AI infrastructure practices don't sit still. You proactively learn what's new in the space — new tools, new attack patterns, new AI-ops practices — and bring back what's actually useful, rather than chasing every trend.
Clear Communication: You can explain a complex AWS routing issue to an engineer and patiently help a non-technical employee fix a SaaS access issue — in clear, confident English.
You Will NOT Be a Good Fit Here If
- You enjoy being the "gatekeeper" who holds the keys to every tool, rather than building automations that let teams manage themselves.
- You enforce security policies that force engineers to wait days just to get a basic permission.
- You rely on manual steps for deployments or IT provisioning instead of writing scripts.
- You panic when production traffic unexpectedly spikes by 300%.
- You reach for a new tool or process before understanding whether the underlying problem could be solved more simply.