The job
VerifyYou is building infrastructure that keeps the internet human. Co-founded by Reddit's former CTO, Marty Weiner, we're focused on solving identity online and enabling platforms to stop bots and fake accounts.
We're hiring a senior platform engineer (5+ years, deep GCP, security-minded) to own the infrastructure underneath that layer. This is the first dedicated platform role at the company. You'd own the deploy path, the access model and the security posture from day one, because nobody owns them today.
What you'll do
- Own IAM and the access model. Move off individually granted permissions onto groups, with Google Workspace as the source of truth and every other system binding to groups rather than people.
- Get Terraform onto a gated path. Build an auditable apply flow using Workload Identity Federation, plan on PR, and approval before anything reaches production. The reusable workflows already exist and nothing calls them yet.
- Own secrets and the credential store, working toward no human holding a long-lived credential anywhere.
- Own the edge. WAF posture, rate limiting and bot mitigation. Adversarial traffic is our product domain, so this work sits close to the thing we sell.
- Build controls that produce their own evidence, so access reviews and change management run as queries against real systems instead of spreadsheets somebody keeps up by hand.
- Own reliability as pilot customers scale. You help us ensure we find out before the customer does
The charter
- Infrastructure as Code. Terraform conventions, module structure, and building out the CI apply path.
- Reliability. Capacity planning, synthetic health checks, alerting, and standing up on-call properly.
- Observability. Structured logs, traces joining the edge to the app, and the audit trail in BigQuery.
- Edge policy hardening. Taking our edge policy from deployed-and-observable to actually enforcing, without breaking live traffic.
- Identity and access. Environment-scoped groups, human database IAM, API-key hashing and rotation.
- Backups and DR. Recovery objectives, restore drills, and making the commitments and the infrastructure agree.
Alongside that, our GRC program is actively executing on SOC 2 and our security posture. A partner runs the audit itself, but you'd build and operate what it measures.
Our stack
- Cloud: GCP. Cloud Run, Secret Manager, Artifact Registry, Cloud Logging, Workload Identity Federation, Cloud Armor, and Cloud CDN behind a shared HTTPS load balancer.
- IaC and CI: Terraform with a shared internal module library; GitHub Actions with reusable workflows.
- Services: Python 3.14 on FastAPI. One primary backend, on Cloud Run.
- Data: Cloud SQL Postgres 18, Firestore in Native mode, Memorystore Valkey, BigQuery, Pub/Sub.
- Frontends: two React + TypeScript apps, served as static bundles from Cloud Storage.
- AWS: a deliberately small footprint, reached from GCP for parts of our architecture.
- Local: the whole stack runs as one docker compose project with emulators.
You'll write Python and Terraform. You'll integrate with the frontends but you won't own them. You get to decide what we adopt next.
What we need
Required:
- 5+ years running cloud infrastructure in production, with deep and current GCP and/or AWS.
- Terraform in a team setting: modules, state, review, and the discipline of never applying by hand.
- A CI/CD path you built and would defend, including gated applies and rollback that actually works.
- Cloud IAM as a design problem: least privilege, group-based access, workload identity, and why humans shouldn't hold long-lived credentials.
- SRE or DevOps practice in production. You've carried a pager and run incident response.
- Hands-on serverless experience: Cloud Run, Lambda, Azure Functions, or equivalent.
- Observability you've instrumented yourself, OpenTelemetry included, and a view on what's actually worth alerting on.
- You read and write application code. Python here. This is not a pure ops role.
- You work effectively with AI tooling and know where it's wrong. Coding agents and AI-assisted review are part of how we ship. We also don't take a bot's severity rating at face value, and neither should you.
Nice to have:
- Time inside a SOC 2 or ISO 27001 estate, enough to know why an auditor asks for what they ask for.
- Abuse prevention at the edge: WAF, rate limiting, bot mitigation.
- Database Administration: connection pooling, read replicas, failover.
- Cost engineering: attribution, unit economics, spend that scales sub-linearly with customers.
- Operating without a platform team around you. You were the person, or one of two.
How we work
Small team, high autonomy, low ceremony. You'd have a real stake in technical direction instead of inheriting someone else's five-year-old decisions. Most of what we're building is close to greenfield.
We run on Linear for execution, Figma for design, Notion for anything durable, and GitHub with agentic code review in the loop. We care a lot about developer experience. If a workflow gets in the way of shipping, we fix it.
Why VerifyYou
The internet has evolved into critical infrastructure, but its trust model hasn't kept pace. AI has made synthetic participation trivial, and legacy solutions like KYC, CAPTCHAs and phone verification are either fragile or invasive. We're building verification infrastructure that proves humanness while keeping personal data private.
You'll own real surface area, ship to production fast, and work directly with the founders and senior technical leadership. The platform has real gaps, which is why this role exists. You'd have the latitude to fix them properly the first time.
Details
- Location: Remote
- Type: Full-time
- Compensation: Competitive base, plus meaningful early-stage equity.
Interview process
No take-home and no algorithm puzzles. The technical round is a conversation about problems we actually have.
- Intro with the Head of Engineering, about 45 minutes.
- Technical conversation with the Head of Engineering and one engineer, drawn from our real estate, about 60 minutes.
- Team conversation with peers, about 45 minutes.
- Founder conversation, about 30 minutes.
How to apply
Complete the form below with:
- Your resume.
- A repo, a write-up, or a description of a system you designed and operated. Infrastructure work often isn't public, so a short write-up of something you built and what you'd change about it is fine.
We're looking for builders with a strong desire to learn and the urgency to deliver high-quality product.
Referrals: $5,000 referral bonus paid on hire (after 90-day retention) for any candidate who lands the role and credits the referrer in their application.