Lead - Platform Security Engineer — On Running
- Location
- Zürich
- Contract
- temporary
- Posted
- 77 days ago
Role overview
In short
At On, our technology moves as fast as our runners: always evolving, always pushing boundaries.
We're building a world-class platform to ignite the human spirit through movement, and our Information Security team is the trusted guardian of that mission.
- In short
- At On, our technology moves as fast as our runners: always evolving, always pushing boundaries.
Application process
- You bring 10+ years of experience in security engineering, platform security, cloud security, DevSecOps, application security, or infrastructure security.
- You have hands-on experience contributing to engineering workflows using Git, pull requests, code reviews, CI/CD pipelines, automation, or infrastructure-as-code.
- You are comfortable working with cloud environments, ideally including Google Cloud Platform, and understand cloud IAM, network exposure, platform security, and secure configuration patterns.
- You have practical experience with vulnerability remediation and know how to move from finding to fix, including validating closure and preventing recurrence.
- You understand CI/CD security and have experience with controls such as secrets scanning, dependency scanning, SAST, infrastructure-as-code scanning, policy-as-code, or secure build pipelines.
- You are familiar with identity and access security concepts, including least privilege, privileged access, service accounts, non-human identities, temporary access, and credential rotation.
- You are able to translate threat models, risk scenarios, and architecture requirements into concrete technical controls that engineers can implement and operate.
- You are curious about emerging AI security risks and motivated to secure modern development workflows involving AI-generated code, coding agents, MCP servers, and automation.
Additional details
- This role is for someone who sees security not as a gate, but as a force multiplier for engineering excellence.
- Participate in operational ownership for security-relevant infrastructure and controls you materially contribute to, including root-cause analysis and incident remediation where needed.
- You have a pragmatic mindset and know how to balance speed, security, engineering quality, and business impact.
- Your mission is to protect the company’s infrastructure and applications by being a pragmatic, trusted, and a collaborative partner to Engineering.
Notes and original content
- Your mission
- Your story
- Meet the team
- What we offer
Questions about this listing
What salary does On Running offer for this role?
On Running lists CHF 101'500 - 154'000 gross per year for this position in Zürich. This is the salary published in the original listing (or, when the employer omits a figure, a realistic estimate for the role and sector) — the calculator on this site converts it to your actual net take-home once cross-border tax and social contributions are applied.
Is this a full-time role, and what type of contract does On Running offer?
This listing is a fixed-term contract position. The contract type shown here comes directly from the employer's original posting; always confirm exact hours, notice period and probation length with On Running during the application process, since these details can vary by role even within the same contract category.
Do I need a cross-border work permit for a role in Zürich?
EU/EFTA residents living in the border zone of the country adjoining Canton Zürich can apply for a G permit; the Swiss employer files it with that canton's migration office after the contract is signed. Border-zone rules and processing times vary by neighbouring country and canton, so confirm the specifics with Zürich's cantonal migration office or with HR during the application.
How do I apply for this position at On Running?
Use the "Apply now" button on this page — it links directly to On Running's original listing at boards.greenhouse.io, so your application goes straight to the employer's own applicant-tracking system. Frontaliere Ticino does not collect or forward applications itself.