Infrastructure Security Engineer

Snorkel AI Snorkel AI · Data AI · Redwood City, CA +1 · 312 - Engineering

Security Engineer to enhance Snorkel's security posture across cloud infrastructure, developer platform, and product ecosystem. Responsibilities include securing cloud environments, building security automation, guiding cross-functional initiatives, and embedding security into engineering workflows. The role involves working across infrastructure, platform, product, and application teams to ensure secure scaling and compliance in cloud-native environments. Requires strong fundamentals in cloud security and motivation to grow.

What you'd actually do

  1. Build and scale Infrastructure as Code (IaC) governance strategies that embed security while enabling developer velocity
  2. Operate and tune Cloud Security Posture Management (CSPM) tooling and coordinate remediation through engineering teams
  3. Investigate security events, triage incidents, identify root causes, and own remediation through resolution
  4. Architect secure AWS cloud account structures — landing zones, multi-account patterns, network segmentation, and cross-account role strategies
  5. Design and implement network security architectures using security groups, Network Access Control Lists (NACLs), subnetting, routing layers, and egress controls

Skills

Required

  • Cloud security fundamentals
  • Infrastructure as Code (IaC)
  • Cloud Security Posture Management (CSPM)
  • Security event investigation and incident response
  • AWS cloud architecture (landing zones, multi-account patterns, network segmentation)
  • Network security design (security groups, NACLs, subnetting, routing, egress controls)
  • Kubernetes and container security
  • Identity and Access Management (IAM) architecture
  • Encryption implementation (data-at-rest, data-in-transit, key management)
  • Threat modeling and architecture reviews
  • Security assessment of AI/ML product architectures
  • Secure automation development (Python, AWS-native services, policy-as-code)
  • Project management for security initiatives
  • Familiarity with security frameworks (NIST CSF, ISO 27001, SOC 2, CIS benchmarks)

Nice to have

  • Experience in a growing startup environment
  • Strong communication and influence skills
  • Cross-functional collaboration and partnership
  • Ownership and judgment in ambiguous situations
  • Teaching and enablement abilities

What the JD emphasized

  • Infrastructure as Code (IaC) governance strategies
  • Cloud Security Posture Management (CSPM) tooling
  • security events
  • AWS cloud account structures
  • network security architectures
  • Kubernetes
  • Identity and Access Management (IAM)
  • encryption everywhere
  • threat modeling
  • AI/ML product architectures
  • secure automation
  • Python
  • policy-as-code
  • NIST CSF
  • ISO 27001
  • SOC 2
  • CIS benchmarks
  • security risks
  • technical documentation
  • security priorities
  • security posture
  • developer velocity
  • security controls
  • security guidance
  • evolving threats and technologies