Security Engineer (l5) - Cloud Architecture, Tooling and Security

Netflix Netflix · Big Tech · United States · Remote · Engineering

Security Engineer role focused on cloud security, IAM, and building tooling/scripting for AWS and GCP environments at Netflix. This role is primarily about securing cloud infrastructure and enabling business needs through secure access patterns and boundaries, rather than directly building AI/ML models.

What you'd actually do

  1. design and implement appropriate, scalable cloud security solutions
  2. design and implement new cloud security strategies and archetypes to discover, self-serve, right-size, and manage cloud resources
  3. develop internal tooling and scripting for GCP to build capabilities where few currently exist
  4. perform threat assessments, apply knowledge of AWS architecture and new AWS services to address security requests
  5. contribute to operational excellence by reducing risks and eliminating tedious access management minutiae

Skills

Required

  • Cloud security fundamentals
  • CloudSec operations
  • AWS account management
  • Security Architecture
  • GCP expertise
  • architect and implement organization-wide security guardrails
  • identity governance
  • defining secure-by-default blueprints for GCP project lifecycles
  • service account management
  • building foundational tooling and org-level security patterns
  • collaborating with product and engineering teams to design security solutions
  • Strong verbal and written communication skills
  • pragmatic approach to security
  • identify high-leverage work and drive it independently
  • Experience securing challenging 3rd-party cloud infrastructure access patterns
  • Experience defining insightful and meaningful metrics to gauge and guide cloud security posture or progress
  • Experience in an L5 role driving mid-complexity projects independently and navigating ambiguity
  • build scrappy tooling/scripting and data analysis tools

Nice to have

  • AWS architecture
  • new AWS services

What the JD emphasized

  • GCP expertise is a must
  • architect and implement organization-wide security guardrails
  • identity governance
  • defining secure-by-default blueprints for GCP project lifecycles and service account management
  • building the foundational tooling and org-level security patterns where few currently exist