Senior Cloud Security Engineer

Braze Braze · Enterprise · New York, NY · Engineering

Senior Cloud Security Engineer role focused on securing cloud-native SaaS infrastructure (AWS, GCP, Kubernetes), implementing security controls, managing vulnerability management, optimizing security tooling, performing threat modeling, contributing to incident response, securing IaC and CI/CD pipelines, and enhancing cloud logging and monitoring. Requires strong Python skills for automation and familiarity with security frameworks.

What you'd actually do

  1. Working closely with Infrastructure, SRE, and Product Engineering to design secure cloud architectures and develop practical, scalable security controls for new and existing services
  2. Implementing and improving end-to-end cloud security controls across AWS, GCP, Kubernetes, CI/CD pipelines, and self-managed systems
  3. Leading and improving our existing vulnerability management workflow for cloud assets, including scanning, triage, prioritization, and remediation with tools like Tenable and native CSP capabilities
  4. Managing and optimizing security tooling such as CrowdStrike (EDR/CSPM/IR), cloud-native security services, and SIEM detection rules (with the help of our existing SIEM Management function)
  5. Performing threat modeling for new cloud technologies and patterns adopted across engineering

Skills

Required

  • Cloud Security
  • Infrastructure Security
  • DevSecOps
  • AWS security
  • IAM
  • control plane security
  • network controls
  • logging
  • monitoring
  • cloud-native security services
  • GCP security
  • Kubernetes/K8’s
  • CrowdStrike
  • Tenable
  • CSPM/CWPP tooling
  • incident responder in cloud environments
  • run-time security
  • CSPM concepts
  • cloud forensics
  • vulnerability management workflows
  • RBAC
  • CI/CD pipelines
  • Infrastructure-as-Code (Terraform preferred)
  • Python
  • SOAR workflows
  • distributed systems
  • MongoDB
  • SOC 2
  • ISO 27001
  • NIST
  • patch management
  • base image hardening
  • version management

Nice to have

  • Azure familiarity
  • hands-on experience securing large-scale, high-throughput distributed systems
  • demonstrated expertise in cloud forensics
  • experience managing or operating enterprise-scale CSPM programs
  • experience contributing to SOAR pipelines or building automated remediation systems
  • prior experience in the SaaS space
  • contributions to open-source cloud or security projects
  • published research, CVEs, conference talks, or community-led cloud security work
  • experience conducting or integrating cloud penetration testing or adversarial simulation techniques

What the JD emphasized

  • deep cloud security expertise
  • expert level skills in modern enterprise networking
  • Expert-level knowledge of AWS security
  • Proven track record as an incident responder in cloud environments
  • Deep operational experience with IAM, RBAC
  • Strong Python skills for automation