Senior Product Security Engineer, Cloud

MongoDB MongoDB · Enterprise · Dublin, Ireland · Platform Security

Senior Product Security Engineer focused on cloud security for MongoDB Atlas and its underlying cloud platforms (AWS, GCP, Azure). The role involves driving security initiatives, performing security reviews, designing secure architectures, embedding security into platforms via automation, identifying posture gaps, partnering with other security teams, influencing roadmaps, and mentoring engineers. Requires strong experience in application, product, and cloud security, with hands-on cloud security architecture and code reasoning skills.

What you'd actually do

  1. Co-own and drive Atlas cloud security initiatives such as control plane hardening, cloud security baselines, identity and access patterns, customer account protections, and data-plane protections for multi-tenant environments
  2. Perform and lead security reviews for Atlas features and platform changes in cloud environments, including architecture review, threat modeling, and targeted testing, with an emphasis on pragmatic, actionable guidance
  3. Design and review cloud architectures across AWS, GCP, and Azure--covering networking, IAM, secrets management, and service-to-service access--and help define secure reference architectures that can be reused by Atlas teams
  4. Embed security into platforms and guardrails by working with platform, SRE, and other security engineering teams to implement policies and automation (e.g., policy-as-code, secure defaults, pre-deployment checks) that make the secure path the easiest path for developers
  5. Use CSPM, infrastructure vulnerability data, and IaC scanning to identify meaningful posture gaps in Atlas environments and drive concrete hardening work with clear ownership, coverage, and success metrics

Skills

Required

  • cloud security architecture
  • AWS
  • GCP
  • Azure
  • security architecture fundamentals
  • threat modeling
  • risk trade-offs
  • application security
  • data security
  • infrastructure security
  • code reasoning (Go, Java, or similar)
  • IaC (Terraform/CloudFormation)
  • CI/CD
  • security automation tooling (CSPM, IaC scanning, SAST, SCA)
  • security reviews
  • project leadership
  • written and verbal communication
  • ownership
  • collaboration
  • actionable feedback

Nice to have

  • security engineer for multi-tenant SaaS or cloud platform
  • data domain security
  • database domain security
  • infrastructure-as-a-service domain security
  • Atlas-like environments
  • control planes orchestrating resources across multiple cloud providers
  • isolation and blast-radius containment
  • improving signal quality and developer adoption of CSPM, vulnerability management, or IaC scanning
  • public contributions to security community (talks, tools, standards, publications)
  • mentoring other security engineers
  • bar-raiser in interviews

What the JD emphasized

  • 7+ years of experience in application, product, and/or cloud security for large-scale, customer-facing systems, ideally in a multi-cloud or SaaS environment
  • Strong, hands-on experience with cloud security architecture on at least one major cloud provider (AWS, GCP, or Azure), with familiarity across
  • Solid security architecture fundamentals: able to design and review end-to-end systems, reason about threat models and risk trade-offs, and recommend appropriate controls across application, data, and infrastructure layers
  • Demonstrated experience leading security reviews and projects in partnership with engineering teams (e.g., threat modeling, design reviews, targeted testing) and turning findings into pragmatic, prioritized remediation work