Senior Security Engineer, Enterprise Security

Braze Braze · Enterprise · New York, NY · Engineering

Senior Security Engineer focused on protecting company employees, assets, and work locations. Responsibilities include investigating threats, implementing security solutions (DLP, SAAS security, hardening), proposing architecture enhancements, developing alerts, building and maintaining security infrastructure, enforcing policies, enhancing SIEM, reviewing business partner technologies, expanding forensics and threat investigation capabilities, securing communications, facilitating compliance, deploying automation, responding to incidents, and mentoring junior staff. The role involves designing, implementing, and managing security solutions, understanding enterprise networking and cloud tech stacks, scaling security infrastructure, acting as a knowledge resource for other security areas, configuring SIEM detections, working within SaaS applications, implementing policy control, aligning with stakeholders, implementing automation for detections and reporting, prioritizing ingestion, maintaining system operability, building new functionality for scale, solving security challenges, participating in on-call rotations, responding to critical incidents, making key decisions on internal product/system deployments, guiding security activities (vulnerability testing, design, investigation), ensuring compliance with security policies, making recommendations for toolset/process improvements, and performing evaluation/recommendation of technology solutions.

What you'd actually do

  1. Design, implement, and manage security solutions to protect Braze’s users and infrastructure
  2. You will need an in-depth understanding of enterprise networking, architecture, and modern user & cloud tech stack. You will be responsible for taking an active role in developing, facilitating, and implementing security infrastructure designed to scale with the organizations growing needs
  3. You will be working to help expand SIEM capabilities by configuring detections and enhancing alerting. You will be working within SaaS applications and automation technologies to develop and document new processes, implement policy control and enforcement, and align with key business stake holders to drive security initiatives
  4. As a senior member of the team, you will work with us to build new functionality that will make it easier, faster, and safer to build for a high scale, growing customer base, and expanding technology footprint
  5. Guide and perform security activities including vulnerability testing and analysis, design and implementation of new solutions/features and investigation into security events

Skills

Required

  • 5+ years of Security Engineering experience
  • strong focus on enterprise security
  • network security
  • endpoint security
  • 3+ years of experience working in a corporate security organization/environment
  • hands on, technical, user facing implementation
  • technical authority in a team environment
  • communication skills
  • organizational skills

Nice to have

  • investigating malware and advanced threats
  • implementing DLP
  • securing SAAS applications
  • hardening internal configurations
  • proposing security architecture enhancements
  • developing alerts & reports
  • building, maintaining, and documenting essential security infrastructure
  • developing and enforcing policies
  • collaborating with other business units to enhance SIEM capabilities
  • reviewing business partner technologies for security improvements
  • expanding upon forensics
  • Threat investigations
  • Malware investigations
  • IAM
  • SSO
  • MDM
  • password management
  • vulnerability remediation
  • securing communications
  • facilitating compliance
  • deploying automation
  • operate independently and collaboratively to implement protective systems
  • mentor junior associates in security concepts
  • participate in on-call rotations
  • respond to critical incidents
  • configuring detections
  • enhancing alerting
  • working within SaaS applications and automation technologies
  • develop and document new processes
  • implement policy control and enforcement
  • align with key business stake holders to drive security initiatives
  • implement automation systems to assist in detections and reporting
  • prioritizing ingestion
  • maintaining system operability
  • build new functionality
  • solve first-in-industry security challenges
  • fill the use cases of our organization
  • work with Security and Engineering resources to help respond to critical incidents and escalations
  • key decision maker regarding internal product and system deployments
  • Guide and perform security activities
  • vulnerability testing and analysis
  • design and implementation of new solutions/features
  • investigation into security events
  • Ensure teams are implementing applications/environments in compliance of defined security policies
  • risk avoidance
  • security best practices
  • Make recommendations on toolset and process modifications and improvements
  • production IT security support
  • Perform the Evaluation and Recommendation of current and future technology solutions
  • mitigate risk to the business
  • Participate in documentation and adherence to Security Policies and Operating Procedures

What the JD emphasized

  • in-depth understanding of enterprise networking, architecture, and modern user & cloud tech stack
  • security infrastructure designed to scale
  • security initiatives
  • build new functionality
  • high scale, growing customer base
  • security challenges
  • critical incidents
  • key decision maker
  • security policies
  • risk avoidance
  • security best practices
  • technology solutions
  • mitigate risk