Staff Security Engineer

Snyk Snyk · Enterprise · MA, United States, United States · Remote

Staff Security Engineer responsible for cloud and identity security in a multi-cloud environment, focusing on AI-driven automation for security tasks, securing AI adoption, and defending the cloud infrastructure supporting AI capabilities. The role involves threat-driven adversarial thinking, building preventative guardrails, and applying AI/LLMs to automate security operations.

What you'd actually do

  1. Owning cloud security posture across AWS and GCP - Driving coverage and signal quality, prioritising by exploitability rather than raw severity counts, holding remediation accountability with the teams that own the resources, and reporting posture as a trend over time.
  2. Leading cloud IAM and least privilege. Designing and enforcing permission models across accounts and projects: organization level policy and guardrails, permission boundaries, cross-account role design, workload identity federation, and the full lifecycle of non-human identities, keys, and secrets.
  3. Hunting and eliminating cloud attack paths. Reasoning about chained privilege escalation, lateral movement between accounts and workloads, and data exposure, then removing the conditions that make those chains possible.
  4. Building preventative guardrails. Pushing controls into infrastructure as code modules, admission control, CI checks, and organization policy so that misconfigurations fail before deployment rather than getting caught afterwards.
  5. Building AI and agentic automation for security work. Using LLMs and agents to automate posture remediation, access reviews, cloud evidence gathering, and investigation enrichment. Turning repeatable expert judgment into tooling the whole team can run.

Skills

Required

  • 8+ years in security engineering
  • at least 4 focused specifically on securing cloud environments at production scale
  • Expert level AWS security
  • strong working knowledge of GCP
  • Deep, hands-on cloud IAM expertise
  • An attacker's understanding of cloud
  • Infrastructure as code
  • Terraform
  • Python or Go
  • Kubernetes security in the cloud
  • Practical experience applying AI to engineering work
  • built something real with LLM APIs or agent frameworks

Nice to have

  • ideally within the EST/CST timezone

What the JD emphasized

  • AI-driven automation
  • AI and agentic automation for security work
  • Securing Snyk's AI adoption
  • Securing the cloud infrastructure behind Snyk's AI capabilities
  • adversarial and threat driven rather than compliance driven
  • expert level AWS security
  • Deep, hands-on cloud IAM expertise
  • An attacker's understanding of cloud
  • Practical experience applying AI to engineering work

Other signals

  • AI-driven automation
  • AI and agentic automation for security work
  • Securing Snyk's AI adoption
  • Securing the cloud infrastructure behind Snyk's AI capabilities