Staff Security Engineer

Job not on LinkedIn

🔥 5 hours ago

🍂 Massachusetts, Texas – Remote

info

💵 $170k - $205k / year

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

info
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Snyk

Snyk

1001 - 5000 employees

🔐 Security

☁️ SaaS

Security • SaaS

Snyk is an AI-powered application security platform that helps developers and security teams find, prioritize, and fix vulnerabilities across code, open-source dependencies, containers, infrastructure-as-code, APIs, and web applications. It offers developer-first tooling and integrations that shift security left in the SDLC, combining static and dynamic testing, software composition analysis, runtime scanning, and an AI-driven “AI Trust” ecosystem delivered as a cloud platform. Snyk focuses on DevSecOps automation, software supply chain risk, and secure development workflows for organizations of all sizes.

📋 Description

• Own cloud security posture across AWS and GCP • Drive coverage and signal quality, prioritize remediation by exploitability, and report posture trends • Lead cloud IAM and least privilege across accounts and projects • Own security posture of the enterprise identity platform, including authentication, authorization, MFA, privileged access, and joiner/mover/leaver enforcement • Hunt and eliminate cloud attack paths involving privilege escalation, lateral movement, and data exposure • Build preventative guardrails in infrastructure as code, admission control, CI checks, and organization policy • Build AI and agentic automation for posture remediation, access reviews, evidence gathering, and investigation enrichment • Establish controls for internal AI and agent use, including agent permissions, MCP server trust, third-party AI risk, and identity/data boundaries • Secure cloud infrastructure behind Snyk’s AI capabilities, including IAM, network segmentation, and data controls • Strengthen cloud detection and response using control-plane and workload telemetry • Act as cloud subject matter expert during incidents • Defend the edge through WAF, DDoS posture, and cloud deception coverage • Partner with Platform and Infrastructure Engineering, Product Security, and Compliance to implement controls • Support cloud controls in Snyk’s public sector environment • Mentor engineers, serve as an escalation point for complex investigations, and participate in the EntSec on-call rotation

🎯 Requirements

• 8+ years in security engineering, including at least 4 years focused on securing production-scale cloud environments • Expert-level AWS security and strong working knowledge of GCP • Ability to reason about IAM policy evaluation, organization-level guardrails, network and VPC design, key management, encryption, and logging architecture • Deep hands-on cloud IAM expertise across multi-account and multi-project estates • Experience with non-human identities, workload identity federation, and secrets management at scale • Understanding of cloud compromise techniques, including credential and token abuse, IAM privilege escalation, metadata and workload identity abuse, exposed storage and services, CI/CD, and supply-chain paths • Ownership of an enterprise CSPM or CNAPP platform • Infrastructure as code and coding ability using Terraform, Python, or Go • Kubernetes security knowledge, including RBAC, service accounts, token handling, admission control, workload identity, network policy, and container runtime posture • Practical experience applying AI to engineering work using LLM APIs or agent frameworks • Understanding of AI-specific risks including prompt injection, over-permissioned agents and tools, untrusted tools and MCP servers, and data leakage • Hands-on enterprise identity platform security experience with a major IdP • Cloud detection fundamentals, provider audit logs, native threat detection services, SIEM telemetry, and detection logic • Strong written communication and stakeholder influence • Bachelor's degree in computer science, information security, or information technology, or equivalent practical experience • Relevant security certifications are welcomed but not required

🏖️ Benefits

• Annual base salary of $170,000 - $205,000 plus bonus • Flexible working hours • Work-from-home allowances • In-office perks • Time off for learning and self development • Generous vacation and wellness time off • Country-specific holidays • 100% paid parental leave for all caregivers • Health benefits • Employee assistance plans • Annual wellness allowance • Country-specific life insurance • Disability benefits • Retirement/pension programs • Mobile phone allowances • Education allowances • Employee resource groups

Apply Now

Similar Jobs

🔥 6 hours ago

Chainguard

51 - 200

🔐 Security

☁️ SaaS

🔒 Cybersecurity

Staff Product Security Engineer securing Chainguard's hardened open-source software supply chain. Building secure pipelines and hardening Kubernetes workloads across GCP and AWS.

🔥 6 hours ago

Collibra

1001 - 5000

💼 Consulting

🏥 Healthcare

📦 Logistics

Collibra public-sector security leader overseeing FOCI mitigation, DCSA compliance, personnel clearances, and Insider Threat programs. Building CPS’s long-term security foundation under its Proxy Agreement and National Industrial Security Program.

🔥 6 hours ago

Optiv

1001 - 5000

Regional cybersecurity sales director leading Optiv’s complex security solutions revenue across the South Atlantic. Recruiting, coaching, forecasting, and expanding executive client and partner relationships.

🔥 7 hours ago

GE HealthCare

10,000+ employees

🏥 Healthcare

💊 Pharmaceuticals

Staff Cyber Security Engineer securing GE HealthCare’s cloud, on-premises, and medical technology environments. Leading architecture, vulnerability management, risk analysis, and compliance initiatives.

🔥 10 hours ago

General Dynamics Information Technology

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Information System Security Officer securing USPS systems through enterprise Splunk architecture and compliance. Supporting cloud, Unix/Linux, risk assessments, and A&A processes.