Senior Product/Cloud Security Engineer

Posted Yesterday
Be an Early Applicant
4 Locations
Remote or Hybrid
Senior level
Software
The Role
Lead cloud and product security for JetBrains Air across AWS and GCP. Define security baselines, operate vulnerability-management platforms, conduct architecture reviews and threat modeling, prioritize remediation, embed security controls into CI/CD and IaC workflows, support incident response, and develop security metrics. Partner closely with platform engineering, SRE, and product teams to integrate practical security controls into development workflows.
Summary Generated by Built In

Are you excited by the challenge of strengthening the security of cloud platforms without slowing engineering teams down? We believe that real cloud security is about setting smart baselines, modeling threats early, and embedding guardrails directly into developer workflows, and we’re keen to hear about how you can help us implement this mentality

About JetBrains

We create intelligent software development tools for developers and teams. More than 15 million users, over 300,000 companies, and 88 of the Fortune Global Top 100 rely on our products to solve real, complex problems. Our mission is simple: make development teams more productive and AI adoptable at scale.

What you’ll do

As our cloud footprint grows, we are investing heavily in the security of the platforms and products that support them. We are looking for a Senior Product/Cloud Security Engineer to help us strengthen the security of the JetBrains Air platform and the services built on top of it.

In this role, you’ll take ownership of cloud and product security across our AWS and GCP environments. You’ll work directly on design choices, architecture reviews, and automation that reduce risk across the entire software development lifecycle. You’ll partner closely with platform engineering, SRE, and product teams to make secure choices the easiest path for developers.

You will have substantial ownership and influence across teams while staying close to technical details.

Day to day, you will:

  • Lead and continuously improve cloud security across JetBrains Air, including security posture, preventive controls, detection, and remediation.
  • Define, maintain, and measure security baselines for AWS and GCP environments, covering IAM, networking, data protection, and workload configuration.
  • Operate and evolve cloud security platforms and vulnerability-management solutions (e.g. Wiz, Orca Security, Upwind, Tenable, etc.).
  • Establish effective processes for triaging, prioritizing, assigning, and remediating cloud security findings and vulnerabilities.
  • Partner with platform engineering, SRE, and product engineering teams to design and implement practical security controls that fit naturally into developer workflows.
  • Perform security design and architecture reviews for cloud services, APIs, and integrations. Conduct threat modeling and risk assessments to provide clear, actionable recommendations.
  • Review product and platform changes for security implications throughout the entire software development lifecycle, from early design to production.
  • Help improve security automation by integrating security checks, guardrails, and evidence into engineering and delivery pipelines.
  • Support incident response, root-cause analysis, and drive systemic improvements that reduce recurrence.
  • Develop meaningful metrics for cloud and product security, communicate trends and risks, and help prioritize security investments.
  • Contribute to security standards, guidance, runbooks, and patterns that make secure engineering easier across JetBrains.
What you’ll bring
  • A pragmatic engineering mindset that balances security controls with developer velocity.
  • A strong sense of ownership and the initiative to spot complex risks and address them early.
  • Excellent communication skills, with the ability to explain technical trade-offs clearly to both engineers and stakeholders.
  • A collaborative mentality when working across distributed teams and engineering disciplines.
  • A high bar for quality and a commitment to building sustainable, long-term security baselines.
  • A curious and analytical approach to threat modeling and architectural risk.
What you’ll need
  • Established professional experience in security engineering or a closely related technical security domain, securing SaaS products or cloud-native services.
  • Strong experience with AWS and/or GCP security – specifically the ability to assess architecture and configurations directly, rather than relying solely on tool outputs.
  • Practical experience deploying, operating, or integrating cloud security and vulnerability-management platforms (e.g., Wiz, Orca Security, Upwind, Tenable).
  • Hands-on experience with security architecture reviews, threat modeling, vulnerability management, and risk-based prioritization.
  • Solid understanding of modern SaaS architectures (APIs, microservices, containers, Kubernetes, identity providers, networking, and managed cloud services).
  • Experience working closely with engineering, SRE, and product teams to translate security requirements into practical engineering solutions.
  • Excellent written and spoken English.
Nice to have
  • Experience building security automation or integrating security controls into CI/CD and infrastructure-as-code (IaC) workflows.
  • Hands-on experience with Terraform or other IaC tools.
  • Experience securing Kubernetes-based platforms and containerized workloads.
  • Familiarity with detection engineering, cloud-native logging and monitoring, or security operations workflows.
  • Scripting or programming experience in Python, Go, Kotlin, Java, or a similar language.
  • Experience contributing to SOC 2, ISO 27001, or other security and compliance frameworks for SaaS products.
  • Experience supporting customer-facing conversations about cloud, product, or platform security.
What success looks like

In this role, success means security is seamlessly integrated into how our platform and product teams build software. You’ll have established clear, measurable security baselines across our cloud infrastructure, reduced actionable security findings, and built strong trust with engineering teams so that threat modeling and security reviews happen naturally early in design.


Why join JetBrains? 

  • Strong base salary. We offer competitive pay that reflects your skills and experience.
  • Flexible work location. Enjoy the freedom to work from home or from the office.
  • Remote work. Spend up to 30 days per year working remotely from abroad.
  • Extra time off. More days to relax, recharge, and do the things you love.
  • Medical insurance allowance. Enjoy peace of mind for you and your family
  • Learning and development opportunities. Access to conferences, courses, and language classes.
  • Relocation support. We help make your move as smooth and stress-free as possible. 
  • Language classes. Pick up the local language or sharpen your English skills.
  • Fuel your day. Enjoy a hot meal or receive a lunch allowance on workdays.
  • Mental health support. To help you feel your best, we provide easy access to professional mental health services.
  • Sports benefit. Enjoy an on-site gym or sports club stipend.
  • Internal events. Join company-wide celebrations and team gatherings.

*Some benefits may vary depending on location.

#LI-HYBRID 
#LI-EP1 

We are an equal opportunity employer
We know great ideas can come from anyone, anywhere. That’s why we do our best to create an open and inclusive workplace – one that welcomes everyone regardless of their background, identity, religion, age, accessibility needs, or orientation.

We process the data provided in your job application in accordance with the Recruitment Privacy Policy.

Skills Required

  • Professional experience in security engineering or a closely related technical security domain
  • Experience securing SaaS products or cloud-native services
  • Strong experience with AWS and/or GCP security, including direct architecture and configuration assessment
  • Experience deploying, operating, or integrating cloud security and vulnerability-management platforms such as Wiz, Orca Security, Upwind, or Tenable
  • Experience with security architecture reviews, threat modeling, vulnerability management, and risk-based prioritization
  • Understanding of SaaS architectures, APIs, microservices, containers, Kubernetes, identity providers, networking, and managed cloud services
  • Experience partnering with engineering, SRE, and product teams to translate security requirements into practical engineering solutions
  • Excellent written and spoken English
  • Experience building security automation or integrating security controls into CI/CD and infrastructure-as-code workflows
  • Hands-on experience with Terraform or other infrastructure-as-code tools
  • Experience securing Kubernetes-based platforms and containerized workloads
  • Familiarity with detection engineering, cloud-native logging and monitoring, or security operations workflows
  • Scripting or programming experience in Python, Go, Kotlin, Java, or a similar language
  • Experience contributing to SOC 2, ISO 27001, or other security and compliance frameworks for SaaS products
  • Experience supporting customer-facing conversations about cloud, product, or platform security

JetBrains Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about JetBrains and has not been reviewed or approved by JetBrains.

  • Fair & Transparent Compensation — Fair & Transparent Compensation: Pay is considered market-competitive for many product and engineering roles in key locations, with published salary ranges on some postings aiding expectation-setting. Feedback suggests total compensation feels fair relative to local markets even if packages are positioned as “competitive but not top‑of‑big‑tech”.
  • Flexible Benefits — Flexible Benefits: Work setup includes hybrid/remote options and flexible hours across many locations. The ability to work abroad for part of the year adds practical flexibility to where work gets done.
  • Leave & Time Off Breadth — Leave & Time Off Breadth: Time off includes additional vacation days beyond local minimums in many countries. U.S. materials also highlight PTO, sick leave, and holidays, underscoring breadth beyond statutory baselines.

JetBrains Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Praha
2,209 Employees
Year Founded: 2000

What We Do

JetBrains creates intelligent software development tools consistently used and trusted by 11.4 million professionals and 88 Fortune Global Top 100 companies. Our lineup of more than 30 products includes IDEs for most programming languages and technologies, such as IntelliJ IDEA, PyCharm, and others, as well as products for team collaboration, like YouTrack and TeamCity. JetBrains is also known for creating the Kotlin programming language, a cross-platform language used by more than 5 million developers worldwide yearly and recommended by Google as the preferred language for Android development. The company is headquartered in Prague, Czech Republic, and has offices around the world. JetBrains IDEs * IntelliJ IDEA (Java and Kotlin Developers) * PyCharm (Python developers) * PhpStorm (PHP developers) * GoLand (Go developers) * Rider (.NET developers) * CLion (C and C++ developers) * Rust Rover (Rust developers) * WebStorm (JavaScript & TypesScript developers) * RubyMine (Ruby and Rails developers) * DataGrip (Tool for multiple databases) * ReSharper (Extension for Visual Studio) * Fleet (Multilingual IDE and code editor) * Aqua (IDE for test automation engineers) .NET & Visual Studio: * Rider (IDE for .NET developers) * ReSharper (Extension for Visual Studio) * ReSharper C++ (Visual Studio Extension for C++ developers) * dotCover (.NET Unit Test Runner and Code Coverage Tool) * dotMemory (.NET Memory Profiler) * dotTrace (.NET Performance Profiler) * dotPeek (.NET decompiler and assembly browser) Team Tools: * TeamCity (Powerful CI out of the box) * YouTrack (Project management for all your teams) * Space (Intelligent code collaboration platform) * Datalore (Collaborative data science platform) * Qodana (Code quality platform for teams) Programming Languages: * Kotlin (Programming Language for the JVM and Android) * MPS (Create Your Own Domain-Specific Language) Education: * JetBrains Academy (Learn and Teach Computer Science) Profile by JetBrains s.r.o.

Similar Jobs

Pfizer Logo Pfizer

Manager, Incentive Compensation

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote or Hybrid
32 Locations
121990 Employees

Samsara Logo Samsara

Consultant

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
Germany
4000 Employees

Atlassian Logo Atlassian

Senior Manager, Customer Success, Strategic - DACH

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
Munich, Bayern, DEU
11000 Employees

NinjaOne Logo NinjaOne

Senior Software Engineer

Information Technology • Productivity • Software • Infrastructure as a Service (IaaS)
Remote or Hybrid
Germany
2000 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account