Senior Security Engineer, Cloud Platform

Posted 3 Days Ago
Be an Early Applicant
Menlo Park, CA
In-Office
Senior level
Software • Big Data Analytics
The only SQL engine that is fast enough to run the most demanding workloads directly on your data lakehouse.
The Role
The Senior Security Engineer will secure cloud platforms, drive threat modeling, ensure data protection, manage vulnerabilities, and enable incident readiness.
Summary Generated by Built In

About CelerData

At CelerData, our mission is to empower organizations to fully leverage their data. We achieve this with our cutting-edge, cloud-native, high-performance analytical database, specifically designed for modern lakehouse architectures. We're challenging established solutions like Snowflake, ClickHouse, and Trino by delivering unmatched query performance and a simplified architecture to enterprises globally. Join us as we help our customers convert their data into practical insights and attain outstanding technical achievements.

Job Overview  

As a Product Security Engineer at CelerData, you’ll embed with our platform and cloud teams to design and build secure-by-default features for StarRocks and CelerData Cloud. You will drive threat modeling, security assurance, and automation across our control plane, data plane, and BYOC (bring-your-own-cloud) deployments. Your work will span identity, secrets and key management, container/Kubernetes hardening,operating security tooling, and vulnerability management—scaling security through paved roads, tooling, and code.

Key Responsibilities  
  • Secure design & threat modeling: Partner with PM/engineering to review architectures and data flows (SaaS, on-prem, BYOC). Define security requirements and mitigations for features such as multi-tenant isolation, row/column-level security, auditing, and encryption.
  • Security Process: Develop processes, tooling and automation to scale security processes and mitigate risks to the business
  • Cloud & Kubernetes hardening: Establish secure baselines for AWS/Azure/GCP; least-privilege IAM; network segmentation and private connectivity (e.g., PrivateLink/Private Endpoint); runtime policies (e.g., Cilium/Calico), admission controls, and secrets handling for K8s.
  • Identity & secrets: Advance SSO/MFA for customers and internal systems; standardize OIDC/SAML flows; engineer passwordless and m2m auth; manage KMS/HSM-backed key lifecycles; integrate with Vault for automated rotation.
  • Data protection: Ensure encryption in transit/at rest for object stores (S3/ADLS/GCS) and internal services; define data classification and tokenization/obfuscation patterns where appropriate.
  • Vulnerability management & assurance: Run coordinated scanning/fuzzing (including C++ components), triage reports (bug bounty/responsible disclosure), drive fixes to closure with clear SLAs, and commission targeted pentests.
  • Detection enablement: Improve security telemetry across control and data planes; contribute product-centric detections/runbooks for abuse, exfiltration, or privilege misuse.
  • Incident readiness: Maintain product incident playbooks; participate in investigations affecting CelerData products and customers; lead post-mortems and drive durable remediation.
  • Developer enablement: Provide clear guidance, examples, and “paved road” modules (Terraform/K8s manifests, SDK patterns). Deliver practical, lightweight training on secure coding and secrets hygiene.
Qualifications  

Minimum Requirements

  • 5+ years in product/application, platform, or cloud security supporting engineering teams shipping distributed systems at scale (or comparable impact).
  • Hands-on with at least one major cloud (AWS/Azure/GCP) and Kubernetes security (RBAC, admission, PSP replacements, runtime policies, image signing).
  • Proficiency in at least one of: Python or Go for automation; plus the ability to read and review C++ and/or Java for security implications.
  • Solid grasp of authN/Z patterns (OIDC/SAML, OAuth2, service-to-service auth), secrets and key management (KMS/HSM, Vault), and TLS mTLS fundamentals.
  • Experience designing controls for multi-tenant SaaS or BYOC architectures (isolation, network egress controls, private connectivity, least-privilege IAM).
  • Clear, pragmatic communicator who can influence design, document decisions, and drive cross-team execution.

Preferred Qualifications

  • Fuzzing experience (e.g., libFuzzer/AFL/OSS-Fuzz) or sanitizers for native code; prior work securing OLAP/DB, storage engines, or high-performance C++ services.
  • IaC security (Terraform + Conftest/OPA checks), cloud org guardrails, SCP/Config/Policy, and drift detection.
  • Familiarity with data security features (RLS/CLS, masking, audit/eventing) in analytics platforms.
  • Contributions to open-source projects (StarRocks/ClickHouse/Trino ecosystems a plus).
  • Relevant certifications (AWS/Azure/GCP security, CNCF/K8s), or equivalent demonstrable experience

Top Skills

AWS
Azure
C++
GCP
Go
Java
Kubernetes
Python
Terraform
Vault
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Menlo Park, CA
68 Employees
Year Founded: 2022

What We Do

CelerData Cloud is the fastest, secure analytical engine that powers customer-facing and AI-driven analytics at scale, delivering consistently reliable and unbeatable performance with a future-proof architecture—ensuring real-time access to open data without ingestion delays or costly data pipelines.

Powered by StarRocks, CelerData delivers 3X the performance/cost of any other solution on the market and is the only platform uniquely designed to enable users to simplify their lakehouse architecture and ditch the need for a data warehouse.

CelerData is used worldwide by market-leading brands including Coinbase, Pinterest, Demandbase, and Expedia to generate critical new insights for these data-driven companies.

Similar Jobs

Anduril Logo Anduril

Capability Associate, Air Defense

Aerospace • Artificial Intelligence • Hardware • Robotics • Security • Software • Defense
In-Office
Irvine, CA, USA
6000 Employees
98K-130K Annually

Motive Logo Motive

Software Engineer

Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Easy Apply
In-Office
5 Locations
4000 Employees
119K-171K Annually

Whatnot Logo Whatnot

Recruiter

eCommerce • Mobile
In-Office
4 Locations
750 Employees
105K-140K Annually

Crunchyroll Logo Crunchyroll

Principal Systems Transformation Manager

Digital Media • eCommerce • Gaming • Mobile • News + Entertainment
Hybrid
Los Angeles, CA, USA
1300 Employees
221K-276K Annually

Similar Companies Hiring

Standard Template Labs Thumbnail
Software • Information Technology • Artificial Intelligence
New York, NY
10 Employees
PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Scotch Thumbnail
Software • Retail • Payments • Fintech • eCommerce • Artificial Intelligence • Analytics
US
25 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account