Staff Cloud Security Engineer - #4824

Reposted 2 Days Ago
Be an Early Applicant
Menlo Park, CA, USA
Hybrid
Senior level
Artificial Intelligence • Big Data • Healthtech • Machine Learning • Software • Biotech
GRAIL is a healthcare company whose mission is to detect cancer early, when it can be cured.
The Role
Lead product security architecture and security-by-design across the product lifecycle. Embed security into SSDLC and DevSecOps, perform threat modeling and risk assessments, define controls for AI/ML products, manage post-market surveillance, oversee penetration and advanced testing, support incident response, partner with cross-functional stakeholders for regulatory compliance, track security metrics, and mentor other engineers.
Summary Generated by Built In
Our mission is to detect cancer early, when it can be cured. We are working to change the trajectory of cancer mortality and bring stakeholders together to adopt innovative, safe, and effective technologies that can transform cancer care.

We are a healthcare company, pioneering new technologies to advance early cancer detection. We have built a multi-disciplinary organization of scientists, engineers, and physicians and we are using the power of next-generation sequencing (NGS), population-scale clinical studies, and state-of-the-art computer science and data science to overcome one of medicine’s greatest challenges.

GRAIL is headquartered in the bay area of California, with locations in Washington, D.C., North Carolina, and the United Kingdom. It is supported by leading global investors and pharmaceutical, technology, and healthcare companies.

For more information, please visit grail.com

GRAIL is seeking a mission-driven and high-impact Staff Cloud Security Engineer to help secure the cloud platforms that power one of healthcare's most innovative early cancer detection technologies. Reporting to the Director of Product Security, this role serves as a technical leader responsible for shaping cloud security strategy, enabling secure product delivery, and helping protect the systems that support GRAIL's life-saving mission.

As a Staff-level individual contributor, you will lead the technical execution of the Cloud Security roadmap, partnering closely with Engineering, Platform, Infrastructure, DevOps, and Product teams to drive secure cloud transformation initiatives. You will provide guidance to other engineers while influencing cloud architecture, DevSecOps practices, and secure development decisions across the product and infrastructure lifecycle. 

This role will help teams navigate an evolving threat landscape by implementing scalable AWS security controls, automation, and cloud-native security best practices while maintaining engineering agility and delivery velocity in a highly regulated environment.

This role is based in Menlo Park, California, and will move to Sunnyvale, California in Fall 2026. GRAIL offers a flexible work arrangement, with the ability to work from GRAIL's office or from home. Our current flexible work arrangement policy requires that a minimum of 60%, or 24 hours, of your total work week be on-site. Your specific schedule, determined in collaboration with your manager, will align with team and business needs and could exceed the 60% requirement for the site.

 

Responsibilities

  • Lead the design, implementation, and continuous improvement of cloud security architectures across AWS environments, ensuring product security, and secure-by-design principles throughout the infrastructure and application lifecycle.

  • Partner with Platform, and Cloud Engineering team to design, implement, and manage AWS-native security services including IAM, KMS, GuardDuty, Security Hub, Inspector, Macie, WAF, Shield, CloudTrail, Config, and CloudWatch for proactive threat detection and risk management.

  • Develop and enforce cloud security standards, guardrails, and governance frameworks across AWS accounts, containers, Kubernetes/EKS, serverless, and hybrid cloud workloads.

  • Automate security monitoring, compliance validation, vulnerability management, and incident response workflows using Infrastructure as Code (IaC), scripting, and cloud-native automation tools.

  • Conduct cloud threat modeling, architecture risk assessments, and security reviews for AWS-hosted applications, APIs, infrastructure, and enterprise-integrated systems.

  • Secure DevOps platforms and cloud-native application environments by implementing least-privilege access controls, secrets management, secure network segmentation, encryption, and workload protection.

  • Manage and enhance continuous cloud security posture management (CSPM), container security, and runtime protection capabilities across AWS environments.

  • Scope, coordinate, and review penetration testing, vulnerability assessments, and advanced security testing activities across cloud infrastructure, applications, and DevOps tooling.

  • Serve as a cloud security subject matter expert during security incidents, forensic investigations, root cause analysis, and remediation activities.

  • Partner with Engineering, Platform, Infrastructure, Compliance, and Product teams to align cloud security strategies with regulatory, privacy, and industry cybersecurity requirements.

  • Define, track, and report cloud security metrics, operational KPIs, and compliance status to provide visibility into organizational security posture and risk trends.

  • Mentor and guide engineers on AWS security best practices, DevSecOps methodologies, automation strategies, and secure cloud engineering principles to strengthen organizational security maturity at GRAIL.

  • These responsibilities summarize the role’s primary responsibilities and are not an exhaustive list. They may change at the company’s discretion.

Required Qualifications

  • 8+ years of experience in product security, cybersecurity, Cloud Security, application security, or related technical security roles.

  • Hands-on experience leading threat modeling, security risk assessments, and vulnerability management for complex software products.

  • Experience embedding security into modern software development environments, including CI/CD and DevSecOps practices.

  • Experience supporting security incident response and conducting root cause analysis in production environments.

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent practical experience.

  • GRAIL Values & Leadership Expectations

  • This Staff-level role is expected to model GRAIL’s core values and LEAD leadership attributes by leading through influence, collaborating across boundaries, driving results with integrity, and continuously improving how product security enables patient impact.

Preferred Qualifications

  • Experience working in regulated environments, including medical devices, healthcare, life sciences, or similarly regulated industries.

  • Knowledge of relevant standards and frameworks such as IEC 62304, ISO 14971, ISO 80001-2, NIST, and FDA pre‑ and post‑market cybersecurity guidance.

  • Experience securing AI/ML systems, including mitigating risks such as data poisoning, model manipulation, and unauthorized access.

  • Demonstrated experience delivering cybersecurity programs, including tabletop exercises and cross‑functional incident simulations.

  • Professional security and cloud certifications such as AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional/Associate, OSCP, GPEN, GCIH, GWAPT, CISSP, CCSP, or equivalent certifications preferred.

  • Strong ability to translate technical security risks into business and patient-impact considerations for senior stakeholders.

  • Experience working with globally distributed teams or international stakeholders.

Physical Demands and Working Environment

  • Ability to work in an office and remote environment under a flexible hybrid arrangement.

  • Occasional travel may be required based on business needs.

The expected, full-time, annual base pay scale for this position is $169kK-$224K


This role may be eligible for other forms of compensation, including an annual bonus and/or incentives, subject to the terms of the applicable plans and Company discretion. This range reflects a good-faith estimate of the range that the Company reasonably expects to pay for the position upon hire; the actual compensation offered may vary depending on factors such as the candidate’s qualifications. Employees in this role are also eligible for GRAIL’s comprehensive and competitive benefits package, offered in accordance with our applicable plans and policies. This package currently includes flexible time-off or vacation; a 401(k) retirement plan with employer match; medical, dental, and vision coverage; and carefully selected mindfulness programs.

GRAIL is an equal employment opportunity employer, and we are committed to building a workplace where every individual can thrive, contribute, and grow. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, gender, gender identity, sexual orientation, age, disability, status as a protected veteran, , or any other class or characteristic protected by applicable federal, state, and local laws. Additionally, GRAIL will consider for employment qualified applicants with arrest and conviction records in a manner consistent with applicable law and provide reasonable accommodations to qualified individuals with disabilities. Please contact us at [email protected] if you require an accommodation to apply for an open position.

GRAIL maintains a drug-free workplace. We welcome job-seekers from all backgrounds to join us!

Skills Required

  • 8+ years of experience in product security, cybersecurity, application security, or related technical security roles
  • Hands-on experience leading threat modeling, security risk assessments, and vulnerability management for complex software products
  • Experience embedding security into modern software development environments, including CI/CD and DevSecOps practices
  • Experience supporting security incident response and conducting root cause analysis in production environments
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent practical experience
  • Experience working in regulated environments (medical devices, healthcare, life sciences)
  • Knowledge of standards and frameworks such as IEC 62304, ISO 14971, ISO 80001-2, NIST, and FDA cybersecurity guidance
  • Experience securing AI/ML systems and mitigating model and data risks
  • Demonstrated experience delivering cybersecurity programs, including tabletop exercises and incident simulations
  • Professional security certifications such as OSCP, GPEN, GCIH, GWAPT, or equivalent
  • Ability to translate technical security risks into business and patient-impact considerations for senior stakeholders
  • Experience working with globally distributed teams or international stakeholders

What the Team is Saying

Neda Ronaghi
Ruth Mauntz
Tristan Matthews
David Jenions
Satnam Alag

GRAIL Compensation & Benefits Highlights

  • Healthcare Strength Comprehensive medical, dental, vision, and mental‑health resources are offered, with FSAs/HSAs and multiple carrier options. Feedback suggests the company covers a large share of premiums, enhancing perceived value.
  • Leave & Time Off Breadth Flexible/“unlimited” time off, sick time, paid holidays, and summer/winter shutdowns provide broad time‑off options. Hybrid/remote work further expands flexibility for many roles.
  • Equity Value & Accessibility An ESPP with a discounted purchase feature and equity grants provide accessible ownership upside confirmed by company filings. Feedback suggests equity is a meaningful part of total rewards.

GRAIL Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Menlo Park, CA
918 Employees
Year Founded: 2016

What We Do

GRAIL is a healthcare company whose mission is to detect cancer early, when it can be cured. GRAIL is using the power of high-intensity sequencing, population-scale clinical studies, and state-of-the-art computer science and data science to enhance the scientific understanding of cancer biology, and to develop and commercialize pioneering products.

Why Work With Us

Everything we do is guided by our mission to detect cancer early, when it can be cured. It’s the reason we’re here, and it’s no small task. The right people make all the difference. That’s why we’re looking for those who strive to share their knowledge, contribute their skills, inspire each other and commit to something bigger than themselves.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

GRAIL Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

GRAIL has a variety of work types depending on the roles. Some roles are onsite like a lab role, some are fully remote like our Galleri Sales Consultant roles. Others are hybrid with 2-3 days onsite. Typically Tuesday and Thursday.

Typical time on-site: 2 days a week
Company Office Image
HQMenlo Park, CA
Company Office Image
London, GB
Company Office Image
Raleigh, NC
Company Office Image
Washington, DC
Learn more

Similar Jobs

GRAIL Logo GRAIL

Staff Software Engineer

Artificial Intelligence • Big Data • Healthtech • Machine Learning • Software • Biotech
Hybrid
Menlo Park, CA, USA
918 Employees
169K-224K Annually

GRAIL Logo GRAIL

Development Engineer

Artificial Intelligence • Big Data • Healthtech • Machine Learning • Software • Biotech
Hybrid
Menlo Park, CA, USA
918 Employees
169K-224K Annually

GRAIL Logo GRAIL

Staff Quality Engineer, Complaint Handling / Post Market Surveillance #4836

Artificial Intelligence • Big Data • Healthtech • Machine Learning • Software • Biotech
Hybrid
2 Locations
918 Employees
118K-156K Annually

GRAIL Logo GRAIL

Corporate Communications Senior Manager #4544

Artificial Intelligence • Big Data • Healthtech • Machine Learning • Software • Biotech
Hybrid
Menlo Park, CA, USA
918 Employees
168K-223K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account