Staff Security Engineer

Posted 2 Hours Ago
Be an Early Applicant
2 Locations
Remote or Hybrid
170K-205K Annually
Senior level
Artificial Intelligence • Cloud • Information Technology • Security • Software • Cybersecurity • Data Privacy
Snyk helps organizations build fast and stay secure in the age of AI.
The Role
Lead cloud and identity security across Snyk's multi-cloud estate (AWS/GCP). Own cloud IAM and least-privilege, CSPM/CNAPP posture, detection and prevention, Kubernetes and enterprise IdP security. Build preventative IaC guardrails, AI/agent automation for remediation and investigations, secure AI adoption and model pipelines, and mentor engineers while participating in on-call rotations and incident response.
Summary Generated by Built In

Snyk is the leader in secure AI software development, helping millions of developers develop fast and stay secure as AI transforms how software is built. Our AI-native Developer Security Platform integrates seamlessly into development and security workflows, making it easy to find, fix, and prevent vulnerabilities — from code and dependencies to containers and cloud.

Our mission is to empower every developer to innovate securely in the AI era — boosting productivity while reducing business risk. We’re not your average security company - we build Snyk on One Team, Care Deeply, Customer Centric, and Forward Thinking.

It’s how we stay driven, supportive, and always one step ahead as AI reshapes our world.

Why this role?

We are hiring a Staff Security Engineer to own cloud and identity security for Snyk's own multi-cloud estate. This is the senior technical seat for cloud security posture across AWS and GCP, for the security of our enterprise identity platform, and for the AI-driven automation that lets a team our size defend an estate this large.

The role is adversarial and threat driven rather than compliance driven. We want someone who looks at a cloud environment the way an attacker does: who can trace a path from an over-permissioned role or an exposed workload through to real business impact, and who then closes off the whole class of problem instead of the single finding. Detection matters here. Prevention matters more. The goal is that insecure configurations cannot be deployed in the first place.

This position can be hired remotely, ideally within the EST/CST timezone.

What you'll do:
  • Owning cloud security posture across AWS and GCP - Driving coverage and signal quality, prioritising by exploitability rather than raw severity counts, holding remediation accountability with the teams that own the resources, and reporting posture as a trend over time.

  • Leading cloud IAM and least privilege. Designing and enforcing permission models across accounts and projects: organization level policy and guardrails, permission boundaries, cross-account role design, workload identity federation, and the full lifecycle of non-human identities, keys, and secrets.

  • Owning the security posture of our enterprise identity platform. Authentication and authorization policy, phishing resistant MFA, privileged access, joiner mover leaver enforcement, and the identity signals that reveal account compromise or insider risk.

  • Hunting and eliminating cloud attack paths. Reasoning about chained privilege escalation, lateral movement between accounts and workloads, and data exposure, then removing the conditions that make those chains possible.

  • Building preventative guardrails. Pushing controls into infrastructure as code modules, admission control, CI checks, and organization policy so that misconfigurations fail before deployment rather than getting caught afterwards.

  • Building AI and agentic automation for security work. Using LLMs and agents to automate posture remediation, access reviews, cloud evidence gathering, and investigation enrichment. Turning repeatable expert judgment into tooling the whole team can run.

  • Securing Snyk's AI adoption. Establishing the controls for internal AI and agent use: permissions and blast radius for autonomous agents, tool and MCP server trust, third party AI risk review, and the identity and data boundaries AI systems operate within.

  • Securing the cloud infrastructure behind Snyk's AI capabilities. IAM, network segmentation, and data controls for the accounts, model workloads, and pipelines that power our AI features.

  • Strengthening cloud detection and response. Making sure cloud control plane and workload telemetry produces detections that fire on real attacker behaviour, and acting as the cloud subject matter expert during incidents.

  • Defending the edge. WAF and DDoS posture, plus cloud deception coverage that catches an intruder early.

  • Partnering across teams. Working with Platform and Infrastructure Engineering, Product Security, and Compliance to land controls through influence rather than mandate. This includes supporting the cloud controls in our public sector environment, which is a smaller part of the role.

  • Raising the team's cloud ceiling. Mentoring engineers, acting as an escalation point for complex cloud investigations, and taking part in the EntSec on-call rotation.

What You'll Need
  • 8+ years in security engineering, including at least 4 focused specifically on securing cloud environments at production scale.

  • Expert level AWS security and strong working knowledge of GCP. You can reason about IAM policy evaluation, organization level guardrails, network and VPC design, key management and encryption, and logging architecture without reaching for the documentation.

  • Deep, hands-on cloud IAM expertise. Designing least privilege models across multi-account and multi-project estates, right-sizing over-permissioned roles without breaking production, and managing non-human identities, workload identity federation, and secrets at scale.

  • An attacker's understanding of cloud. You know how cloud environments actually get compromised (credential and token abuse, IAM privilege escalation chains, metadata and workload identity abuse, exposed storage and services, CI/CD and supply chain paths) and you design controls against those paths rather than against a checklist.

  • Real ownership of an enterprise CSPM or CNAPP platform. Onboarding accounts, tuning signal to noise, building remediation workflows, and holding the line on posture metrics over time.

  • Infrastructure as code and genuine coding ability. Terraform, Python or Go.

  • Kubernetes security in the cloud. RBAC, service accounts and token handling, admission control, workload identity, network policy, and container runtime posture.

  • Practical experience applying AI to engineering work. You have built something real with LLM APIs or agent frameworks, and you understand AI specific risk (prompt injection, over-permissioned agents and tools, untrusted tool and MCP servers, data leakage) well enough to design controls for it.

  • Enterprise identity platform security. Hands-on with a major IdP: policy design, federation, phishing resistant authentication, privileged access, and access review.

  • Cloud detection fundamentals. Cloud provider audit logs and native threat detection services, what good cloud detection logic looks like, and how cloud telemetry lands and gets queried in a SIEM.

  • Strong written communication and stakeholder influence.

  • Bachelor's degree in computer science, information security, or information technology, or equivalent practical experience.

We'd be Lucky if You
  • Have worked in the DevSecOps, cloud security, or AI industry, or have defended a security product company.

  • Have built agentic security tooling, MCP servers, or internal AI platforms, and have well formed opinions about where they should and should not be trusted.

  • Have done cloud incident response or cloud threat hunting on a real intrusion.

  • Have contributed to open source cloud security tooling, or published research on cloud attack techniques.

  • Have led a cloud migration or a multi-cloud consolidation and lived with the security consequences.

  • Have worked in a FedRAMP, NIST 800-53, or similar regulated cloud environment.

  • Hold relevant security certifications. None are required, but they are welcomed. Examples include:

    • CISSP (Certified Information Systems Security Professional)

    • CCSP (Certified Cloud Security Professional)

    • SANS / GIAC: GPCS (Public Cloud Security), GCLD (Cloud Security Essentials), GCSA (Cloud Security Automation), GCFR (Cloud Forensics Responder), GDSA (Defensible Security Architecture), GCPN (Cloud Penetration Tester)

    • AWS Certified Security Specialty

    • Google Professional Cloud Security Engineer

Annual Base Salary Range: $170,000 - $205,000 + bonus.

#LI-TF1

We care deeply about the warm, inclusive environment we’ve created and we value diversity – we welcome applications from those typically underrepresented in tech. If you like the sound of this role but are not totally sure whether you’re the right person, do apply anyway!

About Snyk

Snyk is committed to creating an inclusive and engaging environment where our employees can thrive as we rally behind our common mission to make the digital world a safer place. From Snyk employee resource groups, to global benefits that help our employees prioritize their health, wellness, financial security, and a work/life blend, we aim to support our employees along their entire journeys here at Snyk.

Benefits & Programs

  • Prioritize health, wellness, financial security, and life balance with programs tailored to your location and role.

  • Flexible working hours, work-from home allowances, in-office perks, and time off for learning and self development

  • Generous vacation and wellness time off, country-specific holidays, and 100% paid parental leave for all caregivers

  • Health benefits, employee assistance plans, and annual wellness allowance

  • Country-specific life insurance, disability benefits, and retirement/pension programs, plus mobile phone and education allowances

Skills Required

  • 8+ years in security engineering, including at least 4 focused on securing cloud environments at production scale
  • Expert-level AWS security knowledge and strong working knowledge of GCP
  • Deep, hands-on cloud IAM expertise (least-privilege models, non-human identities, workload identity federation)
  • Practical attacker mindset for cloud compromise paths and designing controls against them
  • Real ownership experience with an enterprise CSPM or CNAPP platform (onboarding, tuning, remediation workflows)
  • Infrastructure as code and coding ability (Terraform plus Python or Go)
  • Kubernetes security in cloud (RBAC, service accounts, admission control, network policy, runtime posture)
  • Practical experience applying AI to engineering work (built with LLM APIs or agent frameworks) and understanding AI-specific risks
  • Enterprise identity platform security experience (major IdP, federation, phishing-resistant MFA, privileged access)
  • Cloud detection fundamentals (provider audit logs, native detections, SIEM integration and detection logic)
  • Strong written communication and stakeholder influence skills
  • Bachelor's degree in computer science, information security, or equivalent practical experience
  • Experience in DevSecOps, cloud security, or AI industry (preferred)
  • Experience building agentic security tooling, MCP servers, or internal AI platforms (preferred)
  • Cloud incident response or cloud threat hunting experience (preferred)
  • Experience with FedRAMP, NIST 800-53, or regulated cloud environments (preferred)
  • Relevant security certifications (CISSP, CCSP, GIAC, AWS/GCP security certs)

What the Team is Saying

Ciana
Carissa
Brian
Erica
Ashok Narayanan
Rodrigo Santos
Lulu Weisz
Lulu Weisz
Ashok Narayanan
Ken MacAskill
Rodrigo Santos
Lulu Weisz
Rodrigo Santos
Lulu Weisz
Ashok Narayanan
Rodrigo Santos

Snyk Compensation & Benefits Highlights

  • Leave & Time Off Breadth Time away is positioned as generous, with flexible or unlimited PTO in some regions and company‑wide Snyk Recharge days that encourage real downtime. Additional offerings like wellness days, local holidays, and volunteer time off are highlighted as part of the package.
  • Parental & Family Support Policies emphasize 100% paid parental leave for all caregivers, complemented by a return‑to‑work program and designated mother’s rooms where applicable. These elements signal a family‑forward approach across locations.
  • Wellbeing & Lifestyle Benefits Health and wellbeing support is broad, including EAP access, a wellness allowance (commonly cited around the mid‑hundreds annually), and unlimited one‑on‑one wellness coaching sessions. Extras like pet insurance and wellness initiatives further reinforce lifestyle support.

Snyk Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Boston, MA
1,000 Employees
Year Founded: 2015

What We Do

Snyk, the leader in secure AI software development, empowers organizations to build fast and stay secure by unleashing developer productivity and reducing business risk. The company’s AI Trust Platform seamlessly integrates into developer and security workflows to accelerate secure software delivery in the AI Era. Snyk delivers trusted, actionable insights and automated remediation, enabling modern organizations to innovate without limits. Snyk is redefining secure AI-driven software delivery for over 4,500 customers worldwide today.

Why Work With Us

Every team member at Snyk contributes to our vision for a more secure digital world. No matter where we are in the world, we operate as one team and work together to shape the future of application security. We take immense pride in the diversity of our people, cultures, and experiences.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Snyk Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: Flexible
Company Office Image
HQBoston
Company Office Image
Bucharest
Company Office Image
Cluj-Napoca
Company Office Image
Lisbon
Company Office Image
London
Company Office Image
Ottawa
Company Office Image
San Francisco
Company Office Image
Singapore
Sydney
Company Office Image
Tel Aviv
Tokyo, JP
Company Office Image
Zürich
Learn more

Similar Jobs

Snyk Logo Snyk

Consultant

Artificial Intelligence • Cloud • Information Technology • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
3 Locations
1000 Employees
130K-150K Annually

Snyk Logo Snyk

Senior Solutions Architect

Artificial Intelligence • Cloud • Information Technology • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
TX, USA
1000 Employees
124K-154K Annually

Snyk Logo Snyk

Staff Technical Success Manager (Central)

Artificial Intelligence • Cloud • Information Technology • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
TX, USA
1000 Employees
119K-149K Annually

Snyk Logo Snyk

Account Executive

Artificial Intelligence • Cloud • Information Technology • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
2 Locations
1000 Employees
106K-133K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account