
Staff Security Engineer
Posted Aug 7

Posted Aug 7
This is a fully remote position, open to applicants in Massachusetts, +1 more state.
• Take ownership of the cloud security posture across AWS and GCP.
• Enhance coverage and signal quality, prioritize remediation based on exploitability, and report on posture trends.
• Lead initiatives for cloud IAM and ensure least privilege across various accounts and projects.
• Manage the security posture of the enterprise identity platform, encompassing authentication, authorization, MFA, privileged access, and enforcement of joiner/mover/leaver policies.
• Proactively hunt and mitigate cloud attack vectors that involve privilege escalation, lateral movement, and data exposure.
• Develop preventative guardrails through infrastructure as code, admission control, CI checks, and organizational policies.
• Create AI-driven automation for posture remediation, access reviews, evidence collection, and enrichment of investigations.
• Implement controls for internal AI and agent utilization, including managing agent permissions, ensuring MCP server trust, assessing third-party AI risks, and maintaining identity/data boundaries.
• Safeguard cloud infrastructure leveraging Snyk’s AI capabilities, which include IAM, network segmentation, and data controls.
• Enhance cloud detection and response through control-plane and workload telemetry.
• Serve as a subject matter expert in cloud technology during incidents.
• Protect the edge through WAF, DDoS posture management, and cloud deception strategies.
• Collaborate with Platform and Infrastructure Engineering, Product Security, and Compliance teams to implement necessary controls.
• Support cloud controls within Snyk’s public sector environment.
• Mentor engineers, act as an escalation point for intricate investigations, and participate in the EntSec on-call rotation.
• Minimum of 8 years in security engineering, with at least 4 years focused on securing production-scale cloud environments.
• Expert-level proficiency in AWS security and a strong understanding of GCP.
• Ability to analyze IAM policy evaluation, organization-level guardrails, network and VPC design, key management, encryption, and logging architecture.
• Extensive hands-on experience with cloud IAM across multi-account and multi-project setups.
• Familiarity with non-human identities, workload identity federation, and large-scale secrets management.
• Knowledge of cloud compromise techniques, such as credential and token abuse, IAM privilege escalation, metadata and workload identity exploitation, exposed storage and services, CI/CD vulnerabilities, and supply-chain risks.
• Experience managing an enterprise CSPM or CNAPP platform.
• Proficiency in infrastructure as code and programming using Terraform, Python, or Go.
• Understanding of Kubernetes security, including RBAC, service accounts, token management, admission control, workload identity, network policy, and container runtime security posture.
• Practical experience applying AI methodologies to engineering tasks using LLM APIs or agent frameworks.
• Awareness of AI-specific risks such as prompt injection, over-permissioned agents and tools, untrusted tools and MCP servers, and data leakage.
• Hands-on experience securing enterprise identity platforms with a major IdP.
• Knowledge of cloud detection fundamentals, provider audit logs, native threat detection services, SIEM telemetry, and detection logic.
• Strong written communication skills and ability to influence stakeholders effectively.
• A Bachelor's degree in computer science, information security, or information technology, or equivalent practical experience.
• Relevant security certifications are a plus but not mandatory.
• Annual base salary ranging from $170,000 to $205,000, plus bonus opportunities.
• Flexible working hours to accommodate personal needs.
• Work-from-home allowances to support remote work.
• In-office perks that enhance the work environment.
• Time off dedicated to learning and self-development.
• Generous vacation and wellness time off policies.
• Country-specific holidays recognized by the company.
• 100% paid parental leave available for all caregivers.
• Comprehensive health benefits offered.
• Employee assistance plans to support well-being.
• Annual wellness allowance for health-related expenses.
• Country-specific life insurance coverage.
• Disability benefits provided.
• Retirement and pension programs available.
• Mobile phone allowances to support communication needs.
• Education allowances for continuous learning.
• Employee resource groups fostering community and support.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.