SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Braze is seeking a Senior Security Engineer II to join its Security Engineering function as a senior individual contributor and technical leader for cloud security. This is a step up from the Senior Cloud Security Engineer role, focused on setting technical direction rather than execution alone.
You will define cloud security standards, reference architectures, and guardrails that Infrastructure, SRE, and Product Engineering teams build upon. You'll set your own objectives and roadmap for high-impact cloud security work in partnership with Security Engineering leadership, and lead cross-functional security initiatives end to end. You'll mentor and uplevel other security and platform engineers through pairing, design review, and feedback, serving as the go-to technical resource for cloud security across the organization.
Key responsibilities span three deep areas:
Secure Architecture & Threat Modeling: Own threat modeling as a discipline for new cloud technologies and services. Partner with engineering teams to design secure-by-default cloud architectures across AWS, GCP, and self-managed systems. Drive control-plane and IAM security strategy, including relationships with external identity providers and least-privilege models at scale. Continually assess security posture and surface systemic and emerging risks.
Detection Engineering, Incident Response & Automation: Advance detection strategy by designing high-signal detections and SIEM rules. Serve as a senior incident responder and cloud-forensics lead for investigations across AWS and GCP. Own and optimize security tooling such as CrowdStrike, Tenable, and native cloud security services. Lead vulnerability management workflows including scanning, triage, prioritization, and remediation for cloud assets.
Kubernetes & Platform Security: Own the security of self-managed Kubernetes environments including control plane, nodes, workload isolation, admission control, and run-time security. Set standards for Infrastructure-as-Code and pipeline security (Terraform preferred). Establish best practices for patch management, base-image hardening, and version management across containerized and VM-based environments. Lead security of large-scale distributed systems and self-managed data stores.
Braze is a modern, cloud-first SaaS company running entirely on cloud-native infrastructure with large-scale, distributed systems spanning AWS, GCP, and self-managed Kubernetes. This is a pure individual contributor role where you lead through technical depth and influence rather than direct people management.