SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security Engineer II

OfferFit - Boston, MA, United States - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Braze is seeking a Senior Cloud Security Engineer II to join its Security Engineering function as a senior individual contributor and technical leader. This is a step up from the Senior Cloud Security Engineer role, focused on setting technical direction rather than execution alone. You will define cloud security standards, reference architectures, and guardrails that Infrastructure, SRE, and Product Engineering teams build upon. You'll lead cross-functional security initiatives end-to-end, mentor other security and platform engineers, and serve as the go-to technical resource for cloud security across the organization. Key responsibilities include: **Secure Architecture & Threat Modeling**: Own threat modeling as a discipline for new cloud technologies and services. Partner with Infrastructure and Engineering teams to design secure-by-default architectures across AWS, GCP, and self-managed systems. Drive control-plane and IAM security strategy, including relationships with external identity providers and least-privilege models at scale. Continuously assess posture and surface systemic risk. **Detection Engineering & Incident Response**: Advance detection strategy by designing high-signal SIEM rules and owning detection coverage for cloud threats. Serve as a senior incident responder and cloud-forensics lead for investigations across AWS and GCP. Codify learnings into standard IR playbooks and preventative controls. Own and optimize security tooling (CrowdStrike, Tenable, native cloud services) and lead vulnerability management workflows. **Kubernetes & Platform Security**: Own security of self-managed Kubernetes environments (control plane, nodes, workload isolation, admission control, runtime security, CI/CD supply chain). Set standards for Infrastructure-as-Code and pipeline security (Terraform preferred). Establish best practices for patch management, base-image hardening, and version management. Lead security of large-scale distributed systems and self-managed data stores like MongoDB. You are a senior individual contributor who leads through technical depth and influence rather than direct authority. You can take ambiguous, open-ended cloud security problems, define objectives, and deliver solutions that become organizational standards. You translate complex cloud attack paths and IAM misconfigurations into actionable guidance engineers adopt, balancing strong controls with operational reality. You raise the people around you through mentorship and review, and stay current with the cloud security landscape.

Similar roles