SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 179,000 - 264,000 / annual
Attentive is an AI marketing platform that combines SMS, RCS, email, and push notifications with AI-powered personalization to help brands build authentic customer relationships. The company serves 8,000+ customers across 70+ industries and is recognized as the #1 SMS marketing provider by G2.
As a Staff Security Engineer focused on Cloud Security, you will drive improvements to how Attentive protects its cloud infrastructure, applications, data, and engineering systems. This is a hands-on, high-impact role working closely with Security, Infrastructure, Platform, SRE, and Engineering teams to understand cloud risks, improve architecture, and build security controls that scale.
Key responsibilities include:
- Own and improve Attentive's cloud security strategy and roadmap, focusing on the risks that matter most
- Design and improve cloud security controls across identity and access, networking, workload security, data protection, secrets, logging, monitoring, and vulnerability management
- Work with engineering teams to build security into cloud architecture, infrastructure-as-code, CI/CD pipelines, containers, Kubernetes, and cloud services
- Improve cloud identity and access controls, including least privilege, privileged access, workload identity, and service-to-service trust
- Improve the security of software delivery and cloud infrastructure, including build, deployment, change, and access processes
- Create reusable security patterns, standards, and automated guardrails that enable teams to build securely
- Identify and prioritize broader cloud risks by connecting vulnerabilities, misconfigurations, access paths, and architecture decisions to realistic business impact
- Help teams fix complex security issues by explaining risk clearly, recommending practical solutions, and setting priorities
- Provide security guidance for new systems and major projects early in the design process
- Improve cloud security monitoring and visibility for detecting and investigating important events and suspicious activity
- Support cloud security incidents by understanding what happened, what was affected, and what needs to change
- Evaluate cloud security tools and capabilities to determine whether to build, automate, configure, or buy solutions
- Define useful cloud security metrics so Security and Engineering leaders can understand risk, progress, and areas needing attention
- Support and guide other engineers through design reviews, technical advice, documentation, and shared security patterns
At the Staff level, you will look beyond individual findings to identify broader risks, set technical direction, and guide teams toward practical security improvements.
REQUIREMENTS:
- 8+ years of experience in security, infrastructure, or related engineering roles, with strong experience in AWS and cloud-native environments
- Strong understanding of cloud security, including identity, access, networking, workload security, encryption, secrets, logging, monitoring, and data protection
- Experience designing and operating security controls in a major cloud platform
- Strong knowledge of cloud identity and access management, including least privilege, workload identity, privileged access, and service-to-service access
- Experience securing containers and Kubernetes, including workload identity, image security, secrets, networking, and runtime controls
- Experience with infrastructure-as-code (e.g., Terraform) and CI/CD, with the ability to automate security checks and controls in engineering workflows
- Ability to review complex systems and identify broader security risks that may not be clear from individual findings
- Experience using cloud security, vulnerability, posture management, or detection tools while applying judgment beyond the severity shown by the tool
- Ability to explain technical issues as realistic attack paths, business impact, and clear remediation priorities
- Good engineering judgment and the ability to balance security, reliability, developer experience, and business needs
- Experience leading technical work and influencing engineers and leaders without direct authority
- Strong written and verbal communication skills with both technical and non-technical audiences