Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Engineer

$170k - $205k

Snyk

Snyk is the leader in secure AI software development, helping millions of developers develop fast and stay secure as AI transforms how software is built. Our AI-native Developer Security Platform integrates seamlessly into development and security workflows, making it easy to find, fix, and prevent vulnerabilities — from code and dependencies to containers and cloud.

Our mission is to empower every developer to innovate securely in the AI era — boosting productivity while reducing business risk. We’re not your average security company - we build Snyk on One Team, Care Deeply, Customer Centric, and Forward Thinking.

It’s how we stay driven, supportive, and always one step ahead as AI reshapes our world.

Why this role?

We are hiring a Staff Security Engineer to own cloud and identity security for Snyk's own multi-cloud estate. This is the senior technical seat for cloud security posture across AWS and GCP, for the security of our enterprise identity platform, and for the AI-driven automation that lets a team our size defend an estate this large.

The role is adversarial and threat driven rather than compliance driven. We want someone who looks at a cloud environment the way an attacker does: who can trace a path from an over-permissioned role or an exposed workload through to real business impact, and who then closes off the whole class of problem instead of the single finding. Detection matters here. Prevention matters more. The goal is that insecure configurations cannot be deployed in the first place.

This position can be hired remotely, ideally within the EST/CST timezone.

What you'll do:
  • Owning cloud security posture across AWS and GCP - Driving coverage and signal quality, prioritising by exploitability rather than raw severity counts, holding remediation accountability with the teams that own the resources, and reporting posture as a trend over time.

  • Leading cloud IAM and least privilege. Designing and enforcing permission models across accounts and projects: organization level policy and guardrails, permission boundaries, cross-account role design, workload identity federation, and the full lifecycle of non-human identities, keys, and secrets.

  • Owning the security posture of our enterprise identity platform. Authentication and authorization policy, phishing resistant MFA, privileged access, joiner mover leaver enforcement, and the identity signals that reveal account compromise or insider risk.

  • Hunting and eliminating cloud attack paths. Reasoning about chained privilege escalation, lateral movement between accounts and workloads, and data exposure, then removing the conditions that make those chains possible.

  • Building preventative guardrails. Pushing controls into infrastructure as code modules, admission control, CI checks, and organization policy so that misconfigurations fail before deployment rather than getting caught afterwards.

  • Building AI and agentic automation for security work. Using LLMs and agents to automate posture remediation, access reviews, cloud evidence gathering, and investigation enrichment. Turning repeatable expert judgment into tooling the whole team can run.

  • Securing Snyk's AI adoption. Establishing the controls for internal AI and agent use: permissions and blast radius for autonomous agents, tool and MCP server trust, third party AI risk review, and the identity and data boundaries AI systems operate within.

  • Securing the cloud infrastructure behind Snyk's AI capabilities. IAM, network segmentation, and data controls for the accounts, model workloads, and pipelines that power our AI features.

  • Strengthening cloud detection and response. Making sure cloud control plane and workload telemetry produces detections that fire on real attacker behaviour, and acting as the cloud subject matter expert during incidents.

  • Defending the edge. WAF and DDoS posture, plus cloud deception coverage that catches an intruder early.

  • Partnering across teams. Working with Platform and Infrastructure Engineering, Product Security, and Compliance to land controls through influence rather than mandate. This includes supporting the cloud controls in our public sector environment, which is a smaller part of the role.

  • Raising the team's cloud ceiling. Mentoring engineers, acting as an escalation point for complex cloud investigations, and taking part in the EntSec on-call rotation.

What You'll Need
  • 8+ years in security engineering, including at least 4 focused specifically on securing cloud environments at production scale.

  • Expert level AWS security and strong working knowledge of GCP. You can reason about IAM policy evaluation, organization level guardrails, network and VPC design, key management and encryption, and logging architecture without reaching for the documentation.

  • Deep, hands-on cloud IAM expertise. Designing least privilege models across multi-account and multi-project estates, right-sizing over-permissioned roles without breaking production, and managing non-human identities, workload identity federation, and secrets at scale.

  • An attacker's understanding of cloud. You know how cloud environments actually get compromised (credential and token abuse, IAM privilege escalation chains, metadata and workload identity abuse, exposed storage and services, CI/CD and supply chain paths) and you design controls against those paths rather than against a checklist.

  • Real ownership of an enterprise CSPM or CNAPP platform. Onboarding accounts, tuning signal to noise, building remediation workflows, and holding the line on posture metrics over time.

  • Infrastructure as code and genuine coding ability. Terraform, Python or Go.

  • Kubernetes security in the cloud. RBAC, service accounts and token handling, admission control, workload identity, network policy, and container runtime posture.

  • Practical experience applying AI to engineering work. You have built something real with LLM APIs or agent frameworks, and you understand AI specific risk (prompt injection, over-permissioned agents and tools, untrusted tool and MCP servers, data leakage) well enough to design controls for it.

  • Enterprise identity platform security. Hands-on with a major IdP: policy design, federation, phishing resistant authentication, privileged access, and access review.

  • Cloud detection fundamentals. Cloud provider audit logs and native threat detection services, what good cloud detection logic looks like, and how cloud telemetry lands and gets queried in a SIEM.

  • Strong written communication and stakeholder influence.

  • Bachelor's degree in computer science, information security, or information technology, or equivalent practical experience.

We'd be Lucky if You
  • Have worked in the DevSecOps, cloud security, or AI industry, or have defended a security product company.

  • Have built agentic security tooling, MCP servers, or internal AI platforms, and have well formed opinions about where they should and should not be trusted.

  • Have done cloud incident response or cloud threat hunting on a real intrusion.

  • Have contributed to open source cloud security tooling, or published research on cloud attack techniques.

  • Have led a cloud migration or a multi-cloud consolidation and lived with the security consequences.

  • Have worked in a FedRAMP, NIST 800-53, or similar regulated cloud environment.

  • Hold relevant security certifications. None are required, but they are welcomed. Examples include:

    • CISSP (Certified Information Systems Security Professional)

    • CCSP (Certified Cloud Security Professional)

    • SANS / GIAC: GPCS (Public Cloud Security), GCLD (Cloud Security Essentials), GCSA (Cloud Security Automation), GCFR (Cloud Forensics Responder), GDSA (Defensible Security Architecture), GCPN (Cloud Penetration Tester)

    • AWS Certified Security Specialty

    • Google Professional Cloud Security Engineer

Annual Base Salary Range: $170,000 - $205,000 + bonus.

#LI-TF1

We care deeply about the warm, inclusive environment we’ve created and we value diversity – we welcome applications from those typically underrepresented in tech. If you like the sound of this role but are not totally sure whether you’re the right person, do apply anyway!

About Snyk

Snyk is committed to creating an inclusive and engaging environment where our employees can thrive as we rally behind our common mission to make the digital world a safer place. From Snyk employee resource groups, to global benefits that help our employees prioritize their health, wellness, financial security, and a work/life blend, we aim to support our employees along their entire journeys here at Snyk.

Benefits & Programs

  • Prioritize health, wellness, financial security, and life balance with programs tailored to your location and role.

  • Flexible working hours, work-from home allowances, in-office perks, and time off for learning and self development

  • Generous vacation and wellness time off, country-specific holidays, and 100% paid parental leave for all caregivers

  • Health benefits, employee assistance plans, and annual wellness allowance

  • Country-specific life insurance, disability benefits, and retirement/pension programs, plus mobile phone and education allowances

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Security Engineer in United States vacancy
  •  ...the sidelines.We're looking for builders, problem-solvers, and security professionals who thrive in a fast-paced environment where...  ...security professionals.Collaborate effectively across security, engineering, development, infrastructure teams, app teams, and various levels... 
    Suggested
    Permanent employment
    Full time
    Part time
    H1b
    Work visa
    Shift work
    Day shift

    Truist

    Atlanta, GA
    1 day ago
  • $152k - $261k

     ...Seattle office. The ideal candidate will be passionate around security and will love to dive deep in order to understand and exploit...  ...Kill Chain, MITRE ATT&CK frameworkComputer Science, Computer Engineering, or related technical DegreeHolder of well-recognized offensive... 
    Suggested
    Temporary work
    Work experience placement
    Work at office

    Coupang

    Seattle, WA
    4 days ago
  •  ...ICS/OT Cybersecurity Engineers and ICS/OT Network Security Engineers support clients in assessing, improving, and maintaining the cybersecurity posture of their ICS/OT environments to mitigate security risks (e.g., insider and external threats, intentional and accidental... 
    Suggested
    Full time
    Work at office
    Remote work

    Logical Systems

    Golden, CO
    12 hours ago
  • $159.3k - $202.4k

    Amazon Healthcare Security's (HealthSec) Security Operations team is hiring a Security Engineer to be the first line of defense to our most critical customer data. You will be a guardian of healthcare information and work with Amazon Healthcare products to secure customer... 
    Suggested
    Flexible hours

    Amazon

    Austin, TX
    4 days ago
  •  ...Atlanta, Raleigh or Charlotte office***• This team uses automated API security tools like Akamai, Salt Security and ReadyAPI tools to identify vulnerabilities in running APIs• This Senior Security Engineer will be experienced with API security testing tools such as Akamai,... 
    Suggested
    Full time
    Part time
    Work at office
    Shift work
    Day shift

    Truist

    Charlotte, NC
    3 days ago
  • $159.3k - $202.4k

     ...communities around the world.Have you wanted an opportunity to secure an advanced satellite based broadband telecom service? The Amazon...  ...builders who aspire to become security advocates & security engineers via 1-1 sessions & office hours.You will assist Red Teams in identifying... 
    Permanent employment
    Internship
    Work at office
    Flexible hours

    Amazon

    Redmond, WA
    2 days ago
  • Hi, we're Oscar. We're hiring a Senior Product Security Engineer 1 to join our Security Team.Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We started Oscar in 2012 to create the kind... 
    Full time
    Work experience placement
    Work at office
    Flexible hours

    Oscar Health Insurance

    Los Angeles, CA
    2 days ago
  • $159.3k - $202.4k

    Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats... 
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    2 days ago
  • $159.3k - $202.4k

    Amazon Healthcare Security's (HealthSec) Detections & Monitoring team is hiring a Security Engineer II to design, build, and operate detection and monitoring capabilities that protect Amazon Health Services (AHS) across cloud infrastructure, applications, endpoints, and... 
    Flexible hours

    Amazon

    Seattle, WA
    1 day ago
  • $159.3k - $202.4k

    The Corporate Services Security (CPSS) Finance and Communication Security (FCS) Team is responsible for securing the applications, infrastructure...  ...make your own life easier and share that benefit with all our engineers globally.Contribute to recruiting activities, mentoring and... 
    Flexible hours

    Amazon

    Boston, MA
    12 hours ago
  • $178.4k - $226.7k

    The Senior Security Engineer is a senior individual contributor responsible for independently driving security initiatives across multiple services and teams. This role requires deep technical expertise in application security, threat modeling, and secure system design,... 
    Internship
    Flexible hours

    Amazon

    Austin, TX
    12 hours ago
  • $147k - $210k

     ...) tooling to scale advanced vulnerability research, defensive engineering, and mitigation strategies across the organization.Participate...  ...into our VRP pipeline to improve efficiency.Conduct deep-dive security research into Android vulnerabilities and threat vectors, converting... 

    Google

    New York, NY
    3 days ago
  • $146.3k - $257.7k

     ...scalers to join us on our journey to create a better future of work with AI. About the roleThis is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building the security foundations that protect the AI systems... 
    Full time
    Work at office
    Local area

    Writer

    San Francisco, CA
    1 day ago
  • Washington DCTechnology - Security /RemoteThe Senior Security Engineer II will be responsible for designing, implementing, and maintaining security services that support our business. You will understand data and automation are important ingredients to our mission and... 
    Temporary work
    Work at office
    Remote work
    Work from home
    Flexible hours

    Aledade

    Washington DC
    4 days ago
  • $159.3k - $212.8k

     ...to no-checkout retail, we push the boundaries of technology in every direction using the globe’s largest AWS deployment.As a Security Engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing these novel services... 
    Internship
    Flexible hours

    Amazon

    New York, NY
    12 hours ago
  • $237.6k - $297k

    We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the... 
    Full time

    Scale AI

    San Francisco, CA
    3 days ago
  • $159.3k - $202.4k

    The Ads Security organization at Amazon is dedicated to creating innovative technical solutions that detect, assess, and mitigate security...  ...are inherently secure. We are seeking a talented Security Engineer to join our team, where you will have the opportunity to contribute... 
    Flexible hours

    Amazon

    Bellevue, WA
    12 hours ago
  • $165k - $242k

     ...CRWV) in March 2025. Learn more at .What You’ll Do:The Enterprise Security team at CoreWeave is responsible for securing how our people...  ..., this is the team to join.About the Role:As a Senior Security Engineer, Enterprise Security, you’ll design and ship the security controls... 
    Permanent employment
    Full time
    Temporary work
    For contractors
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    New York, NY
    4 days ago
  • $100k - $120k

     ...manufacturing, turning abstract ideas into realities that transform the world for good. Your impact The Endpoint Security & Exposure Management Engineer is responsible for the design, implementation, administration, and continuous improvement of endpoint security controls... 
    Full time

    Jacobs

    Dallas, TX
    2 days ago
  • $159.3k - $202.4k

     ...to no-checkout retail, we push the boundaries of technology in every direction using the globe’s largest AWS deployment.As a Security Engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing these novel services... 
    Internship
    Flexible hours

    Amazon

    Seattle, WA
    1 day ago
  • $159.3k - $212.8k

    The AWS Security Hub team is looking for a passionate and innovative security engineer with a focus on compliance and security best practices for AWS, Azure, and GCP services. AWS Security Hub is the security and compliance center for AWS customers. One of its main functions... 
    Internship
    Flexible hours

    Amazon

    New York, NY
    4 days ago
  • $178.4k - $226.7k

     ...communities around the world.Have you wanted an opportunity to secure an advanced satellite broadband telecom service? The Kuiper Security...  ...builders who aspire to become security advocates & security engineers via 1-1 sessions & office hours.You will assist Red Teams in... 
    Permanent employment
    Internship
    Work at office
    Flexible hours

    Amazon

    Redmond, WA
    1 day ago
  •  ...following job description:Designs and implements application security capabilities across the software development lifecycle, including...  ...requirements. Collaborates closely with developers, DevOps engineers, and security teams to identify, assess, and remediate security... 
    Full time
    Part time
    Shift work
    Day shift

    Truist

    Atlanta, GA
    1 day ago
  • $159.3k - $202.4k

    We're looking for a Security Engineer to join the team that secures the foundational compute and networking systems powering AWS — the systems behind EC2, Nitro, EBS, VPC, and more.You'll work directly with service teams across some of the most critical systems in cloud... 
    Internship
    Flexible hours

    Amazon

    Seattle, WA
    1 day ago
  • $178.4k - $226.7k

     ...checkout retail, we push the boundaries of technology in every direction using the globe’s largest AWS deployment.As a Senior Security Engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing these novel services... 
    Internship
    Flexible hours

    Amazon

    Seattle, WA
    4 hours ago
  • $159.3k - $202.4k

    Are you passionate about delivering innovative security solutions and protecting millions of customers through a blend of deep security...  ...Security team is looking for a talented and results-driven Security Engineer to help shape how Amazon protects customer data through secure-... 
    Flexible hours

    Amazon

    Seattle, WA
    3 days ago
  • $266k

     ...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are...  ...engaging a robust security culture. About the RoleAs a Security Engineer, Application Security you will be responsible for identifying and... 
    Work at office
    Remote work
    Relocation package
    Flexible hours

    OpenAI

    San Francisco, CA
    3 days ago
  • $10 per hour

     ...configuration drift across our critical SaaS applications.Own security configuration for the SaaS tools hundreds of Flexporters use daily...  ...years of experience in corporate, enterprise, or IT security engineering — we care more about what you've shipped than the exact number... 
    Work at office
    Immediate start
    Relocation
    Relocation package
    Flexible hours

    Flexport

    San Francisco, CA
    5 days ago
  • $200k - $220k

     ...employees, their laptops, their identities, and the SaaS apps they rely on every day.We are looking for a hands-on Corporate Security Engineer to own and improve the technical controls that keep our workforce and corporate environment safe. This is a security engineering... 
    Work at office
    Local area

    Notion Labs

    New York, NY
    4 days ago
  • $178.4k - $226.7k

    At Amazon Web Services (AWS), Security is our highest priority. We are looking for a passionate, innovative, results oriented Security Engineer. Security Escalations is responsible for driving innovative enhancements that raise the bar for how AWS employees interact with... 
    Internship
    Flexible hours

    AmazonWebServices

    Herndon, VA
    12 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Engineer. Be the first to apply!