Role overview
A senior staff-level security engineering role centered on protecting cloud infrastructure and operationalizing security across an AI-driven personalization platform. The position owns current and target-state security architectures for AWS and GCP environments, leads detection engineering, vulnerability management, and incident response, and shapes secure practices for AI-enabled tooling and emerging product capabilities.
Responsibilities
- Design, implement, and continuously monitor cloud security controls across AWS and GCP environments
- Deploy, configure, tune, and maintain SIEM platforms; author detection rules, playbooks, and alerting workflows
- Identify, triage, and remediate infrastructure and web vulnerabilities; manage full CVE lifecycle including patching and root-cause analysis
- Lead incident triage, coordinate external researcher engagement, and drive vulnerability disclosure programs
- Build automation, tooling, and infrastructure-as-code guardrails with policy-as-code enforcement in CI/CD pipelines
- Define organization-wide security standards, runbooks, and playbooks; mentor junior engineers
Requirements
- 6+ years of relevant security engineering experience
- Strong proficiency in cloud security, network security, URL filtering, common security frameworks, and CVE lifecycle management
- Hands-on experience designing secure AWS and GCP architectures, performing threat modeling, and validating secure IaC
- Practical scripting and automation skills in Python, Go, or Bash
- Demonstrable operational experience with firewalls, WAFs, cloud network controls, and endpoint protections
- Strong cross-functional communication with engineering, leadership, external researchers, and customers
Nice to have
- Experience applying threat modeling and adversary-focused testing to drive resilient designs
- Familiarity with AI/ML security risks, including prompt injection, model data access, and secure AI adoption
Benefits and work setup
- Remote work supported
- Equity grants (RSUs or stock options) based on role, seniority, and location
- Company-wide performance bonus eligibility
- $1,500 annual professional education budget for books, courses, or certifications
- Up to 26 calendar weeks of paid parental leave for primary caregivers
- Quarterly company-wide \"disconnect\" days off
- Employee assistance program and wellness app subscription
- Sports, yoga, and meditation opportunities
- Five paid volunteer days per year
Senior Staff Security Engineer in Location not specified at Unknown Company
This position is listed as full time and able to be worked remotely.