Staff Security Engineer, Cloud

ALSOPalo Alto, CA
$205,000 - $240,000

About The Position

ALSO is seeking a Staff Security Engineer for Cloud to own and build the security for a connected, software-defined EV platform. This role involves setting and implementing security architecture for a cloud-based system that handles vehicle telemetry, remote diagnostics, fleet intelligence, and customer-facing APIs. The engineer will be responsible for threat modeling, implementing security controls in Go, and acting as the go-to person for security-related questions, with the autonomy to implement solutions.

Requirements

  • 10+ years in backend and infrastructure engineering, with a substantial portion spent owning security in production.
  • Expert, hands-on AWS: IAM, VPC and network design, KMS, Secrets Manager, GuardDuty, Security Hub, CloudTrail, Config, and org-level guardrails (SCPs), alongside core compute and data services (EKS, ECS, ECR, Lambda, DynamoDB, S3).
  • Deep Kubernetes and container security — RBAC, admission controllers, pod security standards, network policy, secrets handling, runtime detection, and image hardening — with real experience operating clusters, not just reading about them.
  • Fast, fluent Go: you design, review, and ship production Go code today, not several years ago.
  • Microservices and distributed systems security: service-to-service authentication and authorization, API gateway patterns, rate limiting, tenant isolation, and event-driven pipeline security.
  • Identity protocols and applied cryptography in practice: OAuth2, OIDC, JWT, SAML, mutual TLS, and PKI with certificate lifecycle management at scale.
  • Infrastructure and policy as code, with security gating built into CI/CD.
  • Threat modeling and secure architecture review as routine practice, with specific examples of designs you've changed, plus incident response you've personally led from detection through postmortem.
  • Demonstrated 0 to 1 ownership: you've stood up a security function or program where none existed, without a large team behind you.

Responsibilities

  • Own cloud security end to end — strategy, architecture, implementation, and operations across AWS, Kubernetes, and our microservices platform — including threat modeling new systems in architecture reviews before the code exists.
  • Design and implement identity and access at scale: workload identity, org-wide IAM, least privilege by default, secrets management, and certificate/key lifecycle, including mutual TLS between services and between cloud and vehicle.
  • Harden containers and orchestration: image provenance, admission control, runtime and network policy, service mesh configuration, and clean isolation across microservices.
  • Secure the software supply chain: SBOM generation, dependency and image scanning, signed artifacts, and CI/CD pipelines that fail closed on what matters and stay quiet on what doesn't.
  • Build the controls in Go — authorization services, policy enforcement, provisioning and rotation tooling — and serve as the DevSecOps function, writing guardrails and policy as code so other engineers move fast without routing every decision through security.
  • Run detection and response: security logging and telemetry, meaningful alerting, runbooks, on-call for security incidents, and blameless postmortems that produce real fixes.
  • Secure the vehicle-to-cloud boundary: device identity and provisioning, fleet-wide certificate rotation, secure OTA update paths, and anomaly and tamper detection at scale.
  • Contribute to core backend work alongside the team, and own assurance — penetration tests, vulnerability management, evidence collection, and proportionate standards work that strengthens the product instead of slowing it down.

Benefits

  • Excellent health, dental and vision insurance covered up to 100% by ALSO
  • FSA & HSA options
  • One Medical membership and dedicated insurance advocates
  • Rich fertility and family building benefits with Progyny
  • Flexible time off
  • 401(k) match
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service