Staff Security Engineer

SnykBoston, MA
$170,000 - $205,000Remote

About The Position

Snyk is seeking a Staff Security Engineer to take ownership of cloud and identity security for Snyk's multi-cloud environment (AWS and GCP). This senior technical role focuses on cloud security posture, enterprise identity platform security, and AI-driven automation. The position is adversarial and threat-driven, emphasizing the ability to identify and mitigate entire classes of vulnerabilities from an attacker's perspective. The goal is to prevent insecure configurations from being deployed. This role can be hired remotely, ideally within the EST/CST timezone.

Requirements

  • 8+ years in security engineering, with at least 4 years focused on securing cloud environments at production scale.
  • Expert-level AWS security and strong working knowledge of GCP, including IAM policy evaluation, organization-level guardrails, network and VPC design, key management, encryption, and logging architecture.
  • Deep, hands-on cloud IAM expertise in designing least privilege models, right-sizing roles, and managing non-human identities, workload identity federation, and secrets at scale.
  • An attacker's understanding of cloud compromise methods (credential/token abuse, IAM privilege escalation, metadata/workload identity abuse, exposed services, CI/CD/supply chain paths) and designing controls against them.
  • Real ownership experience with an enterprise CSPM or CNAPP platform, including onboarding accounts, tuning signal to noise, building remediation workflows, and tracking posture metrics.
  • Proficiency in infrastructure as code (Terraform) and coding ability (Python or Go).
  • Kubernetes security experience in the cloud, including RBAC, service accounts, token handling, admission control, workload identity, network policy, and container runtime posture.
  • Practical experience applying AI to engineering work, including building with LLM APIs or agent frameworks, and understanding AI-specific risks (prompt injection, over-permissioned agents, untrusted servers, data leakage) to design controls.
  • Enterprise identity platform security experience, including hands-on work with a major IdP, policy design, federation, phishing-resistant authentication, privileged access, and access review.
  • Understanding of cloud detection fundamentals, including cloud provider audit logs, native threat detection services, effective detection logic, and SIEM integration.
  • Strong written communication and stakeholder influence skills.
  • Bachelor's degree in computer science, information security, or information technology, or equivalent practical experience.

Nice To Haves

  • Experience in DevSecOps, cloud security, or the AI industry, or defending a security product company.
  • Experience building agentic security tooling, MCP servers, or internal AI platforms, with informed opinions on trust.
  • Experience with cloud incident response or cloud threat hunting.
  • Contributions to open-source cloud security tooling or published research on cloud attack techniques.
  • Experience leading a cloud migration or multi-cloud consolidation.
  • Experience in regulated cloud environments such as FedRAMP or NIST 800-53.
  • Relevant security certifications (CISSP, CCSP, SANS/GIAC, AWS Certified Security Specialty, Google Professional Cloud Security Engineer).

Responsibilities

  • Owning cloud security posture across AWS and GCP, driving coverage and signal quality, prioritizing by exploitability, holding remediation accountability, and reporting posture trends.
  • Leading cloud IAM and least privilege initiatives, designing and enforcing permission models, organization-level policies, permission boundaries, cross-account role design, workload identity federation, and managing non-human identities, keys, and secrets.
  • Owning the security posture of the enterprise identity platform, including authentication and authorization policy, phishing-resistant MFA, privileged access, joiner/mover/leaver enforcement, and identity signals for compromise detection.
  • Hunting and eliminating cloud attack paths by reasoning about chained privilege escalation, lateral movement, and data exposure, and removing the conditions that enable them.
  • Building preventative guardrails through infrastructure as code, admission control, CI checks, and organization policy to fail misconfigurations before deployment.
  • Building AI and agentic automation for security tasks such as posture remediation, access reviews, cloud evidence gathering, and investigation enrichment.
  • Securing Snyk's AI adoption by establishing controls for internal AI and agent use, including permissions, blast radius for autonomous agents, tool and MCP server trust, third-party AI risk review, and identity/data boundaries.
  • Securing the cloud infrastructure behind Snyk's AI capabilities, including IAM, network segmentation, and data controls for accounts, model workloads, and pipelines.
  • Strengthening cloud detection and response by ensuring cloud telemetry produces detections for real attacker behavior and acting as a cloud subject matter expert during incidents.
  • Defending the edge through WAF and DDoS posture, and cloud deception coverage.
  • Partnering with Platform and Infrastructure Engineering, Product Security, and Compliance to implement controls through influence, including supporting cloud controls in the public sector environment.
  • Raising the team's cloud security expertise through mentoring engineers, acting as an escalation point for complex investigations, and participating in the EntSec on-call rotation.

Benefits

  • Flexible working hours
  • Work-from-home allowances
  • In-office perks
  • Time off for learning and self-development
  • Generous vacation and wellness time off
  • Country-specific holidays
  • 100% paid parental leave for all caregivers
  • Health benefits
  • Employee assistance plans
  • Annual wellness allowance
  • Country-specific life insurance
  • Disability benefits
  • Retirement/pension programs
  • Mobile phone allowances
  • Education allowances
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service