Braze

Senior Security Engineer II

$235,000/yearFull-time · San Francisco
✓ Verified live on the employer's own system · added 16 days ago
Save search
Mid-level · 3+ yrs exp

Requirements

Experience: 3+ years

Skills & tools

SecurityTeam LeadershipDevopsManagementProject ManagementCloud PlatformsLogisticsDistributed Systems

Benefits — mentioned in this posting

Bonus / commissionEquity / stock
Apply on company site ↗ See your fit → free

Full job description

We're looking for a Senior Cloud Security Engineer II to join our Security Engineering function as a senior individual contributor and technical leader for cloud security.

This is a step up from our Senior Cloud Security Engineer role. Where a Senior engineer executes and improves our cloud security controls, a Senior Cloud Security Engineer II sets the technical direction: you define the standards and reference patterns other engineers build on, lead cross-team security initiatives end to end, take on the ambiguous problems that don't yet have a playbook (and write the playbook), and raise the bar for the whole team through mentorship and review.

You'll go especially deep across three areas - secure architecture and threat modeling, detection engineering and incident response, and Kubernetes and platform security - and you'll shape how Braze does cloud security across Engineering. This is a pure IC role; you lead through technical depth and influence rather than direct people management.

- Define the cloud security standards, guardrails, and reference architectures that Infrastructure, SRE, and Product Engineering build on - turning point-in-time fixes into durable, org-wide patterns

- Set your own objectives and roadmap for high-impact cloud security work, in partnership with Security Engineering leadership, and drive it to measurable outcomes

- Lead cross-functional security initiatives end to end - scope, timeline, stakeholders, and delivery - guiding technical debates to a decision and owning the result

- Mentor and uplevel other security and platform engineers through pairing, design review, and feedback; act as a force multiplier and the go-to technical resource for cloud security

- Represent cloud security in architecture and design forums, translating complex attack paths and risk into clear, actionable guidance engineers will actually adopt

- Own threat modeling as a discipline for new cloud technologies, services, and patterns adopted across Engineering - making it a repeatable, scalable practice rather than a one-off exercise

- Partner with Infrastructure, SRE, and Product Engineering to design secure-by-default cloud architectures and build practical, scalable controls across AWS, GCP, and self-managed systems

- Drive control-plane and IAM security strategy across AWS and GCP, including relationships with external identity providers, RBAC models, and least privilege at scale

- Continually assess posture, surface systemic and emerging risk, and set the priorities that reduce it

- Advance our detection strategy: design high-signal detections and SIEM rules (with our SIEM Management function) and own detection coverage for cloud threats end to end

- Serve as a senior incident responder and cloud-forensics lead for cloud and run-time security investigations across AWS and GCP - and codify what you learn into standard IR playbooks and preventative controls

- Own and optimize security tooling such as CrowdStrike (EDR/CSPM/IR), Tenable, and native cloud security services, and lead our vulnerability management workflow - scanning, triage, prioritization, and remediation - for cloud assets

- Own the security of our self-managed Kubernetes environments - control plane, nodes, workload isolation, admission control, run-time security, and the CI/CD supply chain feeding them

- Set the standards for Infrastructure-as-Code and pipeline security (Terraform preferred): design and harden IaC and CI/CD automation so security is built into how we ship

- Establish best practices for patch management, base-image hardening, and version management across containerized and VM-based environments

- Lead the security of large-scale, distributed systems and self-managed data stores (e.g., MongoDB), accounting for their real-world operational and security implications

You are a senior individual contributor who leads through technical depth and influence rather than authority. You can take an ambiguous, open-ended cloud security problem, define the objective yourself, and deliver a solution that becomes the way Braze does it going forward. You translate complex cloud attack paths, IAM misconfigurations, and multi-step threat scenarios into guidance engineers adopt, and you balance strong controls with operational reality.

You raise the people around you - through mentorship, review, and the standards you set - and you stay current with the cloud security landscape, tools, and threats. Above all, you can walk someone through the messy middle - what you tried, what broke, and what you'd do differently.

- Several years owning cloud security in production - on-call for it, not adjacent to it

- Hands-on, not theoretical: AWS as primary cloud, working GCP, self-managed Kubernetes

For candidates based in the United States, the pay range for this position at the start of employment is expected to be between $149,000 and $235,000/year with an expected On Target Earnings (OTE) between $166,000 and $261,000/year (including bonus or commission). Your exact offer may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience.

In addition to cash compensation, this role qualifies for a comprehensive Total Rewards package that includes equity grants of restricted stock (RSUs) so that you will own a piece of our company.

More jobs at Braze

Similar jobs near San Francisco

Tell me when more Security Engineer, IAM jobs post near San Francisco, California (Remote) We re-check every listing against the employer’s own board — no résumé needed.

Search Senior Security Engineer II jobs near San Francisco → Browse all live jobs

This posting was published by Braze on their own careers system and is shown here with a direct link to apply there. Employers: for corrections or removal, contact jobs@veritahire.com.