Base Salary
$149k - $235k/yr
Responsibilities
- Define cloud security standards, guardrails, and reference architectures for Infrastructure, SRE, and Product Engineering.
- Set objectives and roadmaps for high-impact cloud security work and drive measurable outcomes.
- Lead cross-functional security initiatives from scope through delivery and own the results.
- Mentor and upskill security and platform engineers through pairing, design reviews, and feedback.
- Represent cloud security in architecture and design forums and provide actionable guidance on attack paths and risk.
- Own threat modeling for new cloud technologies, services, and engineering patterns.
- Develop secure-by-default architectures and controls across AWS, GCP, and self-managed systems.
- Lead control-plane and IAM security strategy, including external identity providers, RBAC, and least privilege.
- Design cloud threat detections and SIEM rules and own detection coverage end to end.
- Serve as a senior incident responder and cloud-forensics lead and create incident response playbooks.
- Manage CrowdStrike, Tenable, native cloud security services, and cloud vulnerability management workflows.
- Own security for self-managed Kubernetes control planes, nodes, workloads, admission controls, runtime security, and CI/CD supply chains.
- Set Infrastructure-as-Code and pipeline security standards, with Terraform preferred.
- Establish patch management, base-image hardening, and version-management practices for containerized and VM-based environments.
- Lead security for large-scale distributed systems and self-managed MongoDB data stores.
Requirements
- Several years of production experience owning cloud security, including on-call responsibility.
- Hands-on experience with AWS as the primary cloud, working knowledge of GCP, and self-managed Kubernetes.
- Ability to read and write Python and Terraform code.
- Experience with secure architecture, threat modeling, IAM, detection engineering, incident response, cloud forensics, vulnerability management, Kubernetes security, and Infrastructure-as-Code security.
- Ability to lead ambiguous, organization-wide security initiatives through technical depth, influence, mentorship, and clear standards.
Benefits
- Compensation may include equity grants, retirement and employee stock purchase plans, flexible paid time off, and comprehensive medical, dental, vision, life, and disability benefits.
- Family services include fertility benefits and equal paid parental leave.
- Professional development includes formal career pathing, learning platforms, and a yearly learning stipend.
- Braze supports hybrid ways of working and offers a curated in-office employee experience.
- Employees can participate in Volunteer Week, donation matching, and Employee Resource Groups.
- The role is part of a collaborative culture recognized as a Great Place to Work®.
Tech Stack
About Braze
Braze is the leading customer engagement platform that empowers brands to Be Absolutely Engaging.™ Braze allows any marketer to collect and take action on any amount of data from any source, so they can creatively engage with customers in real time, across channels from one platform. From cross-channel messaging and journey orchestration to Al-powered experimentation and optimization, Braze enables companies to build and maintain absolutely engaging relationships with their customers that foster growth and loyalty. The company has been recognized as a 2024 U.S. News & World Report Best Companies to Work For, 2024 Best Small & Medium Workplaces in Europe by Great Place to Work®, 2024 Fortune Best Workplaces for Women™ by Great Place to Work® and was named a Leader by Gartner® in the 2024 Magic Quadrant™ for Multichannel Marketing Hubs and a Strong Performer in The Forrester Wave™: Email Marketing Service Providers, Q3 2024. Braze is headquartered in New York with 15 offices across AMER, LATAM, EMEA, and APAC. Learn more at braze.com.