
Staff Security Engineer, Cloud & AI Platform
Brookfield Asset Management8 days ago
Remote, United StatesStaff+
Responsibilities
- Define cloud and AI security architecture, standards, secure-by-default patterns, and engineering guidance.
- Review infrastructure and application designs for authorization, networking, data protection, secrets, and tenant-isolation risks.
- Secure multi-account AWS environments using IAM, service control policies, KMS, VPC controls, WAF, logging, and detection services.
- Build reusable security controls in Terraform or OpenTofu with testing, monitoring, safe rollout, and recovery patterns.
- Secure GitHub Actions runners, OIDC trust, workflows, artifacts, deployment roles, and developer security checks.
- Lead threat modeling and security design reviews for applications, APIs, data ingestion, authentication, authorization, and agentic systems.
- Define secure patterns for Amazon Bedrock and other model platforms and harden MCP servers, gateways, sandboxes, and code-execution environments.
- Build repeatable AI security evaluations and adversarial tests and connect findings to engineering remediation.
- Translate telemetry into detections, runbooks, ownership, and escalation paths while leading technical response and root-cause remediation.
- Produce control evidence for GRC and Privacy and mentor engineers across partner teams.
Requirements
- 8+ years of experience and demonstrated senior- or Staff-level ownership of production security or platform systems.
- Deep AWS security experience across IAM, multi-account or AWS Organizations environments, logging and detection, KMS, networking, and service-to-service authorization.
- Strong Terraform or OpenTofu skills, including modular design, remote execution, policy controls, and safe state-aware changes.
- Experience securing CI/CD systems such as GitHub Actions, including OIDC federation, runner trust boundaries, secrets, artifacts, and deployment permissions.
- Working knowledge of threat modeling, authentication and authorization, secure API design, secrets handling, dependency risk, and vulnerability remediation.
- Ability to read and write production-quality automation or application code in Python, Go, Ruby, or a comparable language.
- Ability to influence teams without direct management, make pragmatic risk decisions, and turn ambiguous security needs into implemented controls.
- Preferred experience with Amazon Bedrock, AgentCore, MCP, LLM gateways, AI guardrails, or production agentic systems.
- Preferred experience with ECS/Fargate or EKS security, image supply chains, runtime isolation, egress control, identity platforms, and enterprise entitlement systems.
- Preferred experience with Scalr, Terraform Cloud, CrowdStrike Falcon Cloud Security, Datadog, CloudWatch, S3, Snowflake, PostgreSQL/Aurora, vendor data ingestion, AI threat modeling, red teaming, or security evaluations.
Benefits
- Remote role based in the US Tennessee location.
- 401(k) matching, tuition reimbursement, summer Fridays, paid maternity leave, and an employee referral program.
- Career progression, training, and development opportunities across Brookfield.
- Base salary and short-term incentive program are provided, with compensation varying by geography and qualifications; specific amounts are not stated.