GRAIL

Staff Cloud Security Engineer - #4824

GRAIL
Apply
2 months ago
Sunnyvale, CA, USAStaff+

Base Salary

$169k - $224k/yr

Responsibilities

  • Lead the design, implementation, and continuous improvement of cloud security architectures across AWS environments.
  • Implement and manage AWS security services including IAM, KMS, GuardDuty, Security Hub, Inspector, Macie, WAF, Shield, CloudTrail, Config, and CloudWatch.
  • Develop cloud security standards, guardrails, and governance frameworks for AWS accounts, containers, Kubernetes/EKS, serverless, and hybrid workloads.
  • Automate security monitoring, compliance validation, vulnerability management, and incident-response workflows using infrastructure as code, scripting, and cloud-native automation.
  • Conduct threat modeling, architecture risk assessments, security reviews, vulnerability assessments, and penetration-testing coordination.
  • Secure DevOps platforms and cloud-native environments through access controls, secrets management, network segmentation, encryption, and workload protection.
  • Manage cloud security posture management, container security, and runtime protection capabilities.
  • Serve as a cloud security subject matter expert during incidents, forensic investigations, root cause analysis, and remediation.
  • Define and report cloud security metrics, operational KPIs, and compliance status.
  • Mentor and guide engineers on AWS security, DevSecOps, automation, and secure cloud engineering practices.

Requirements

  • 8+ years of experience in product security, cybersecurity, cloud security, application security, or related technical security roles.
  • Hands-on experience leading threat modeling, security risk assessments, and vulnerability management for complex software products.
  • Experience embedding security into modern software development environments, including CI/CD and DevSecOps practices.
  • Experience supporting security incident response and conducting root cause analysis in production environments.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent practical experience.
  • Preferred experience includes work in regulated environments such as medical devices, healthcare, or life sciences.
  • Preferred knowledge includes IEC 62304, ISO 14971, ISO 80001-2, NIST, and FDA pre- and post-market cybersecurity guidance.
  • Preferred experience includes securing AI/ML systems, delivering cybersecurity programs and incident simulations, and working with globally distributed teams.
  • Preferred certifications include AWS Certified Security – Specialty, AWS Certified Solutions Architect, OSCP, GPEN, GCIH, GWAPT, CISSP, or CCSP.

Benefits

  • Flexible hybrid arrangement based in Sunnyvale, California, with at least 60% or 24 hours of the work week on-site and the remainder potentially remote.
  • Full-time role with occasional travel based on business needs.
  • Annual bonus and/or incentives may be available subject to applicable plans and company discretion.
  • Benefits include flexible time off or vacation, a 401(k) retirement plan with employer match, medical, dental, and vision coverage, and mindfulness programs.

Tech Stack

Categories

GRAIL

About GRAIL

1,001-5,000 employees
Contact me