
Staff Security Engineer, Cloud & AI Platform
Brookfield Properties8 days ago
Remote, United StatesStaff+
Responsibilities
- Define cloud and AI security architecture, standards, secure-by-default patterns, and engineering guidance.
- Review infrastructure and application designs for authorization, networking, data protection, secrets, and tenant-isolation risks.
- Design and operate AWS multi-account security controls involving IAM, service control policies, KMS, VPC controls, WAF, logging, and detection.
- Build reusable security controls in Terraform or OpenTofu with testing, monitoring, safe rollout, and recovery patterns.
- Secure GitHub Actions and runners through OIDC trust, environment separation, workflow protection, action pinning, artifact integrity, and least-privilege deployment roles.
- Integrate secrets detection, dependency and container scanning, SBOMs, Infrastructure as Code analysis, code scanning, and risk-based release gates into developer workflows.
- Lead threat modeling and security design reviews for web applications, APIs, data ingestion, authentication and authorization flows, and agentic systems.
- Define secure patterns for Amazon Bedrock and other model platforms, and harden agent tools, MCP servers, gateways, sandboxes, and code-execution environments.
- Build repeatable AI security evaluations and adversarial tests and connect findings to engineering remediation.
- Lead technical response and root-cause remediation for cloud, identity, software supply chain, and AI security incidents.
- Mentor engineers, influence teams without direct authority, and produce control evidence for GRC and Privacy.
Requirements
- 8+ years of experience.
- Demonstrated senior or Staff-level ownership of production security or platform systems, including architecture decisions used by other engineers.
- Deep AWS security experience across IAM, multi-account or AWS Organizations environments, logging and detection, KMS, networking, and service-to-service authorization.
- Strong Terraform or OpenTofu skills, including modular design, remote execution, policy controls, and safe state-aware changes.
- Experience securing CI/CD systems such as GitHub Actions, including OIDC federation, runner trust boundaries, secrets, artifacts, and deployment permissions.
- Working knowledge of threat modeling, authentication and authorization, secure API design, secrets handling, dependency risk, and vulnerability remediation.
- Ability to read and write production-quality automation or application code in Python, Go, Ruby, or a comparable language.
- Ability to influence teams without direct management authority, make pragmatic risk decisions, and turn ambiguous security needs into implemented controls.
- Preferred experience with Amazon Bedrock, AgentCore, MCP, LLM gateways, AI guardrails, or production agentic systems.
- Preferred container and orchestration security experience with ECS/Fargate or EKS, image supply chains, runtime isolation, and egress control.
- Preferred identity platform experience with IAM Identity Center, Okta, Delinea, SAML, OIDC, OAuth, SCIM, ABAC, and enterprise entitlement systems.
- Preferred experience with Scalr, Terraform Cloud, CrowdStrike Falcon Cloud Security, Datadog, CloudWatch, or comparable tooling.
- Preferred experience securing data platforms involving S3, Snowflake, PostgreSQL/Aurora, or vendor data ingestion.
- Preferred AI threat modeling, red teaming, or security evaluation experience.
Benefits
- US TN-based remote work arrangement.
- 401(k) matching.
- Tuition reimbursement.
- Summer Fridays.
- Paid maternity leave.
- Employee referral program.
- Training and career development opportunities.