> Markdown version of [/jobs/ext/2160846-cloud-security-engineer-ii](https://www.wearedevelopers.com/jobs/ext/2160846-cloud-security-engineer-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer II - **Company:** Braze - **Location:** Boston, MA, United States - **Experience:** Expert - **Salary:** $235,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing, Cloud Computing Security, Continuous Integration, Data Stores, Distributed Systems, Disk Controller, Identity and Access Management, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Python (Programming Language), MongoDB, Network Control, Role-Based Access Control, Reliability Engineering, Security Information and Event Management, Software Vulnerability Management, Kubernetes, Patch Management, Terraform, Software Version Control - **Published:** August 21, 2026 - **Apply:** https://job-boards.greenhouse.io/braze/jobs/8140264 ## About the Role You are a senior individual contributor who leads through technical depth and influence rather than authority. You can take an ambiguous, open-ended cloud security problem, define the objective yourself, and deliver a solution that becomes the way Braze does it going forward. You translate complex cloud attack paths, IAM misconfigurations, and multi-step threat scenarios into guidance engineers adopt, and you balance strong controls with operational reality. You raise the people around you - through mentorship, review, and the standards you set - and you stay current with the cloud security landscape, tools, and threats. Above all, you can walk someone through the messy middle - what you tried, what broke, and what you'd do differently., * Several years owning cloud security in production - on-call for it, not adjacent to it * Hands-on, not theoretical: AWS as primary cloud, working GCP, self-managed Kubernetes * You read and write code (Python, TF) ## Description Set the technical direction (leadership & standards): * Define the cloud security standards, guardrails, and reference architectures that Infrastructure, SRE, and Product Engineering build on - turning point-in-time fixes into durable, org-wide patterns * Set your own objectives and roadmap for high-impact cloud security work, in partnership with Security Engineering leadership, and drive it to measurable outcomes * Lead cross-functional security initiatives end to end - scope, timeline, stakeholders, and delivery - guiding technical debates to a decision and owning the result * Mentor and uplevel other security and platform engineers through pairing, design review, and feedback; act as a force multiplier and the go-to technical resource for cloud security * Represent cloud security in architecture and design forums, translating complex attack paths and risk into clear, actionable guidance engineers will actually adopt Secure architecture & threat modeling: * Own threat modeling as a discipline for new cloud technologies, services, and patterns adopted across Engineering - making it a repeatable, scalable practice rather than a one-off exercise * Partner with Infrastructure, SRE, and Product Engineering to design secure-by-default cloud architectures and build practical, scalable controls across AWS, GCP, and self-managed systems * Drive control-plane and IAM security strategy across AWS and GCP, including relationships with external identity providers, RBAC models, and least privilege at scale * Continually assess posture, surface systemic and emerging risk, and set the priorities that reduce it Detection engineering, incident response & automation: * Advance our detection strategy: design high-signal detections and SIEM rules (with our SIEM Management function) and own detection coverage for cloud threats end to end * Serve as a senior incident responder and cloud-forensics lead for cloud and run-time security investigations across AWS and GCP - and codify what you learn into standard IR playbooks and preventative controls * Own and optimize security tooling such as CrowdStrike (EDR/CSPM/IR), Tenable, and native cloud security services, and lead our vulnerability management workflow - scanning, triage, prioritization, and remediation - for cloud assets Kubernetes & platform security: * Own the security of our self-managed Kubernetes environments - control plane, nodes, workload isolation, admission control, run-time security, and the CI/CD supply chain feeding them * Set the standards for Infrastructure-as-Code and pipeline security (Terraform preferred): design and harden IaC and CI/CD automation so security is built into how we ship * Establish best practices for patch management, base-image hardening, and version management across containerized and VM-based environments * Lead the security of large-scale, distributed systems and self-managed data stores (e.g., MongoDB), accounting for their real-world operational and security implications ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [40 Minutes to Build a Serverless COVID-19 REST and GraphQL APIs](https://www.wearedevelopers.com/videos/208-40-minutes-to-build-a-serverless-covid-19-rest-and-graphql-apis) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)