Cloud Security Engineer II
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+9 more
Job description
Set the technical direction (leadership & standards):
- Define the cloud security standards, guardrails, and reference architectures that Infrastructure, SRE, and Product Engineering build on - turning point-in-time fixes into durable, org-wide patterns
- Set your own objectives and roadmap for high-impact cloud security work, in partnership with Security Engineering leadership, and drive it to measurable outcomes
- Lead cross-functional security initiatives end to end - scope, timeline, stakeholders, and delivery - guiding technical debates to a decision and owning the result
- Mentor and uplevel other security and platform engineers through pairing, design review, and feedback; act as a force multiplier and the go-to technical resource for cloud security
- Represent cloud security in architecture and design forums, translating complex attack paths and risk into clear, actionable guidance engineers will actually adopt
Secure architecture & threat modeling:
- Own threat modeling as a discipline for new cloud technologies, services, and patterns adopted across Engineering - making it a repeatable, scalable practice rather than a one-off exercise
- Partner with Infrastructure, SRE, and Product Engineering to design secure-by-default cloud architectures and build practical, scalable controls across AWS, GCP, and self-managed systems
- Drive control-plane and IAM security strategy across AWS and GCP, including relationships with external identity providers, RBAC models, and least privilege at scale
- Continually assess posture, surface systemic and emerging risk, and set the priorities that reduce it
Detection engineering, incident response & automation:
- Advance our detection strategy: design high-signal detections and SIEM rules (with our SIEM Management function) and own detection coverage for cloud threats end to end
- Serve as a senior incident responder and cloud-forensics lead for cloud and run-time security investigations across AWS and GCP - and codify what you learn into standard IR playbooks and preventative controls
- Own and optimize security tooling such as CrowdStrike (EDR/CSPM/IR), Tenable, and native cloud security services, and lead our vulnerability management workflow - scanning, triage, prioritization, and remediation - for cloud assets
Kubernetes & platform security:
- Own the security of our self-managed Kubernetes environments - control plane, nodes, workload isolation, admission control, run-time security, and the CI/CD supply chain feeding them
- Set the standards for Infrastructure-as-Code and pipeline security (Terraform preferred): design and harden IaC and CI/CD automation so security is built into how we ship
- Establish best practices for patch management, base-image hardening, and version management across containerized and VM-based environments
- Lead the security of large-scale, distributed systems and self-managed data stores (e.g., MongoDB), accounting for their real-world operational and security implications
Requirements
You are a senior individual contributor who leads through technical depth and influence rather than authority. You can take an ambiguous, open-ended cloud security problem, define the objective yourself, and deliver a solution that becomes the way Braze does it going forward. You translate complex cloud attack paths, IAM misconfigurations, and multi-step threat scenarios into guidance engineers adopt, and you balance strong controls with operational reality. You raise the people around you - through mentorship, review, and the standards you set - and you stay current with the cloud security landscape, tools, and threats. Above all, you can walk someone through the messy middle - what you tried, what broke, and what you’d do differently., * Several years owning cloud security in production - on-call for it, not adjacent to it
- Hands-on, not theoretical: AWS as primary cloud, working GCP, self-managed Kubernetes
- You read and write code (Python, TF)
Benefits & conditions
For candidates based in the United States, the pay range for this position at the start of employment is expected to be between $149,000 and $235,000/year with an expected On Target Earnings (OTE) between $166,000 and $261,000/year (including bonus or commission). Your exact offer may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. In addition to cash compensation, this role qualifies for a comprehensive Total Rewards package that includes equity grants of restricted stock (RSUs) so that you will own a piece of our company., Braze benefits vary by location, and we encourage you to review our specific benefits offerings for each country here. More details on benefits plans will be provided if you receive an offer of employment.
From offering comprehensive benefits to fostering hybrid ways of working, we’ve got you covered so you can prioritize work-life harmony. Braze offers benefits such as:
- Competitive compensation that may include equity
- Retirement and Employee Stock Purchase Plans
- Flexible paid time off
- Comprehensive benefit plans covering medical, dental, vision, life, and disability
- Family services that include fertility benefits and equal paid parental leave
- Professional development supported by formal career pathing, learning platforms, and a yearly learning stipend
- A curated in-office employee experience, designed to foster community, team connections, and innovation
- Opportunities to give back to your community, including an annual company-wide Volunteer Week and donation matching
- Employee Resource Groups that provide supportive communities within Braze
- Collaborative, transparent, and fun culture recognized as a Great Place to Work®, Select… Will you now or in the future require visa sponsorship?* Select… LinkedIn Profile Select ‘Yes’ to join Braze’s Talent Community and receive newsletters to help you stay up to date on career-related news, events and opportunities at Braze. * Select…
About the company
At Braze, we have found our people. We’re a genuinely approachable, exceptionally kind, and intensely passionate crew.
We seek to ignite that passion by setting high standards, championing teamwork, and creating work-life harmony as we collectively navigate rapid growth on a global scale while striving for greater equity and opportunity - inside and outside our organization.
To flourish here, you must be prepared to set a high bar for yourself and those around you. There is always a way to contribute: Acting with autonomy, having accountability and being open to new perspectives are essential to our continued success.
Our deep curiosity to learn and our eagerness to share diverse passions with others gives us balance and injects a one-of-a-kind vibrancy into our culture.
If you are driven to solve exhilarating challenges and have a bias toward action in the face of change, you will be empowered to make a real impact here, with a sharp and passionate team at your back. If Braze sounds like a place where you can thrive, we can’t wait to meet you.
Braze is a modern, cloud-first SaaS company running entirely on cloud-native infrastructure - large-scale, distributed systems spanning AWS, GCP, and self-managed Kubernetes, backed by self-managed data stores such as MongoDB. We’re looking for a Senior Cloud Security Engineer II to join our Security Engineering function as a senior individual contributor and technical leader for cloud security.
This is a step up from our Senior Cloud Security Engineer role. Where a Senior engineer executes and improves our cloud security controls, a Senior Cloud Security Engineer II sets the technical direction: you define the standards and reference patterns other engineers build on, lead cross-team security initiatives end to end, take on the ambiguous problems that don’t yet have a playbook (and write the playbook), and raise the bar for the whole team through mentorship and review. You’ll go especially deep across three areas - secure architecture and threat modeling, detection engineering and incident response, and Kubernetes and platform security - and you’ll shape how Braze does cloud security across Engineering. This is a pure IC role; you lead through technical depth and influence rather than direct people management., Braze is the leading customer engagement platform that empowers brands to Be Absolutely Engaging . Braze helps brands deliver great customer experiences that drive value both for consumers and for their businesses. Built on a foundation of composable intelligence, BrazeAI allows marketers to combine and activate AI agents, models, and features at every touchpoint throughout the Braze Customer Engagement Platform for smarter, faster, and more meaningful customer engagement. From cross-channel messaging and journey orchestration to Al-powered decisioning and optimization, Braze enables companies to turn action into interaction through autonomous, 1:1 personalized experiences.
The company has been consistently recognized as a Leader in marketing technology by industry analysts, and was named a G2 “Best of Marketing and Digital Advertising Software Product” in 2026. Braze was also named a 2026 Best Places to Work by Built In, a 2025 America’s Greenest Companies by Newsweek, and a 2025 Fortune Best Workplace in Technology by Great Place To Work®. Braze is also proudly certified as a Great Place to Work® in the U.S., the UK, Australia, and Singapore.
The company is headquartered in New York with offices in Austin, Berlin, Bucharest, Chicago, Dubai, Jakarta, London, Paris, San Francisco, São Paulo, Singapore, Seoul, Sydney and Tokyo. BRAZE IS AN EQUAL OPPORTUNITY EMPLOYER
At Braze, we strive to create equitable growth and opportunities inside and outside the organization.
Building meaningful connections is at the heart of everything we do, and that includes our recruiting practices. We’re committed to offering all candidates a fair, accessible, and inclusive experience - regardless of age, color, disability, gender identity, marital status, maternity, national origin, pregnancy, race, religion, sex, sexual orientation, or status as a protected veteran. When applying and interviewing with Braze, we want you to feel comfortable showcasing what makes you you., We are also committed to providing reasonable accommodations to qualified individuals with disabilities. To request an accommodation as part of the interview process or during your potential employment with Braze, please let your recruiter know and a member of our People Relations team will follow up with you.
When sharing your veteran status, please consider the following:
-
A “disabled veteran” is one of the following:
- a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
- a person who was discharged or released from active duty because of a service-connected disability.
A “recently separated veteran” means any veteran during the three-year period beginning on the date of such veteran’s discharge or release from active duty in the U.S. military, ground, naval, or air service.
An “active duty wartime or campaign badge veteran” means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
An “Armed forces service medal veteran” means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.
When sharing your disability status, please consider the following:
You are considered to have a disability if you have a physical or mental impairment or medical condition that substantially limits a major life activity, or if you have a history or record of such an impairment or medical condition. Voluntary Self-Identification of Race/Ethnicity (Check all that apply) Select… Voluntary Self-Identification of Gender and Gender Identity (Select one) Select… Voluntary Self-Identification of Veteran Status (Select one) Select…
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
7 Cloud Computing Trends Coming in 2025 for Developers
Highest Paying Tech Companies for Developers