Senior Security Engineer II
at Braze
- Seniority
- Senior
- Location
- Boston
- Posted
- 5d ago
at Braze
<div class="content-intro"><p>At Braze, we have found our people. We’re a genuinely approachable, exceptionally kind, and intensely passionate crew.</p> <p>We seek to ignite that passion by setting high standards, championing teamwork, and creating work-life harmony as we collectively navigate rapid growth on a global scale while striving for greater equity and opportunity – inside and outside our organization.</p> <p>To flourish here, you must be prepared to set a high bar for yourself and those around you. There is always a way to contribute: Acting with autonomy, having accountability and being open to new perspectives are essential to our continued success.</p> <p>Our deep curiosity to learn and our eagerness to share diverse passions with others gives us balance and injects a one-of-a-kind vibrancy into our culture.</p> <p>If you are driven to solve exhilarating challenges and have a bias toward action in the face of change, you will be empowered to make a real impact here, with a sharp and passionate team at your back. If Braze sounds like a place where you can thrive, we can’t wait to meet you.</p></div><p>Braze is a modern, cloud-first SaaS company running entirely on cloud-native infrastructure — large-scale, distributed systems spanning AWS, GCP, and self-managed Kubernetes, backed by self-managed data stores such as MongoDB. We're looking for a Senior Cloud Security Engineer II to join our Security Engineering function as a senior individual contributor and technical leader for cloud security.</p> <p>This is a step up from our Senior Cloud Security Engineer role. Where a Senior engineer executes and improves our cloud security controls, a Senior Cloud Security Engineer II sets the technical direction: you define the standards and reference patterns other engineers build on, lead cross-team security initiatives end to end, take on the ambiguous problems that don't yet have a playbook (and write the playbook), and raise the bar for the whole team through mentorship and review. You'll go especially deep across three areas — secure architecture and threat modeling, detection engineering and incident response, and Kubernetes and platform security — and you'll shape how Braze does cloud security across Engineering. This is a pure IC role; you lead through technical depth and influence rather than direct people management.</p> <p><strong>WHAT YOU'LL DO</strong></p> <p>Set the technical direction (leadership & standards):</p> <ul> <li>Define the cloud security standards, guardrails, and reference architectures that Infrastructure, SRE, and Product Engineering build on — turning point-in-time fixes into durable, org-wide patterns</li> <li>Set your own objectives and roadmap for high-impact cloud security work, in partnership with Security Engineering leadership, and drive it to measurable outcomes</li> <li>Lead cross-functional security initiatives end to end — scope, timeline, stakeholders, and delivery — guiding technical debates to a decision and owning the result</li> <li>Mentor and uplevel other security and platform engineers through pairing, design review, and feedback; act as a force multiplier and the go-to technical resource for cloud security</li> <li>Represent cloud security in architecture and design forums, translating complex attack paths and risk into clear, actionable guidance engineers will actually adopt</li> </ul> <p>Secure architecture & threat modeling:</p> <ul> <li>Own threat modeling as a discipline for new cloud technologies, services, and patterns adopted across Engineering — making it a repeatable, scalable practice rather than a one-off exercise</li> <li>Partner with Infrastructure, SRE, and Product Engineering to design secure-by-default cloud architectures and build practical, scalable controls across AWS, GCP, and self-managed systems</li> <li>Drive control-plane and IAM security strategy across AWS and GCP, including relationships with external identity providers, RBAC models, and least privilege at scale</li> <li>Continually assess posture, surface systemic and emerging risk, and set the priorities that reduce it</li> </ul> <p>Detection engineering, incident response & automation:</p> <ul> <li>Advance our detection strategy: design high-signal detections and SIEM rules (with our SIEM Management function) and own detection coverage for cloud threats end to end</li> <li>Serve as a senior incident responder and cloud-forensics lead for cloud and run-time security investigations across AWS and GCP — and codify what you learn into standard IR playbooks and preventative controls</li> <li>Own and optimize security tooling such as CrowdStrike (EDR/CSPM/IR), Tenable, and native cloud security services, and lead our vulnerability management workflow — scanning, triage, prioritization, and remediation — for cloud assets</li> </ul> <p>Kubernetes & platform security:</p> <ul> <li>Own the security of our self-managed Kubernetes environments — control plane, nodes, workload isolation, admission control, run-time security, and the CI/CD supply chain feeding them</li> <li>Set the standards for Infrastructure-as-Code and pipeline security (Terraform preferred): design and harden IaC and CI/CD automation so security is built into how we ship</li> <li>Establish best practices for patch management, base-image hardening, and version management across containerized and VM-based environments</li> <li>Lead the security of large-scale, distributed systems and self-managed data stores (e.g., MongoDB), accounting for their real-world operational and security implications</li> </ul> <p><strong>WHO YOU ARE</strong></p> <p>You are a senior individual contributor who leads through technical depth and influence rather than authority. You can take an ambiguous, open-ended cloud security problem, define the objective yourself, and deliver a solution that becomes the way Braze does it going forward. You translate complex cloud attack paths, IAM misconfigurations, and multi