Staff Security Engineer
Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.
About the job
Responsibilities
- Participate in daily security operations, including on-call rotation, threat modeling, and incident response.
- Architect and develop performant detective tooling, automation, systems, and services.
- Define Detection and Response strategy and deliver multi-year roadmaps, programs, and projects.
- Prioritize improvements to the Incident Response program and broader security operations.
- Conduct technology and security research and architecture reviews across the Twilio platform.
- Collaborate with internal customers to understand and solve challenges involving diverse threat actors and activity.
- Mentor and support team members and build effective internal relationships.
Requirements
- 3+ years of security engineering experience in a production cloud environment.
- Subject-matter expertise in security issues and technologies.
- Experience designing and building AI agents and agentic workflows.
- Ability to use AI for complex threat hunting and high-fidelity detections.
- Experience detecting and responding to AI threats using MITRE ATLAS or a similar framework.
- Advanced knowledge of service-oriented architectures and cloud security technologies.
- Experience addressing difficult security challenges across a technology stack.
- Experience with SIEM platforms and extending their functionality.
- Experience with SOAR tools and automating manual security processes.
- Experience with infrastructure as code, such as Terraform or CloudFormation.
- Experience with AWS, Google Cloud, or another major cloud platform.
Nice-to-haves
- Excellent written and verbal communication skills.
- Ability to influence and build effective relationships across organizational levels.
- Bachelor's degree in Computer Science, Engineering, or a related technical discipline, or equivalent experience.
Compensation and benefits
- Salary ranges vary by eligible U.S. location:
- Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont, or Washington, D.C.: $155,520–$194,400.
- New York, New Jersey, Washington State, or California outside the San Francisco Bay Area: $164,640–$205,800.
- San Francisco Bay Area, California: $182,960–$228,700.
- May be eligible for equity and a corporate bonus plan.
- Benefits include healthcare insurance, 401(k), paid sick time, paid personal time off, and paid parental leave.
- Occasional travel may be required for project or team meetings.
Skills
Threat Modeling, Incident Response, AI Agents, Agentic Workflows, Threat Hunting, Mitre Atlas, Service-Oriented Architecture, SIEM, Soar, Terraform, CloudFormation, AWS, GCP, Security Automation, Cloud Security
Similar jobs
Security Engineering jobsLeads enterprise AI security architecture and develops security systems, automation, and agentic AI identity strategies at scale. Requires 7+ years in security or infrastructure security, enterprise technical leadership, cloud and container security expertise, and strong programming skills.
Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.
Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.
Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.
Staff-level security engineer leading enterprise IAM, cloud identity, AI platform access, and non-human identity governance. The role requires deep Okta, infrastructure-as-code, Python, GCP or AWS, and regulated-environment experience.