Senior Software Engineer
Senior Software Engineer building Snowflake's core identity, access management, and AI-native security infrastructure for the Data Cloud. Design secure agent workflows, IAM systems, encryption, and policy enforcement tooling at massive scale.
About the job
Responsibilities
- Design and implement critical AI security capabilities — including controlled, audited agent workflows, MCP server and client security, agent identity frameworks, and admin guardrails — that form the foundation for secure agentic enterprise adoption.
- Build and evolve foundational identity and access management systems, including authentication protocols, SSO integrations, multi-factor authentication, OAuth/OIDC, SAML, SCIM, and fine-grained RBAC that scales to millions of objects and users.
- Design and develop core security infrastructure spanning secret management, key management, service identity, and end-to-end encryption across a natively multi-cloud environment.
- Build and maintain security tooling to define, monitor, enforce, and detect policy violations across the platform; implement automation and self-service processes that increase developer autonomy and promote secure-by-default engineering.
- Design and implement extensible, plug-and-play platform components that enable first-, second-, and third-party security detectors, responders, and visualizations to be built on top of Snowflake's Trust Center.
- Leverage industry-accredited benchmarks (e.g., CIS) to develop standards-based security posture assessments; contribute to behavioral analytics pipelines and PII attribution capabilities that help detect, prevent, and respond to threats and abuse vectors.
- Partner with engineering teams across the company to understand security pain points and deliver solutions that reduce friction without compromising safety.
- Lead the design and enforcement of secure network architectures to actively defend against ransomware attacks and detect sophisticated data exfiltration attempts.
- Participate in design reviews, code reviews, and on-call rotations; hold a high bar for code quality, reliability, and sound technical decisions.
Requirements
- 5+ years of industry experience designing, building, and operating large-scale distributed systems in production cloud environments.
- Strong foundational computer science skills — data structures, algorithms, systems design, and distributed computing.
- Proficiency in one or more of Java, C++, Python, Golang, or Rust, with solid SQL skills for data-driven features.
- Experience shipping and on-calling production services with a focus on availability, reliability, and observability.
- A collaborative, low-ego approach to engineering — comfortable iterating quickly and working across PM, design, and peer engineering teams.
- BS in Computer Science, Computer Engineering, or a related technical discipline, or equivalent practical experience.
Nice-to-Haves
- Knowledge of identity and access management concepts and protocols — SAML, SCIM, OAuth, OIDC, Federation, MFA, or RBAC.
- Familiarity with security infrastructure domains such as secret management, key management, service identity, authentication, or authorization.
- Experience with database internals, query engines, or data platform systems.
- Exposure to machine learning or AI systems, particularly applied to anomaly detection, behavioral analytics, or risk classification.
- Contributions to developer platforms, SDKs, or multi-tenant extensibility frameworks.
- Experience deploying and operating services on Kubernetes or production cloud platforms (AWS, Azure, or GCP).
Skills
Java, C++, Python, Go, Rust, SQL, Distributed Systems, IAM, SAML, SCIM, OAuth, OIDC, RBAC, Kubernetes, AWS
Similar jobs
Security Engineering jobsBuild secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.
Own and advance the security of Anyscale’s production and multi-cloud infrastructure, including hardening, segmentation, Kubernetes runtime protection, and access controls. Requires 8+ years of security engineering experience and hands-on expertise with AWS, Azure, Kubernetes, and cloud security tooling.
Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.