Security Engineer - Tech Lead
Lead design and implementation of security foundations including access governance, RBAC/ABAC, secrets management, and agent permissions for AI platforms. Partner with teams to embed secure practices while maintaining velocity; requires hands-on coding and production security experience.
About the job
What You’ll Do
- Design and mature how access to production systems is granted and governed
- Implement scalable RBAC / ABAC approaches across infrastructure and products
- Build robust secrets management and credential lifecycle practices
- Establish strong encryption and key management patterns
- Define how agents and automated systems receive authority, how it is scoped, and how it is revoked
- Create auditability and forensic visibility for user and system actions
- Lead threat modeling across infrastructure, product, and research domains
- Collaborate with engineering teams to make secure patterns easy and automatic
- Help drive readiness for enterprise security expectations and reviews
- Strengthen incident detection and response capabilities
- Raise the company’s security bar while preserving development velocity
Required
- Built and operated security foundations in real production environments
- Excellent at writing code, reviewing infrastructure, and shipping systems
- Recognize that in AI platforms, software systems can act with real authority
- Thought deeply about how services, automations, or models are scoped, constrained, and observed
- Think in terms of systems and trust boundaries
- High agency—identify problems and drive them to resolution
- Balance pragmatism with long-term rigor
- Engineers trust you and enjoy partnering with you
What Sets You Apart
- Helped organizations evolve toward mature, scalable security architectures
- Experience implementing least-privilege access and modern identity models
- Built durable approaches to secrets management and credential lifecycle
- Understand the nuances of securing multi-tenant AI platforms
- Strong opinions on how autonomous systems should be permissioned and governed
- Know how to build detection and response capabilities in high-growth environments
- Can represent the company in detailed customer and partner security discussions
- Build platforms and paved roads that engineers love to use
Compensation
Base pay range: $230,000 – $360,000 per year.
Skills
RBAC, Abac, Secrets Management, Encryption, Key Management, Threat Modeling, Identity Management, Access Control, Audit Logging, Incident Response
Similar jobs
Security Engineering jobsLeads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Leads a hands-on security engineering function spanning AI security, application and cloud security, detection and response, identity, and compliance controls. The role requires 8+ years of security engineering experience, deep AWS expertise, production code review ability, and experience operating in PCI DSS scope.
Owns production-edge security for enterprise financial-institution connectivity, including PKI, mTLS, AWS networking, webhook security, and vulnerability remediation. Requires 6+ years of hands-on platform, infrastructure, or network security engineering experience.
Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.
Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.