Director of Engineering - Application, Cloud and Offensive Security
Leads engineering teams across application security, cloud security assurance, and offensive security (red team) at Snowflake. Defines strategy, builds high-performing teams, embeds security in AI products, and communicates risks to executives. Requires 12+ years in security engineering leadership and deep expertise in at least two security pillars.
About the job
Responsibilities
- Define and execute the security strategy across three core pillars: application security, cloud security assurance, and offensive security (including the red team program), setting direction and driving measurable outcomes across all three pillars.
- Build and develop a high-performing security engineering organization, hiring top talent and creating a culture of rigor, ownership, and continuous improvement.
- Drive the offensive security program including red team operations, adversarial simulations, and proactive threat modeling to stay ahead of emerging attack vectors in an AI-accelerated threat landscape.
- Partner closely with engineering, product, and infrastructure leadership to embed security into Snowflake's AI products and cloud architecture from the ground up.
- Own the cloud security assurance function, ensuring Snowflake's cloud environment meets the security standards expected by enterprise customers and regulators worldwide.
- Translate security risk into business impact, communicating program status, emerging threats, and strategic priorities to executive stakeholders with clarity and confidence.
- Influence company-wide security posture through cross-functional collaboration with Legal, Compliance, Trust, and the broader CISO organization.
Requirements
- 12+ years of progressive experience in security engineering, with significant tenure in leadership roles overseeing multi-domain security programs (or equivalent experience).
- Deep expertise across at least two of the three pillars: application security, cloud security, or offensive security, with working knowledge across all three.
- Proven track record building and scaling high-performing security engineering teams in a fast-paced enterprise technology environment.
- Strong command of cloud security architecture across AWS, Azure, or GCP, including cloud-native security controls, identity, and infrastructure security.
- Experience leading or overseeing a red team or offensive security program, with a clear understanding of adversarial tactics, techniques, and procedures (TTPs).
- Exceptional ability to partner with product and engineering organizations, influencing secure-by-design practices and embedding security without creating velocity drag.
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
Nice-to-Haves
- Experience securing AI/ML workloads, large language model infrastructure, or AI-adjacent attack surfaces.
- Familiarity with security for multi-tenant cloud data platforms at enterprise scale.
- Industry certifications such as CISSP, OSCP, GREM, or equivalent.
- Contributions to industry security research, conference presentations, or open-source security tooling.
Skills
Application Security, Cloud Security, Offensive Security, Red Team, AWS, Azure, GCP, Kubernetes, Ttps, Ai/Ml Security, Cissp, Oscp, Grem
Similar jobs
Engineering Management jobsLeads the technical direction, engineering quality, reliability, and hands-on architecture of a 30-person organization building payment, ledger, wallet, and settlement infrastructure. Requires 10+ years of production software experience, 4+ years leading engineers, and deep distributed-systems and regulated-finance expertise.
Leads the product and engineering strategy for AI-native enterprise applications across Finance, HR, and Legal, partnering with executives to transform workflows into intelligent products. Requires 15+ years in enterprise technology, product management, or software engineering and substantial multidisciplinary leadership experience.
Leads the AI Platform organization, setting technical strategy for production AI agents and the shared platform used across the company. Requires 12+ years of engineering experience, including leadership through managers and strong expertise in agent architecture, evaluation, reliability, and guardrails.
Leads a team building foundational security services for Crusoe’s GPU cloud and infrastructure fleet, spanning identity, cryptography, runtime protection, access, vulnerability management, and architectural isolation. Requires 8+ years leading hands-on software or security engineering teams at large-scale infrastructure platforms.
Leads the architecture, production launch, and team buildout for a safety-critical flexible-compute control system that manages AI infrastructure power in coordination with utilities. Requires extensive software engineering and team leadership experience, distributed orchestration expertise, and knowledge of data-center power systems and grid programs.