Senior Security Engineer II
About the role
Braze is seeking a Senior Cloud Security Engineer II to join our Security Engineering function as a senior individual contributor and technical leader for cloud security. This role is a step up from our Senior Cloud Security Engineer position, focusing on setting technical direction, defining standards, and leading cross-team security initiatives. You will shape secure architecture, threat modeling, detection engineering, incident response, and Kubernetes/platform security across our cloud-native infrastructure spanning AWS, GCP, and self-managed Kubernetes. This is a pure individual contributor role where you lead through technical depth and influence rather than direct people management.
Responsibilities
- Set the technical direction (leadership & standards):
- Define cloud security standards, guardrails, and reference architectures for Infrastructure, SRE, and Product Engineering.
- Set your own objectives and roadmap for high-impact cloud security work in partnership with Security Engineering leadership.
- Lead cross-functional security initiatives end-to-end, including scoping, timelines, stakeholder management, and delivery.
- Mentor and uplevel other security and platform engineers through pairing, design review, and feedback.
- Represent cloud security in architecture and design forums, translating complex attack paths and risk into actionable guidance.
- Secure architecture & threat modeling:
- Own threat modeling as a repeatable, scalable practice for new cloud technologies and services.
- Partner with Infrastructure, SRE, and Product Engineering to design secure-by-default cloud architectures.
- Drive control-plane and IAM security strategy across AWS and GCP, including RBAC models and least privilege at scale.
- Assess posture, surface systemic and emerging risks, and set priorities to reduce them.
- Detection engineering, incident response & automation:
- Advance detection strategy by designing high-signal detections and SIEM rules for cloud threats.
- Serve as a senior incident responder and cloud-forensics lead for investigations across AWS and GCP.
- Codify incident response learnings into standard playbooks and preventative controls.
- Own and optimize security tooling (e.g., CrowdStrike, Tenable) and lead vulnerability management workflows.
- Kubernetes & platform security:
- Own the security of self-managed Kubernetes environments, including control plane, workload isolation, and admission control.
- Set standards for Infrastructure-as-Code (IaC) and pipeline security, hardening Terraform and CI/CD automation.
- Establish best practices for patch management, base-image hardening, and version management.
- Lead the security of large-scale distributed systems and self-managed data stores (e.g., MongoDB).
Requirements
- Several years owning cloud security in production, including on-call responsibilities.
- Hands-on experience with AWS as a primary cloud provider, working knowledge of GCP, and self-managed Kubernetes.
- Ability to read and write code (Python, Terraform preferred).
- Senior individual contributor who leads through technical depth and influence rather than authority.
- Ability to define objectives for ambiguous cloud security problems and deliver scalable solutions.
- Strong mentorship skills to uplevel peers through review, feedback, and standards.
- Deep expertise in secure architecture, threat modeling, detection engineering, and Kubernetes/platform security.
Pay
For candidates based in the United States, the pay range for this position at the start of employment is expected to be between $149,000 and $235,000/year, with an expected On Target Earnings (OTE) between $166,000 and $261,000/year (including bonus or commission). Your exact offer may vary depending on market location, job-related knowledge, skills, and experience. This role also qualifies for equity grants of restricted stock (RSUs).
Benefits
- Competitive compensation, including equity.
- Retirement and Employee Stock Purchase Plans.
- Flexible paid time off.
- Comprehensive medical, dental, vision, life, and disability coverage.
- Family services, including fertility benefits and equal paid parental leave.
- Professional development supported by formal career pathing, learning platforms, and a yearly learning stipend.
- Curated in-office employee experience fostering community and innovation.
- Opportunities for community giving, including Volunteer Week and donation matching.
- Employee Resource Groups providing supportive communities within Braze.
- Collaborative, transparent, and fun culture recognized as a Great Place to Work®.
About Braze
Braze is the leading customer engagement platform empowering brands to deliver personalized experiences through composable intelligence (BrazeAI™). Our platform enables marketers to combine and activate AI agents, models, and features for smarter, faster, and more meaningful customer engagement. Braze is a modern, cloud-first SaaS company running on distributed systems across AWS, GCP, and self-managed Kubernetes, with offices in New York, Austin, Berlin, London, San Francisco, Singapore, Sydney, and other global locations.