Senior Security Engineer II
Braze · Chicago, IL · 1 mo ago
HybridInformation Technology$149k–$235k/yrFull-time
About the role
Braze is seeking a Senior Cloud Security Engineer II to lead our Security Engineering function. This role is a step up from our Senior Cloud Security Engineer role, where the incumbent executes and improves our cloud security controls. The Senior Cloud Security Engineer II sets the technical direction, defines standards and reference patterns, leads cross-team security initiatives, mentors and uplevels other security and platform engineers, and represents cloud security in architecture and design forums.
Responsibilities
- Set the technical direction (leadership & standards):
- Define cloud security standards, guardrails, and reference architectures
- Drive high-impact cloud security work with measurable outcomes
- Lead cross-functional security initiatives end to end:
- Scope, timeline, stakeholders, and delivery
- Guide technical debates to a decision and own the result
- Mentor and uplevel other security and platform engineers:
- Pair, design review, and feedback
- Act as a force multiplier and go-to technical resource for cloud security
- Represent cloud security in architecture and design forums:
- Translate complex attack paths and risk into clear, actionable guidance
- Secure architecture & threat modeling:
- Own threat modeling as a discipline for new cloud technologies
- Design secure-by-default cloud architectures and build practical, scalable controls
- Drive control-plane and IAM security strategy across AWS and GCP
- Assess posture, surface systemic and emerging risk, and set priorities to reduce it
- Detection engineering, incident response & automation:
- Advance detection strategy: design high-signal detections and SIEM rules
- Own detection coverage for cloud threats end to end
- Serve as a senior incident responder and cloud-forensics lead
- Codify learned insights into standard IR playbooks and preventative controls
- Optimize security tooling such as CrowdStrike, Tenable, and native cloud security services
- Lead vulnerability management workflow for cloud assets
- Kubernetes & platform security:
- Own the security of self-managed Kubernetes environments
- Set standards for Infrastructure-as-Code and pipeline security
- Establish best practices for patch management, base-image hardening, and version management
Qualifications
- Several years owning cloud security in production — on-call for it, not adjacent to it
- Hands-on, not theoretical: AWS as primary cloud, working GCP, self-managed Kubernetes
- Read and write code (Python, TF)
What you are
- A senior individual contributor who leads through technical depth and influence rather than authority
- Can take an ambiguous, open-ended cloud security problem, define the objective yourself, and deliver a solution that becomes the way Braze does it going forward
- Translate complex cloud attack paths, IAM misconfigurations, and multi-step threat scenarios into guidance engineers adopt
- Balance strong controls with operational reality
- Raise the people around you — through mentorship, review, and the standards you set — and stay current with the cloud security landscape, tools, and threats
- Walk someone through the messy middle — what you tried, what broke, and what you'd do differently
Hard prerequisites
- Several years owning cloud security in production — on-call for it, not adjacent to it
- Hands-on, not theoretical: AWS as primary cloud, working GCP, self-managed Kubernetes
- Read and write code (Python, TF)
Pay and Benefits
The pay range for this position at the start of employment is expected to be between $149,000 and $235,000/year with an expected On Target Earnings (OTE) between $166,000 and $261,000/year (including bonus or commission).