CronJobs

security jobs

Senior Product Security Engineer

Snyk · United States - Boston Office

hybridsenior$192,000–$240,000Posted Sep 30, 2026GCPAWSKubernetesTerraformIAMGKECI/CDGitOps

Apply on the employer site

About this role

**Senior Product Security Engineer (Platform)** **About the role** Snyk is building the next generation security platform where security isn’t a queue of work—it’s a coordinated workforce of security agents working alongside your engineers. As a **Senior Product Security Engineer (Platform)**, you’ll pair deep **GCP and AWS infrastructure** expertise with **AI coding agents** to turn threat models into concrete **Terraform, Kubernetes, and pipeline** fixes, then work directly with platform teams to get those changes merged. **What you’ll do** - **Threat model** Snyk’s cloud infrastructure across **GCP and AWS** to identify security requirements, then negotiate changes with the teams that own the systems. - Use **AI coding agents** (e.g., Claude Code) to draft **Terraform, Kubernetes, and pipeline** changes that address security gaps for owning teams to review and merge. - Run **agent-driven fixes at scale** across many repositories, scoping changes so platform teams can confidently review and merge. - Write and maintain the **guidance AI agents rely on** (skills, prompts, instruction files, security baselines) to ensure consistent output quality. - Connect agents to **live cloud, CSPM, and ticketing data** via **MCP servers, CLI tools, and provider APIs** so fixes are grounded in the real environment. - **Critically review** AI-generated infrastructure changes (e.g., catch invented resources, unsafe defaults, and overly broad IAM permissions). - **Harden GCP IAM**, including resource hierarchy, roles/conditions, service accounts and workload identity federation, and organization policy constraints—plus the AWS IAM equivalent. - Improve **Kubernetes/container security** (primarily **GKE**): cluster hardening (private clusters, Autopilot), RBAC, admission control, workload identity, network policy, and secure image pipelines (Artifact Registry, Binary Authorization). - Add **automated security testing and CSPM tooling** to **CI/CD and GitOps** pipelines, and help teams triage and fix what those tools surface. - Benchmark infrastructure against secure configuration baselines (e.g., **CIS Google Cloud Foundation Benchmark**) and frameworks such as **ISO 27001** and **NIST 800-53**. - Limit risks introduced by AI agents (e.g., **prompt injection**, over-broad permissions, leaked secrets, and changes made without review). - Measure whether agent-driven fixing is working across teams and continuously improve the approach. **What you’ll bring** - **5–8 years** running or securing cloud infrastructure; ideally built and operated production platforms on **GCP or AWS**. - Deep, hands-on **GCP** knowledge (security services included) and solid working knowledge of **AWS** (AWS IAM depth is a bonus). - Strong grasp of **GCP IAM**: resource hierarchy, roles/conditions, service accounts/workload identity federation, organization policy constraints, and least-privilege design. - Practical **Kubernetes/container** experience (primarily **GKE**): private clusters/Autopilot, RBAC, admission control, workload identity, network policy, and secure container images. **EKS** experience welcome. - Comfort with **Infrastructure as Code** (e.g., **Terraform**) and automated deployment (**CI/CD**, **GitOps**). - Solid **DevSecOps** practice: threat modeling, shift-left testing, continuous monitoring, and the judgment to translate that into concrete infrastructure changes. - Confidence using **AI coding agents** day to day, including writing guidance/prompts tha

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord