Senior Product Security Engineer
Snyk · United States - Boston Office
About this role
**Senior Product Security Engineer (Platform)** **About the role** Snyk is building the next generation security platform where security isn’t a queue of work—it’s a coordinated workforce of security agents working alongside your engineers. As a **Senior Product Security Engineer (Platform)**, you’ll pair deep **GCP and AWS infrastructure** expertise with **AI coding agents** to turn threat models into concrete **Terraform, Kubernetes, and pipeline** fixes, then work directly with platform teams to get those changes merged. **What you’ll do** - **Threat model** Snyk’s cloud infrastructure across **GCP and AWS** to identify security requirements, then negotiate changes with the teams that own the systems. - Use **AI coding agents** (e.g., Claude Code) to draft **Terraform, Kubernetes, and pipeline** changes that address security gaps for owning teams to review and merge. - Run **agent-driven fixes at scale** across many repositories, scoping changes so platform teams can confidently review and merge. - Write and maintain the **guidance AI agents rely on** (skills, prompts, instruction files, security baselines) to ensure consistent output quality. - Connect agents to **live cloud, CSPM, and ticketing data** via **MCP servers, CLI tools, and provider APIs** so fixes are grounded in the real environment. - **Critically review** AI-generated infrastructure changes (e.g., catch invented resources, unsafe defaults, and overly broad IAM permissions). - **Harden GCP IAM**, including resource hierarchy, roles/conditions, service accounts and workload identity federation, and organization policy constraints—plus the AWS IAM equivalent. - Improve **Kubernetes/container security** (primarily **GKE**): cluster hardening (private clusters, Autopilot), RBAC, admission control, workload identity, network policy, and secure image pipelines (Artifact Registry, Binary Authorization). - Add **automated security testing and CSPM tooling** to **CI/CD and GitOps** pipelines, and help teams triage and fix what those tools surface. - Benchmark infrastructure against secure configuration baselines (e.g., **CIS Google Cloud Foundation Benchmark**) and frameworks such as **ISO 27001** and **NIST 800-53**. - Limit risks introduced by AI agents (e.g., **prompt injection**, over-broad permissions, leaked secrets, and changes made without review). - Measure whether agent-driven fixing is working across teams and continuously improve the approach. **What you’ll bring** - **5–8 years** running or securing cloud infrastructure; ideally built and operated production platforms on **GCP or AWS**. - Deep, hands-on **GCP** knowledge (security services included) and solid working knowledge of **AWS** (AWS IAM depth is a bonus). - Strong grasp of **GCP IAM**: resource hierarchy, roles/conditions, service accounts/workload identity federation, organization policy constraints, and least-privilege design. - Practical **Kubernetes/container** experience (primarily **GKE**): private clusters/Autopilot, RBAC, admission control, workload identity, network policy, and secure container images. **EKS** experience welcome. - Comfort with **Infrastructure as Code** (e.g., **Terraform**) and automated deployment (**CI/CD**, **GitOps**). - Solid **DevSecOps** practice: threat modeling, shift-left testing, continuous monitoring, and the judgment to translate that into concrete infrastructure changes. - Confidence using **AI coding agents** day to day, including writing guidance/prompts tha
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.