Software Engineer — Security
Snorkel AI · New York City, NY (Hybrid); San Francisco, CA (Hybrid)
About this role
**Software Engineer — Security** **About Snorkel** At Snorkel, we believe meaningful AI doesn’t start with the model—it starts with the data. We help enterprises transform expert knowledge into specialized AI at scale, turning data into production-ready, high-performance systems. **About the Role** We’re seeking a **Security Engineer** to evolve Snorkel’s security posture across our **cloud infrastructure**, **developer platform**, and **product ecosystem**. You’ll partner with the security lead to secure cloud environments, build security automation, guide cross-functional initiatives, and embed security into engineering workflows. **Key Responsibilities** - Build and scale **Infrastructure as Code (IaC) governance** strategies that enable developer velocity - Operate and tune **Cloud Security Posture Management (CSPM)** tooling and coordinate remediation - Investigate **security events**, triage incidents, identify root causes, and own remediation - Architect secure **AWS cloud account structures** (landing zones, multi-account patterns, segmentation, cross-account roles) - Design **network security architectures** (security groups, NACLs, subnetting, routing, egress controls) - Establish secure-by-default patterns across **Kubernetes** and containerized workloads - Design and govern **IAM role & policy architectures** for human and machine identities - Implement **encryption everywhere** (data-at-rest, data-in-transit, key rotation with **AWS KMS**) - Conduct **threat modeling**, architecture reviews, and secure design assessments - Assess and secure **AI/ML product architectures** (trust boundaries, API boundaries, training/inference data flows) - Build secure automation using **Python**, AWS-native services, and **policy-as-code** frameworks - Own complex security projects end-to-end (discovery → design docs → implementation → rollout → long-term ownership) - Align cloud security strategy with **NIST CSF, ISO 27001, SOC 2, and CIS benchmarks** **Professional Skills** - Communicate security risks, trade-offs, and recommendations clearly to technical and non-technical audiences - Write concise, structured technical documentation (design docs, runbooks, postmortems, policy proposals) - Build alignment across teams without relying on positional authority - Partner cross-functionally to balance security posture with developer velocity - Default to collaboration over enforcement; seek to understand team workflows and constraints - Exercise judgment on when to push hard vs. accept managed risk with compensating controls - Teach and grow others through training, code review feedback, and accessible documentation **Technical Skills & Experience (Foundational)** - Programming skills in **Python, Go, or similar** for security tooling and automation - Experience operating systems at scale in **cloud-native, containerized environments** - Proficiency with **Infrastructure as Code (Terraform)** (modules, CI/CD, deployment governance, security reviews) - **AWS cloud architecture** (multi-account strategies, landing zones, isolation, cross-account roles) - **IAM** (least privilege; human and machine identity patterns) - **Network security** (security groups, NACLs, VPC design, subnet segmentation, routing, egress) **Preferred Experience (Nice-to-Have)** - Secure SDLC practices (SAST, SCA, SBOM automation, secrets scanning, bug bounty management) - Incident response / DFIR / on-call security operations - Detection engineering (SIEM, correlati
Listing freshness
CronJobs last confirmed this listing 17h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.