Senior Product Security Engineer

Snyk Ltd.

Boston, Northern (MA, KY)

Hybrid

USD 140,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Snyk is seeking a Senior Product Security Engineer (Platform) to bridge cloud security with AI-driven code fixes. You will collaborate with platform teams to implement Terraform, Kubernetes, and CI/CD changes, ensuring secure-by-default options for the engineers building Snyk's platform.

You'll work across GCP and AWS, focusing on IAM, Kubernetes hardening, and secure container pipelines, while enabling AI agents to operate safely and at scale.

Qualifications

  • 5-8 years running or securing cloud infrastructure, ideally production platforms on GCP/AWS.
  • Deep GCP security services knowledge with working AWS familiarity.
  • Strong GCP IAM understanding: hierarchy, roles, service accounts, federation.
  • Practical Kubernetes and container security on GKE; EKS welcome.

Responsibilities

  • Threat model Snyk's cloud infra across GCP/AWS and negotiate changes with owning teams.
  • Use AI agents to draft Terraform/Kubernetes/pipeline fixes and submit for merge.
  • Run agent-driven fixes at scale with scoped changes for review.
  • Write and maintain guidance AI agents rely on to meet standards.
  • Connect agents to live cloud data via MCP, CLI tools, and provider APIs.
  • Critically review AI-generated changes for unsafe defaults and over-broad IAM.
  • Harden IAM across GCP and AWS and ensure least privilege.
  • Improve Kubernetes security and secure container pipelines.

Skills

Cloud security
GCP knowledge
AWS knowledge
IAM expertise
Kubernetes security
Terraform
CI/CD
DevSecOps
Threat modeling
AI coding agents

Tools

Terraform
Kubernetes
Artifact Registry
Binary Authorization

Job description

Unleash AI Innovators, Securely

Software is being rewritten in real time. AI agents are starting to write more code than humans do, at a speed no security team has ever had to match, and that single shift is opening up the biggest opportunity our industry has seen in a decade. We're not bracing for it, we're building the company that owns it.

Snyk is building the next generation security platform where security isn't a set of tools people operate. It's a team of security agents working alongside your engineers, finding, fixing, and governing risk at the speed software is now built. These agents work alongside both the company build and the agents they adopt. Security stops being a queue of work waiting for people, and becomes a coordinated workforce companies direct and trust.

Job Summary

Snyk's Product Security team works consultatively with the engineering teams that build and run our cloud platform: we identify the security requirements, agree together on what needs to change, and the owning teams implement it. As a Senior Product Security Engineer (Platform), you'll pair deep GCP and AWS infrastructure experience with AI coding agents to turn threat models into concrete Terraform, Kubernetes, and pipeline fixes, then work directly with platform teams to get those fixes merged. The goal is simple to state and hard to do well: make the secure option the easy option for the engineers building Snyk's platform.

About the Team

You'll join Snyk's Product Security team, which operates as an advisor rather than an owner: the cloud infrastructure teams retain ownership and operation of their systems, and Product Security's job is to find what needs to change and make that change easy to ship. The team sits close to Snyk's platform and infrastructure organization and is increasingly built around AI agents doing real infrastructure work, not just reviewing someone else's.

What You’ll Do

  • Threat model Snyk's cloud infrastructure across GCP and AWS to identify the security requirements platform teams need to meet, then negotiate the resulting changes directly with the teams that own the systems.

  • Use AI coding agents (for example Claude Code) to draft the Terraform, Kubernetes, and pipeline changes that fix identified security gaps, and raise them for the owning team to review and merge.

  • Run agent-driven fixes at scale across many repositories, scoping every change so the owning platform team can review and merge it with confidence.

  • Write and maintain the guidance AI agents rely on (skills, prompts, instruction files, security baselines) so agent output consistently matches Snyk's standards.

  • Connect agents to live cloud, CSPM, and ticketing data through MCP servers, command-line tools, and provider APIs so their fixes are grounded in the real environment.

  • Review AI-generated infrastructure changes critically: catch invented resources, unsafe defaults, and IAM permissions scoped wider than they need to be.

  • Harden GCP identity and access management, including the resource hierarchy, IAM roles and conditions, service accounts and workload identity federation, and organization policy constraints, plus the AWS IAM equivalent.

  • Improve Kubernetes and container security, primarily on GKE: cluster hardening (private clusters, Autopilot), RBAC, admission control, workload identity, network policy, and secure container image pipelines (Artifact Registry, Binary Authorization).

  • Add automated security testing and CSPM tooling to CI/CD and GitOps pipelines, then help teams triage and fix what those tools surface.

  • Benchmark infrastructure against secure configuration baselines such as the CIS Google Cloud Foundation Benchmark, and against the infrastructure controls in frameworks like ISO 27001 and NIST 800-53.

  • Limit the risks AI agents themselves introduce: prompt injection, over-broad permissions, leaked secrets, and changes made without review.

  • Measure whether agent-driven fixing is actually working across teams, and improve the approach as you learn what does and doesn't land.

What you’ll bring

  • 5-8 years running or securing cloud infrastructure, ideally having built and operated production platforms on GCP or AWS before moving into security.

  • Deep, hands‑on GCP knowledge, including its security services, plus a good working knowledge of AWS; equivalent AWS IAM depth is a bonus.

  • Strong grasp of GCP IAM: resource hierarchy (organization, folders, projects), IAM roles and conditions, service accounts and workload identity federation, organization policy constraints, and least privilege design.

  • Practical Kubernetes and container experience, primarily GKE: cluster hardening (private clusters, Autopilot), RBAC, admission control, workload identity, network policy, and secure container images. EKS experience is also welcome.

  • Comfort with infrastructure as code (for example Terraform) and automated deployment: CI/CD pipelines and GitOps.

  • Solid DevSecOps practice: threat modeling, early shift‑left testing, and continuous monitoring, plus the judgment to turn that into concrete infrastructure changes.

  • Confidence using AI coding agents (for example Claude Code) day to day, including writing the guidance and prompts that keep their output reliable at scale.

  • A critical eye for AI-generated infrastructure output: able to spot invented resources, unsafe defaults, and overly broad IAM permissions before anything ships.

  • Comfort working consultatively: influencing and negotiating changes with teams who own and run the infrastructure, rather than owning it yourself.

  • Nice to have: application security knowledge (for example code review, OWASP Top 10), or experience with Snyk's products or similar security testing tools.

About Snyk

Snyk is committed to creating an inclusive and engaging environment where our employees can thrive as we rally behind our common mission to make the digital world a safer place. From Snyk employee resource groups, to global benefits that help our employees prioritize their health, wellness, financial security, and a work/life blend, we aim to support our employees along their entire journeys here at Snyk.

Equal Employment Opportunity

Snyk is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Product Security Engineer
Senior Product Security Engineer

Snyk • Boston (MA)

On-site
USD 192,000 - 230,000
Flexible working hours
Work-from-home allowance
Vacation and wellness time off
+1
Technical Success Manager
Technical Success Manager

Snyk Ltd. • Boston (MA), Northern (KY)

Hybrid
USD 120,000 - 160,000
Senior Technical Success Manager
Senior Technical Success Manager

Snyk Ltd. • Boston (MA), Northern (KY)

Hybrid
USD 140,000 - 190,000
Solutions Engineer
Solutions Engineer

Snyk • New York (NY), Northern (KY)

On-site
USD 130,000 - 180,000
Flexible working hours
Work-from-home allowance
In-office perks
+3
GSI Director
GSI Director

Snyk Ltd. • Boston (MA), Northern (KY)

Hybrid
USD 190,000 - 230,000
Senior Technical Success Manager
Senior Technical Success Manager

Snyk • Boston (MA), Northern (KY)

On-site
USD 120,000 - 180,000
Flexible working hours
Work-from-home allowances
In-office perks
+6
Senior Technical Support Engineer
Senior Technical Support Engineer

Snyk • Northern (KY)

On-site
USD 90,000 - 130,000
Flexible working hours
Work-from-home allowances
In-office perks
Software Engineer
Software Engineer

SupportFinity™ • Boston (MA)

On-site
USD 130,000 - 160,000
Flexible working hours
Work-from-home allowances
In-office perks
+1
Technical Support Engineer
Technical Support Engineer

Snyk • North Carolina

On-site
USD 70,000 - 90,000
Flexible working hours
Work-from-home allowances
Parental leave
Account Director
Account Director

Snyk Ltd. • Northern (KY)

Hybrid
USD 90,000 - 140,000