Senior Staff Security Engineer

bloomreach

United States

Remote

USD 150,000 - 210,000

Full time

9 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Equity grants
Performance bonus eligibility
Education budget
Parental leave
Disconnect days
Employee assistance program
Wellness program
Volunteer days

Job summary

Bloomreach seeks a senior staff-level security engineer to safeguard cloud infrastructure and operationalize security across an AI-driven personalization platform. You will own AWS/GCP architectures, lead detection engineering, vulnerability management, and incident response, shaping secure practices for AI-enabled tooling and product capabilities.

You will design controls, automate guardrails, and mentor engineers while collaborating with cross-functional teams to maintain strong security

Qualifications

  • 6+ years of security engineering experience.
  • Hands-on cloud security, network security, CVE lifecycle, and threat modeling.
  • Experience designing secure AWS and GCP architectures and validating IaC.
  • Scripting skills in Python, Go or Bash.
  • Operational experience with firewalls, WAFs, cloud network controls, and endpoint protections.

Responsibilities

  • Design, implement, and monitor cloud security controls across AWS and GCP environments.
  • Deploy, configure, tune, and maintain SIEM platforms; write detection rules and playbooks.
  • Identify, triage, and remediate infrastructure and web vulnerabilities; manage CVE lifecycle including patching.
  • Lead incident triage, coordinate researcher engagement, and drive vulnerability disclosures.
  • Build automation and guardrails with policy-as-code in CI/CD pipelines.
  • Define security standards, runbooks, and playbooks; mentor junior engineers.

Skills

Cloud security
Network security
Threat modeling
CVE lifecycle
IaC security
Python
Go
Bash
WAFs
Incident response
AWS security
GCP security
Communication

Job description

Role overview

A senior staff-level security engineering role centered on protecting cloud infrastructure and operationalizing security across an AI-driven personalization platform. The position owns current and target-state security architectures for AWS and GCP environments, leads detection engineering, vulnerability management, and incident response, and shapes secure practices for AI-enabled tooling and emerging product capabilities.



Responsibilities


  • Design, implement, and continuously monitor cloud security controls across AWS and GCP environments

  • Deploy, configure, tune, and maintain SIEM platforms; author detection rules, playbooks, and alerting workflows

  • Identify, triage, and remediate infrastructure and web vulnerabilities; manage full CVE lifecycle including patching and root-cause analysis

  • Lead incident triage, coordinate external researcher engagement, and drive vulnerability disclosure programs

  • Build automation, tooling, and infrastructure-as-code guardrails with policy-as-code enforcement in CI/CD pipelines

  • Define organization-wide security standards, runbooks, and playbooks; mentor junior engineers



Requirements


  • 6+ years of relevant security engineering experience

  • Strong proficiency in cloud security, network security, URL filtering, common security frameworks, and CVE lifecycle management

  • Hands-on experience designing secure AWS and GCP architectures, performing threat modeling, and validating secure IaC

  • Practical scripting and automation skills in Python, Go, or Bash

  • Demonstrable operational experience with firewalls, WAFs, cloud network controls, and endpoint protections

  • Strong cross-functional communication with engineering, leadership, external researchers, and customers



Nice to have


  • Experience applying threat modeling and adversary-focused testing to drive resilient designs

  • Familiarity with AI/ML security risks, including prompt injection, model data access, and secure AI adoption



Benefits and work setup


  • Remote work supported

  • Equity grants (RSUs or stock options) based on role, seniority, and location

  • Company-wide performance bonus eligibility

  • $1,500 annual professional education budget for books, courses, or certifications

  • Up to 26 calendar weeks of paid parental leave for primary caregivers

  • Quarterly company-wide \"disconnect\" days off

  • Employee assistance program and wellness app subscription

  • Sports, yoga, and meditation opportunities

  • Five paid volunteer days per year

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Director, Security Engineering
Senior Director, Security Engineering

iterable • United States

Remote
USD 220,000 - 300,000
Equity
401(k) plan
Medical insurance
+8
Senior Security Engineer – Hybrid (4649)
Senior Security Engineer – Hybrid (4649)

Hireclout • Los Angeles (CA)

On-site
USD 180,000 - 200,000
Competitive compensation package
Equity participation
100% covered medical, dental, and vision coverage
+5
Cloud Engineer
Cloud Engineer

Tata Consultancy Services • New London (NH)

On-site
USD 150,000 - 180,000
Annual incentive
Medical coverage
Parental leave
+6
Senior Security Engineer
Senior Security Engineer

Wintermeyer Ventures • San Francisco (CA)

On-site
USD 200,000 - 330,000
Equity
Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2
Infrastructure Security Engineer
Infrastructure Security Engineer

Pantera Capital • Palo Alto (CA)

On-site
USD 200,000 - 340,000
Equity
Comprehensive medical coverage
401(k) retirement plan
+2
Senior Security Engineer
Senior Security Engineer

muonspace • United States

Hybrid
USD 193,000 - 218,000
Competitive equity grant
Comprehensive benefits
Hybrid/remote work options
+3
Senior Software Development Engineer, AWS Security
Senior Software Development Engineer, AWS Security

Amazon • Seattle (WA)

On-site
USD 168,000 - 227,000
Health insurance
401(k) matching
Paid time off
+1
Senior Staff Engineer - DevSecOps
Senior Staff Engineer - DevSecOps

Exelixis Inc • Alameda (CA)

On-site
USD 154,500 - 220,500
401(k) plan with company contributions
Group medical, dental, and vision coverage
Flexible spending accounts
+1
Senior Manager, Security & IT Ops
Senior Manager, Security & IT Ops

Hazelcast • Northern (KY)

Hybrid
USD 120,000 - 160,000
Unlimited PTO
Medical/Dental/Vision Insurance
HSA/FSA
+3