Staff Security Engineer, Cloud & AI Platform

Brookfield Asset Management Inc.

Northern (KY)

Hybrid

USD 150,000 - 190,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Brookfield Asset Management is seeking a Staff Security Engineer to secure our Cloud & AI Platform for Real Estate. You will lead threat modelling, security design reviews, and implement controls across AWS, IaC, and AI systems.

In this builder role, you will partner with Cloud Solutions, AI engineering, Identity, and CyberOps to deliver reusable security patterns, safe rollouts, and evidence-driven guardrails across multiple accounts.

Qualifications

  • 8+ years of experience in production security or platform systems.
  • Senior or staff-level ownership and architecture decisions.
  • Deep AWS security experience across IAM, multi-account, logging, KMS, networking.
  • Strong Terraform/OpenTofu, modular design, remote execution, policy controls.
  • Experience securing CI/CD systems such as GitHub Actions, including OIDC federation, runner trust boundaries, secrets, artifacts, and deployment permissions.
  • Ability to read and write production-quality automation or application code in Python, Go, Ruby.
  • Nice to Have: Bedrock, AgentCore, MCP, LLM gateways, AI guardrails, production agentic systems.
  • Container security: ECS/Fargate or EKS, image supply chains, runtime isolation.

Responsibilities

  • Lead security architecture for cloud and AI platforms; set direction and secure-by-default patterns.
  • Define security engineering standards and document key decisions; communicate risk to leadership.
  • Review designs for authorization, data protection, secrets, and tenant isolation.
  • Mentor engineers to make sound security decisions independently.
  • Partner with Cloud Solutions, AI engineering, Identity, CyberOps, and GRC/Privacy to drive adoption.
  • Own AWS multi-account security: account boundaries, SCPs, IAM Identity Center, KMS, VPC controls, WAF.
  • Design least-privilege access across AWS, Okta, GitHub Actions, and IaC platforms.

Skills

8+ years
AWS security
Terraform/OpenTofu
GitHub Actions
App security
Threat modelling
IAM & access
CI/CD security
Python/Go/Ruby

Tools

Terraform/OpenTofu
GitHub Actions
Okta
CloudWatch
KMS
CloudTrail

Job description

Location US TN - Remote Business - Real Estate

Brookfield Culture

Brookfield has a unique and dynamic culture. We seek team members who have a long-term focus and whose values align with our Attributes of a Brookfield Leader: Entrepreneurial, Collaborative and Disciplined. Brookfield is committed to the development of our people through challenging work assignments and exposure to diverse businesses.

Job Description

The Staff Security Engineer, Cloud & AI Platform is a deeply technical, hands‑on role responsible for making Brookfield Real Estate’s cloud and AI platforms secure by design. You will lead security architecture and implementation across AWS, Infrastructure as Code, software delivery, internally developed applications, and AI/agent systems. This is a builder role. You will threat‑model a design, review the underlying Terraform and application code, implement the control, instrument it, and help teams adopt it without unnecessary friction. Security requirements become reusable modules, automated checks, secure defaults, and clear engineering guidance rather than documents and findings lists. You will partner closely with Cloud Solutions, application engineering, AI engineering, Identity, CyberOps, and GRC/Privacy. Platform engineering continues to own general platform uptime, capacity, and deployment mechanics, and CyberOps continues to own alert triage; this role owns the architecture, controls, tooling, and assurance mechanisms that make those systems safe.

Role & Responsibilities
  • Leadership & Security Architecture: Help define security architecture for the cloud and AI platforms: set direction, write specs, and steward secure‑by‑default patterns across teams.
  • Define security engineering standards and paved roads, document important decisions, and communicate risk and trade‑offs to engineering and business leadership.
  • Review infrastructure and application designs for authorization, network, data‑protection, secrets, and tenant‑isolation risks.
  • Mentor engineers and raise the organization’s ability to make sound security decisions independently.
  • Partner with Cloud Solutions, application engineering, AI engineering, Identity, CyberOps, and GRC/Privacy to prioritize work and drive adoption.
  • Cloud & Identity Security: Own and evolve security architecture for a multi‑account AWS organization — account boundaries, service control policies, IAM Identity Center, delegated security services, KMS, VPC controls, and WAF.
  • Design least‑privilege human and workload access across AWS, Okta, GitHub Actions, and Infrastructure as Code platforms using federation and short‑lived credentials.
  • Build and maintain reusable security controls in Terraform or OpenTofu, with safe rollout, testing, monitoring, and recovery patterns.
  • Strengthen centralized logging and evidence — CloudTrail, Config, GuardDuty, Security Hub, Macie, and CloudWatch — and keep guardrails current as the environment grows.
  • Secure Software Delivery: Establish secure GitHub Actions and runner patterns, including OIDC trust, environment separation, workflow protection, action pinning, artifact integrity, and least‑privilege deployment roles.
  • Integrate practical security checks into developer workflows — secrets detection, dependency and container scanning, SBOMs, Infrastructure as Code analysis, code scanning, and risk‑based release gates.
  • Support vulnerability management for internally developed software, from detection and prioritization through remediation evidence and exception handling. Partner with the Vulnerability Manager to establish prioritization and reduce false positives.
  • Improve controls with engineers rather than around them, avoiding noisy or easily bypassed gates.
  • Application & AI Security: Lead threat modelling and security design reviews for web applications, APIs, data ingestion, authentication and authorization flows, and agentic systems.
  • Define secure patterns for Amazon Bedrock and other model platforms, including model access, guardrail lifecycle, invocation logging, usage attribution, and sensitive‑data controls.
  • Harden agent tools, MCP servers, gateways, sandboxes, and code‑execution environments against prompt injection, confused‑deputy attacks, excessive agency, secret disclosure, data exfiltration, and cross‑tenant access.
  • Build repeatable security evaluations and adversarial tests for AI‑enabled features and connect findings to engineering remediation.
  • Detection, Response & Assurance: Translate cloud and application telemetry into actionable detections, runbooks, ownership, and escalation paths in partnership with CyberOps.
  • Lead technical response and root‑cause remediation for cloud, identity, software supply chain, and AI security incidents.
  • Establish severity and ownership standards for cloud findings, software vulnerabilities, and AI security issues, with clear remediation expectations.
  • Produce the control evidence GRC and Privacy need, without turning engineering work into manual reporting.
Your Qualifications
  • 8+ years Experience
  • Demonstrated senior or Staff‑level ownership of production security or platform systems, including architecture decisions others build on
  • Deep AWS security experience across IAM, multi‑account or AWS Organizations environments, logging and detection, KMS, networking, and service‑to‑service authorization
  • Strong Terraform or OpenTofu skills, including modular design, remote execution, policy controls, and safe state‑aware changes
  • Experience securing CI/CD systems such as GitHub Actions, including OIDC federation, runner trust boundaries, secrets, artifacts, and deployment permissions
  • Working knowledge of application security fundamentals: threat modeling, authentication and authorization, secure API design, secrets handling, dependency risk, and vulnerability remediation
  • Ability to read and write production‑quality automation or application code in Python, Go, Ruby, or a comparable language
  • Demonstrated ability to influence teams you do not manage, make pragmatic risk decisions, and turn ambiguous security needs into implemented controls
  • Nice to Have: Experience with Amazon Bedrock, AgentCore, MCP, LLM gateways, AI guardrails, or production agentic systems
  • Container and orchestration security — ECS/Fargate or EKS, image supply chains, runtime isolation, and egress control
  • Identity platform depth: IAM Identity Center, Okta, Delinea, SAML, OIDC, OAuth, SCIM, ABAC, and enterprise entitlement systems
  • Experience with Scalr, Terraform Cloud, or another remote Infrastructure as Code platform
  • Familiarity with CrowdStrike Falcon Cloud Security, Datadog, CloudWatch, or comparable security and observability tooling
  • Data platform and sensitive‑data controls involving S3, Snowflake, PostgreSQL/Aurora, or vendor data ingestion
  • AI threat modeling, red teaming, or security evaluation experience
Your Career @ Brookfield

At Brookfield, your career progression is important to us. As a successful employee, you will have the opportunity to grow within your team, department, and across the Brookfield organization. Our leadership teams are dedicated to the accomplishments of their employees. We also invest time into training and developing our people.

Why Brookfield?

We imagine, create, and operate on a foundation of values to build a better world, together. Brookfield strives to create spaces where going to work never feels routine. As a Brookfield employee, you will enjoy many benefits such as 401K matching, tuition reimbursement, summer Fridays, paid maternity leave and more. There is also a generous employee referral program because we want our existing team members to help us build a more diverse workplace through their networks.

Our compensation structure is comprised of a base salary and a short‑term incentive program (cash bonus). Cash compensation tends to vary based on geography to account for local market conditions and is set to be market competitive. Compensation decisions are based on a number of factors including relative experience, overall years of experience, industry experience, education and designations.

Brookfield is committed to maintaining a Positive Work Environment that is safe and respectful; our shared success depends on it. We do not tolerate workplace discrimination, violence or harassment. We are proud to be an Equal Opportunity Employer and make employment decisions based on qualifications, merit and business needs, without regard to any characteristic protected by applicable law.

Applicant information is collected and handled in accordance with our Applicant Privacy Notice.

Brookfield Asset Management

Brookfield Asset Management is a leading global alternative asset manager with over US$1 trillion of assets under management across real estate, infrastructure, renewable power and transition, private equity and credit. Brookfield owns and operates long‑life assets and businesses, many of which form the backbone of the global economy. Utilizing its global reach, access to large‑scale capital and operational expertise, Brookfield offers a range of alternative investment products to investors around the world—including public and private pension plans, endowments and foundations, sovereign wealth funds, financial institutions, insurance companies and private wealth investors.

Brookfield Asset Management Ltd. (BAM) is a public company listed on the New York (NYSE: BAM) and Toronto (TSX: BAM) stock exchanges. Brookfield Corporation is a public company listed on the New York (NYSE: BN) and Toronto (TSX: BN) stock exchanges.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer, Cloud & AI Platform
Staff Security Engineer, Cloud & AI Platform

Brookfield Properties (USA II) LLC • Tennessee

Hybrid
USD 140,000 - 190,000
401K matching
Tuition reimbursement
Summer Fridays
Technology Services, Project Manager
Technology Services, Project Manager

Brookfield Corp. • New York (NY)

On-site
USD 120,000 - 130,000
Technology Services, Project Manager
Technology Services, Project Manager

Brookfield Asset Management LLC • New York (NY)

On-site
USD 120,000 - 130,000
Staff Security Engineer, Cloud & AI Platform
Staff Security Engineer, Cloud & AI Platform

Brookfield Properties • Northern (KY)

Hybrid
USD 180,000 - 230,000
401K matching
tuition reimbursement
summer Fridays
+2
Associate / Senior Associate, ABF Investments
Associate / Senior Associate, ABF Investments

BNRE US Services LLC • New York (NY)

On-site
USD 150,000 - 220,000
Internal Audit Manager
Internal Audit Manager

Brookfield Asset Management ULC • New York (NY)

On-site
USD 120,000 - 140,000
Legal Analyst
Legal Analyst

Brookfield Asset Management LLC • New York (NY)

On-site
USD 90,000 - 130,000
Associate, Housing
Associate, Housing

Brookfield Properties (USA) LLC • New York (NY)

On-site
USD 130,000 - 150,000
Associate, Investments
Associate, Investments

Brookfield Asset Management LLC • New York (NY)

On-site
USD 175,000 - 200,000
Administrative Assistant
Administrative Assistant

Brookfield Corp. • New York (NY)

On-site
USD 85,000 - 100,000