Get more replies from employers
Send a job-specific resume in minutes.
Brookfield Properties is seeking a Staff Security Engineer for Cloud & AI Platform. You will shape security architecture across AWS, IaC, and AI systems, building reusable controls and secure-by-default patterns that scale with the business.
You will partner with Cloud Solutions, application and AI engineering, Identity, CyberOps and GRC/Privacy to implement practical security that minimizes friction and accelerates delivery while protecting data and workloads.
The Staff Security Engineer, Cloud & AI Platform is a deeply technical, hands‑on role responsible for making Brookfield Real Estate’s cloud and AI platforms secure by design. You will lead security architecture and implementation across AWS, Infrastructure as Code, software delivery, internally developed applications, and AI/agent systems. This is a builder role. You will threat‑model a design, review the underlying Terraform and application code, implement the control, instrument it, and help teams adopt it without unnecessary friction. Security requirements become reusable modules, automated checks, secure defaults, and clear engineering guidance rather than documents and findings lists. You will partner closely with Cloud Solutions, application engineering, AI engineering, Identity, CyberOps, and GRC/Privacy. Platform engineering continues to own general platform uptime, capacity, and deployment mechanics, and CyberOps continues to own alert triage; this role owns the architecture, controls, tooling, and assurance mechanisms that make those systems safe.
Help define security architecture for the cloud and AI platforms: set direction, write specs, and steward secure‑by‑default patterns across teams Define security engineering standards and paved roads, document important decisions, and communicate risk and trade‑offs to engineering and business leadership Review infrastructure and application designs for authorization, network, data‑protection, secrets, and tenant‑isolation risks Mentor engineers and raise the organization’s ability to make sound security decisions independently Partner with Cloud Solutions, application engineering, AI engineering, Identity, CyberOps, and GRC/Privacy to prioritize work and drive adoption
Own and evolve security architecture for a multi‑account AWS organization — account boundaries, service control policies, IAM Identity Center, delegated security services, KMS, VPC controls, and WAF Design least‑privilege human and workload access across AWS, Okta, GitHub Actions, and Infrastructure as Code platforms using federation and short‑lived credentials Build and maintain reusable security controls in Terraform or OpenTofu, with safe rollout, testing, monitoring, and recovery patterns Strengthen centralized logging and evidence — CloudTrail, Config, GuardDuty, Security Hub, Macie, and CloudWatch — and keep guardrails current as the environment grows
Establish secure GitHub Actions and runner patterns, including OIDC trust, environment separation, workflow protection, action pinning, artifact integrity, and least‑privilege deployment roles Integrate practical security checks into developer workflows — secrets detection, dependency and container scanning, SBOMs, Infrastructure as Code analysis, code scanning, and risk‑based release gates Support vulnerability management for internally developed software, from detection and prioritization through remediation evidence and exception handling. Partner with the Vulnerability Manager to establish prioritization and reduce false positives Improve controls with engineers rather than around them, avoiding noisy or easily bypassed gates
Lead threat modeling and security design reviews for web applications, APIs, data ingestion, authentication and authorization flows, and agentic systems Define secure patterns for Amazon Bedrock and other model platforms, including model access, guardrail lifecycle, invocation logging, usage attribution, and sensitive‑data controls Harden agent tools, MCP servers, gateways, sandboxes, and code‑execution environments against prompt injection, confused‑deputy attacks, excessive agency, secret disclosure, data exfiltration, and cross‑tenant access Build repeatable security evaluations and adversarial tests for AI‑enabled features and connect findings to engineering remediation
Translate cloud and application telemetry into actionable detections, runbooks, ownership, and escalation paths in partnership with CyberOps Lead technical response and root‑cause remediation for cloud, identity, software supply chain, and AI security incidents Establish severity and ownership standards for cloud findings, software vulnerabilities, and AI security issues, with clear remediation expectations Produce the control evidence GRC and Privacy need, without turning engineering work into manual reporting
At Brookfield, your career progression is important to us. As a successful employee, you will have the opportunity to grow within your team, department, and across the Brookfield organization. Our leadership teams are dedicated to the accomplishments of their employees. We also invest time into training and developing our people.
We imagine, create, and operate on a foundation of values to build a better world, together. Brookfield strives to create spaces where going to work never feels routine. As a Brookfield employee, you will enjoy many benefits such as 401K matching, tuition reimbursement, summer Fridays, paid maternity leave and more. There is also a generous employee referral program because we want our existing team members to help us build a more diverse workplace through their networks. We are proud to create a diverse environment and are proud to be an equal opportunity employer.
We are grateful for your interest in this position, however, only candidates selected for pre‑screening will be contacted.
The Brookfield Real Estate ecosystem spans the globe through multiple operating companies, all united by our core values. We cover every facet of real estate—from offices and retail spaces to logistics centers, residential homes, and hotels. Across thousands of properties worldwide, we combine world‑class expertise with deep local insights to drive exceptional value. Together, we transform neighborhoods and build lasting communities that stand the test of time. By leveraging the global scale of our operating companies and fostering trusted local partnerships, we collaborate seamlessly to support our communities and achieve shared success.