Snowflake delivers the AI Data Cloud to help organizations share data, build apps and power their business with AI.
Security Engineer – Threat Detection
Location
United States
Posted
28 days ago
Salary
$122K - $174.8K / year
Seniority
Senior
Job Description
Security Engineer – Threat Detection
Snowflake
• Develop and deploy detections using modern engineering practices (testing/validation, CI/CD pipelines, detections as code, detection development lifecycle, etc.), including both rules-based and AI-assisted detections • Mature our threat detection program by analyzing gaps and mitigating risks via detective controls, including experimentation with AI/ML approaches where they improve signal-to-noise ratio or analyst efficiency • Build and maintain strong partnerships with our stakeholders to provide detection as a service, including self-service patterns, reusable components, and AI-enhanced detections that support their domains • Continuously measure and improve detection quality (coverage, precision/recall, false positive rate, latency)
Job Requirements
- Security Engineering Experience (Threat Detection, Incident Response, Threat Hunting, Product Security, Corporate Security, or other related disciplines)
- Solid experience writing code (Python, Go, etc.), with a desire to apply these skills to AI/ML-powered use cases in detection and response
- Experience collaborating with various security teams and stakeholders
- Ability to review and analyze logging and observability requirements that support detection and response
- A risk-based approach to security to help prioritize key security initiatives and determine when AI provides meaningful value over traditional rules and heuristics
- Knowledge of the current security landscape with domain knowledge in several of: cloud security, identity and access, SaaS security, endpoint security, data security, and insider risk
- An automation-first mindset for scaling security, including comfort with CI/CD, infrastructure as code, and “detections as code.”
- A humble, team-oriented engineer who prioritizes team success in a zero-ego environment
- Experience with development in a high-level programming language (Go, Python, etc.)
- Experience handling data programmatically (SQL, Python, etc.)
- Experience writing production code including unit tests, version control, and CI/CD integration
- Experience with at least one major cloud provider (AWS, Azure, GCP) and understanding of its native logging, monitoring, and security services
- Familiarity with the risks that impact SaaS products and workstations
Benefits
- We are laser focused on doing security in the agentic era, and we do not tolerate the status quo
- We have strong demand from our customers and strong support from the business for security, giving us both mandate and runway to invest in next-generation, AI-driven detection and response capabilities
- We are a great team with a diverse set of backgrounds and skills and we are excited to add engineers who want to push the frontier of AI in security
- You want to be part of a team solving Security Threat Detection at a global scale, leveraging Snowflake’s own data platform and AI capabilities to build detections and workflows that meaningfully raise the bar for defenders
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Build and mature a detection and response program • Detect and respond to security incidents and participate in an incident on-call rotation • Develop innovative ways to detect security incidents. • Design and build the security for the future of our infrastructure. • Partner with the infrastructure team, engineering team, compliance team and within security teams to maintain and further improve our cloud security posture. • Create solutions and processes to identify, resolve and mitigate security vulnerabilities and risks. • Research threats and attack vectors that impact WW applications and infrastructure. • Devise and bolster defense-in-depth through secure-by-default frameworks, architectures and processes. • Mentor and share security standards and processes with all parts of the organization.
• As a Security Engineer at Offchain Labs, you will play a key role in defining and improving our cloud security posture and collaborate across teams to ensure that our operations are secure, compliant, and aligned with regulatory and industry best practices - such as SOC2. • Leverage your extensive experience in Cloud Security to design, implement, and improve secure cloud-native architectures and CI/CD pipelines. • Apply deep expertise in cloud infrastructure security to proactively identify risks, enforce best practices, and harden systems across the entire technology stack. • Automate security controls and educate developers for future-proofing against vulnerabilities. • Play an active part in designing and evolving the company’s overall information security governance and compliance program through: policies, standards, procedures, awareness. • Work closely with engineering, infrastructure, and product teams to make sure controls fit both business objectives and technical realities.
• Assess the current cloud and infrastructure security posture across AWS environments, Kubernetes platforms, and supporting services • Identify critical gaps and define a prioritized roadmap for improving security maturity across identity, runtime, network, and platform layers • Define and implement enterprise security controls across IAM governance, workload/runtime posture, and DNS security • Embed security guardrails, standards, and policies into the Platform Engineering and Cloud Center of Excellence (CoE) frameworks from the beginning of the transformation • Partner with platform teams to design secure-by-default self-service infrastructure patterns, templates, and workflows • Establish identity and access governance models including account strategy, role design, least-privilege policies, and federated access • Design and implement security standards for Kubernetes and containerized workloads, including supply chain security, workload isolation, and runtime protection • Define DNS and network security practices, including private networking, segmentation, service discovery, and threat protection • Collaborate with DevSecOps teams to integrate automated security testing, policy enforcement, and compliance checks into CI/CD pipelines • Support the creation of security observability, monitoring, incident response, and threat detection capabilities across the platform • Provide security leadership and mentoring to engineering teams to promote security ownership and best practices • Support organizational change management and stakeholder alignment to ensure security adoption across teams • Continuously evolve the security framework as the platform and operating model mature
• Assess the current cloud and infrastructure security posture across AWS environments, Kubernetes platforms, and supporting services • Identify critical gaps and define a prioritized roadmap for improving security maturity across identity, runtime, network, and platform layers • Define and implement enterprise security controls across IAM governance, workload/runtime posture, and DNS security • Embed security guardrails, standards, and policies into the Platform Engineering and Cloud Center of Excellence (CoE) frameworks from the beginning of the transformation • Partner with platform teams to design secure-by-default self-service infrastructure patterns, templates, and workflows • Establish identity and access governance models including account strategy, role design, least-privilege policies, and federated access • Design and implement security standards for Kubernetes and containerized workloads, including supply chain security, workload isolation, and runtime protection • Define DNS and network security practices, including private networking, segmentation, service discovery, and threat protection • Collaborate with DevSecOps teams to integrate automated security testing, policy enforcement, and compliance checks into CI/CD pipelines • Support the creation of security observability, monitoring, incident response, and threat detection capabilities across the platform • Provide security leadership and mentoring to engineering teams to promote security ownership and best practices • Support organizational change management and stakeholder alignment to ensure security adoption across teams • Continuously evolve the security framework as the platform and operating model mature



