About the company
Braze is a modern, cloud-first SaaS company running entirely on cloud-native infrastructure — large-scale, distributed systems spanning AWS, GCP, and self-managed Kubernetes, backed by self-managed data stores such as MongoDB.
Responsibilities
- Set the technical direction (leadership & standards): Define the cloud security standards, guardrails, and reference architectures that Infrastructure, SRE, and Product Engineering build on — turning point-in-time fixes into durable, org-wide patterns.
- Set your own objectives and roadmap for high-impact cloud security work, in partnership with Security Engineering leadership, and drive it to measurable outcomes.
- Lead cross-functional security initiatives end to end — scope, timeline, stakeholders, and delivery — guiding technical debates to a decision and owning the result.
- Mentor and uplevel other security and platform engineers through pairing, design review, and feedback; act as a force multiplier and the go-to technical resource for cloud security.
- Represent cloud security in architecture and design forums, translating complex attack paths and risk into clear, actionable guidance engineers will actually adopt.
- Own threat modeling as a discipline for new cloud technologies, services, and patterns adopted across Engineering — making it a repeatable, scalable practice rather than a one-off exercise.
- Partner with Infrastructure, SRE, and Product Engineering to design secure-by-default cloud architectures and build practical, scalable controls across AWS, GCP, and self-managed systems.
- Drive control-plane and IAM security strategy across AWS and GCP, including relationships with external identity providers, RBAC models, and least privilege at scale.
- Continually assess posture, surface systemic and emerging risk, and set the priorities that reduce it.
- Advance our detection strategy: design high-signal detections and SIEM rules (with our SIEM Management function) and own detection coverage for cloud threats end to end.
- Serve as a senior incident responder and cloud-forensics lead for cloud and run-time security investigations across AWS and GCP — and codify what you learn into standard IR playbooks and preventative controls.
- Own and optimize security tooling such as CrowdStrike (EDR/CSPM/IR), Tenable, and native cloud security services, and lead our vulnerability management workflow — scanning, triage, prioritization, and remediation — for cloud assets.
- Own the security of our self-managed Kubernetes environments — control plane, nodes, workload isolation, admission control, run-time security, and the CI/CD supply chain feeding them.
- Set the standards for Infrastructure-as-Code and pipeline security (Terraform preferred): design and harden IaC and CI/CD automation so security is built into how we ship.
- Establish best practices for patch management, base-image hardening, and version management across containerized and VM-based environments.
- Lead the security of large-scale, distributed systems and self-managed data stores (e.g., MongoDB), accounting for their real-world operational and security implications.
Requirements
- You are a senior individual contributor who leads through technical depth and influence rather than authority.
- You can take an ambiguous, open-ended cloud security problem, define the objective yourself, and deliver a solution that becomes the way Braze does it going forward.
- You translate complex cloud attack paths, IAM misconfigurations, and multi-step threat scenarios into guidance engineers adopt, and you balance strong controls with operational reality.
- You raise the people around you — through mentorship, review, and the standards you set — and you stay current with the cloud security landscape.