Snowflake

Senior Red Team Engineer

Snowflake3 weeks ago
Location

US, Remote

Workplace

Remote

Type

Full Time

Salary

USD 176,000 – 253,000

Level

Senior

Role

Security Engineer

Posted

Jul 1, 2026

Full TimeRemoteSenior

The role

Summary

Lead security assessments and vulnerability research as a Senior Red Team Engineer at Snowflake, where you'll conduct offensive security operations across diverse cloud environments (AWS, GCP, Azure) to identify and remediate critical security risks. This role combines hands-on penetration testing, security tool development, and cross-functional collaboration within Snowflake's Security Foundations organization, requiring 4+ years of offensive security experience and strong programming capabilities to protect both Snowflake's infrastructure and customer data in an AI-native, cloud-native technology company.

What you'll do

Execute Security Assessments: Conduct comprehensive security assessments and penetration testing across Snowflake's corporate and product environments, including cloud infrastructure on AWS, GCP, and Azure. Identify vulnerabilities in software, systems, networks, and cloud configurations using both automated tools and manual testing techniques. Document findings with detailed technical analysis and severity ratings.
Develop Security Tools and Infrastructure: Design, develop, and maintain specialized tools, automation frameworks, and offensive security infrastructure to enhance Red Team capabilities across diverse cloud environments and novel platforms. Build custom exploitation tools, reconnaissance utilities, and assessment automation to improve efficiency and coverage of security engagements.
Plan and Scope Engagements: Define scope, objectives, methodology, and timelines for security assessments in collaboration with stakeholders. Establish meaningful security metrics to measure Red Team impact, track remediation rates, and demonstrate ROI of security testing initiatives across the organization.
Communicate Findings to Stakeholders: Translate technical vulnerabilities into clear narratives for both technical engineering teams and executive leadership. Present security findings, risk assessments, remediation recommendations, and strategic security insights through reports, presentations, and workshops tailored to audience expertise levels.
Build Red Team Capability and Culture: Contribute to expanding the Red Team's scope, impact, and maturity within Snowflake's Security Foundations organization. Mentor team members, establish best practices for offensive security operations, and help develop the strategic direction of the Red Team function to address evolving cloud security threats.
Conduct Security Research: Perform original security research on emerging vulnerabilities, cloud misconfigurations, and attack methodologies. Stay current with the latest offensive security techniques, cloud security threats, and zero-day research to identify novel attack vectors and enhance Red Team testing approaches.

What we look for

Technical

Programming ProficiencyStrong ability to read, write, and debug code in at least one modern programming language such as Golang, Python, Java, JavaScript, C++, or C. Preferred candidates demonstrate strong proficiency in at least one language with the ability to quickly learn additional languages as needed for security research.
Cloud Platform SecurityDeep understanding of cloud security architecture, common misconfigurations, and attack surfaces in AWS, GCP, and Azure. Knowledge of cloud-native security services, container security, serverless security, and infrastructure-as-code vulnerabilities.
Offensive Security Tools and TechniquesProficiency with industry-standard penetration testing and offensive security tools including command-line utilities, network analysis tools, exploitation frameworks, and custom tooling. Ability to develop custom tools using your preferred programming language to augment standard offensive security capabilities.
Systems and Network SecurityStrong foundational knowledge of operating systems (Linux, Windows), network protocols, DNS, authentication mechanisms, and network architecture. Understanding of lateral movement techniques, privilege escalation paths, and persistence mechanisms in enterprise environments.

Education

Information Security FoundationFormal education or equivalent practical experience in computer science, cybersecurity, information security, or related fields. While not strictly required, relevant certifications such as OSCP, CEH, GIAC (GPEN, GCIH), or equivalent demonstrate commitment to offensive security expertise.
Continuous Learning MindsetDemonstrated commitment to ongoing professional development and staying current with emerging security threats, cloud technologies, and offensive security techniques. Active participation in security communities, conferences, or training programs indicates passion for the security discipline.

Experience

Offensive Security ExperienceMinimum 4+ years working in an information security discipline with a demonstrated focus on offensive security, including penetration testing, vulnerability assessment, or red team operations. Preferred candidates possess 6+ years of experience, particularly in high-growth, cloud-native technology companies.
Cloud Security Assessment ExperienceProven track record identifying and exploiting common bugs, misconfigurations, and security gaps in cloud infrastructure and native services across AWS, GCP, and Azure platforms. Hands-on experience with cloud-specific attack vectors, identity and access management vulnerabilities, and infrastructure-as-code security assessment.
Vulnerability Research and ExploitationDemonstrated ability to discover, analyze, and exploit software vulnerabilities through source code analysis, binary analysis, or dynamic testing. Experience developing proof-of-concept exploits and understanding of common vulnerability classes (injection, authentication bypass, privilege escalation, data exfiltration).
Cross-Functional CollaborationProven ability to work effectively with security teams, software engineers, infrastructure teams, and business stakeholders across diverse organizational functions. Experience translating technical security concepts for non-technical audiences and building consensus around security priorities.

Skills

Required skills

Penetration TestingAbility to conduct comprehensive penetration tests including reconnaissance, vulnerability scanning, exploitation, and post-exploitation activities. Experience with manual testing methodologies and understanding of both technical and business aspects of security assessments.
Vulnerability AssessmentProficiency in identifying, analyzing, and documenting software vulnerabilities and security misconfigurations. Ability to assess risk severity, determine business impact, and recommend effective remediation strategies.
Security Tool DevelopmentCapability to develop custom security tools, scripts, and automation frameworks to enhance offensive security operations. Experience with tool design, performance optimization, and integration into Red Team workflows.
Technical CommunicationStrong ability to document findings clearly and concisely for diverse audiences including technical teams, security professionals, and non-technical business executives. Proficiency in creating security reports, executive summaries, and technical briefs.
Cloud Infrastructure SecurityDeep knowledge of AWS, GCP, and Azure cloud environments including common misconfigurations, insecure defaults, and attack surface areas specific to cloud-native architectures and services.
Code AnalysisAbility to read, understand, and identify security issues in source code across multiple programming languages. Experience with code review for security purposes and identifying common coding vulnerabilities.

Nice to have

Security Research and PublicationsContributions to the security community through open-source security tools, published research papers, conference talks, or vulnerability disclosures. Demonstrated thought leadership and influence within the cybersecurity community.
Advanced Programming SkillsStrong proficiency in one or more primary programming languages with ability to architect and implement complex security tools. Experience with performance optimization, system-level programming, or development of sophisticated exploitation frameworks.
Red Team LeadershipPrior experience leading or mentoring Red Team operations in fast-growing, cloud-native technology companies. Ability to develop Red Team strategy, manage security assessment programs, and drive organizational security improvements.
Container and Kubernetes SecuritySpecialized knowledge of containerization security, Kubernetes cluster attack surfaces, and cloud-native application security. Experience with container escape techniques, orchestration platform vulnerabilities, and microservices security assessment.
Infrastructure-as-Code SecurityUnderstanding of IaC platforms (Terraform, CloudFormation, Ansible) and ability to identify security misconfigurations in infrastructure definitions. Experience testing IaC pipelines for security vulnerabilities and misconfiguration risks.

Compensation & benefits

Salary

USD 176,000 – 253,000 (annual)

Stock options

Available

Benefits

Comprehensive Health Insurance

Medical, dental, and vision coverage with employee and dependent options. Snowflake offers multiple plan tiers to accommodate different healthcare needs and preferences.

Retirement Benefits

401(k) retirement plan with company matching to help you build long-term financial security. Employer matching contributions accelerate your retirement savings.

Equity Compensation

Competitive stock option and RSU packages aligned with company performance. Equity vesting schedules provide long-term value creation and ownership stake in Snowflake's growth.

Flexible Time Off

Generous paid time off policy including vacation days, sick leave, and holidays. Snowflake encourages work-life balance and personal well-being through flexible time off arrangements.

Professional Development

Tuition reimbursement, security certification support (OSCP, CEH, GIAC certifications), conference attendance budgets, and access to learning platforms. Investment in continuous skill development aligns with Snowflake's commitment to technical excellence.

Wellness Programs

Access to fitness center discounts, mental health resources, wellness coaching, and employee assistance programs supporting holistic employee well-being.

Parental and Family Leave

Comprehensive parental leave policies and family support benefits to accommodate diverse life situations and promote work-life integration.

Home Office Setup

Equipment stipends and support for creating an optimal remote or hybrid work environment, reflecting Snowflake's flexible work arrangements.


Apply for this position

You'll be redirected to the company's application page


Snowflake

Snowflake

View all jobs

Snowflake is an American cloud computing company offering data warehousing and analytics platforms.

Bozeman, Montana, United StatesFounded 2012snowflake.com

Tech Stack

Languages
GolangPythonJavaJavaScriptC/C++
Frameworks
Metasploit FrameworkBurp SuiteCobalt Strike
Databases
Cloud Data Warehousing Security
Tools
AWS Security ToolsGCP Security ToolsAzure Security ToolsNmap and Network ReconnaissanceWireshark and Network AnalysisKali Linux and Security DistributionsGit and Version Control
Other
Cloud-Native Attack SurfacesOffensive Security MethodologySecurity Assessment Documentation

Interview Guides

11 guides available for Snowflake

Apply Now