Staff Security Engineer - Enterprise Security
Security Engineer · Staff · Full Time · Remote
Opens Snowflake's application page
Role
What you'll do.
Staff Security Engineer role at Snowflake's Enterprise Security team responsible for designing, deploying, and scaling endpoint security solutions including EDR, DLP, MDM, and AI security tools across complex multi-cloud environments. The position requires 5+ years of hands-on information security experience with strong software engineering proficiency in Python, Go, Java, or C++ and expertise in modern threat detection, incident response, and zero-trust architecture. This is a high-impact opportunity to architect foundational security primitives at enterprise scale while mentoring engineering teams and driving secure development practices across a rapidly growing organization.
Responsibilities
- Endpoint Security Architecture & Scaling: Develop, maintain, and scale enterprise endpoint security solutions across the organization's infrastructure. Lead technical ownership of the endpoint security tooling roadmap, including EDR (Endpoint Detection and Response), DLP (Data Loss Prevention), MDM (Mobile Device Management), secure browser solutions, and AI-powered security tools. Design and implement these solutions across heterogeneous Windows, macOS, and Linux environments while accommodating Snowflake's rapid growth trajectory and evolving threat landscape.
- AI-Powered Security Automation & Platform Engineering: Build intelligent security platforms and automation frameworks using AI and sophisticated software engineering practices. Engineer solutions that reduce operational toil, increase detection fidelity, and accelerate incident response times. Develop robust APIs, automation workflows, and detection pipelines leveraging machine learning to stay ahead of adversarial tactics. Contribute architectural decisions for integrating AI-assisted security workflows into the broader security operations infrastructure.
- Threat Detection & Incident Response: Design and implement real-time detection and prevention systems to identify endpoint compromise, lateral movement, and data exfiltration attempts. Build comprehensive threat intelligence pipelines that aggregate security signals across the enterprise. Monitor security events, investigate incidents, and develop proactive hunting strategies. Establish detection tuning processes to maximize signal-to-noise ratios while maintaining operational efficiency.
- Zero-Trust & Risk Assessment: Conduct continuous risk and threat analyses to proactively identify and remediate endpoint security vulnerabilities across the enterprise fleet. Apply zero-trust security principles and implement continuous verification mechanisms to reduce attack surface exposure. Develop vulnerability management programs, assess endpoint configurations against security standards, and establish remediation prioritization frameworks.
- Security Policy & Compliance Framework Development: Develop and implement unified security policies, procedures, and technical standards for endpoint protection across Snowflake's multi-cloud infrastructure. Ensure alignment with regulatory requirements, compliance frameworks (SOC 2, ISO 27001, FedRAMP), and industry best practices. Document security baselines and maintain audit trails for compliance validation.
- Cross-Functional Security Partnership & Leadership: Partner strategically with Security, Engineering, IT, and Product teams to define enterprise security strategy and drive secure engineering practices throughout the organization. Provide technical guidance and mentorship to staff and end-users. Champion security culture through enablement programs, technical training, and security awareness initiatives. Establish thought leadership around security engineering excellence and emerging threats.
- Security Engineering Excellence & Mentorship: Establish and maintain highest standards for security engineering practices including threat modeling, secure design review, detection quality assurance, and incident response procedures. Mentor junior and mid-level security engineers on advanced techniques, adversarial perspectives, and security tradecrafts. Introduce cutting-edge security methodologies and drive continuous improvement of team capabilities.
Qualifications
What we look for.
Technical
EDR & DLP Platform Expertise
Hands-on experience with enterprise endpoint detection and response (EDR) platforms and data loss prevention (DLP) solutions. Familiarity with leading platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Palo Alto Networks Cortex XDR, or similar enterprise security tools.
Cloud Security & Multi-Cloud Infrastructure
Experience with cloud security architecture across major providers (AWS, Google Cloud Platform, Azure). Understanding of cloud-native security controls, identity and access management (IAM), network security groups, and security service integrations in multi-cloud environments.
Security Automation & Detection Engineering
Experience developing security automation frameworks, detection rules, and response playbooks. Familiarity with SIEM platforms, log aggregation systems, query languages (SPL, KQL, or similar), and building data pipelines for security analytics.
Vulnerability Assessment & Remediation
Experience conducting vulnerability assessments, using vulnerability scanning tools, and developing remediation workflows. Knowledge of patch management, asset inventory systems, and continuous compliance monitoring frameworks.
Education
Bachelor's Degree in Technical Field
Bachelor's degree in Computer Science, Information Security, Cybersecurity, Computer Engineering, or a related technical discipline. Equivalent practical industry experience in security engineering roles may substitute for formal degree requirements.
Experience
Hands-On Information Security Background
5+ years of direct experience in information security disciplines including security engineering, threat intelligence and detection engineering, incident response investigations, or security operations. Demonstrated progression from individual contributor roles to leading complex security initiatives at enterprise scale.
Endpoint Security Expertise
Hands-on experience designing, deploying, maintaining, and optimizing endpoint security tools such as EDR platforms, DLP solutions, MDM systems, and secure browser technologies. Proven track record managing these tools across heterogeneous operating systems (Windows, macOS, Linux) in complex enterprise environments.
Software Development & AI Engineering
Proficiency in software development using at least one of: Python, Go, Java, C, or C++. Strong experience leveraging AI-assisted development tools and integrating machine learning approaches into security solutions. Comfortable with version control, testing frameworks, and CI/CD pipelines.
Technical Project Leadership
Demonstrated ability to lead technical projects independently from conception through delivery. Experience driving data-informed architectural decisions, managing stakeholder expectations, and executing end-to-end security engineering initiatives. Comfortable working in ambiguous environments and establishing technical direction.
Foundational Technology Knowledge
Strong understanding of operating system internals, network protocols and architecture, application security platforms, endpoint security concepts, and industry best practices. Knowledge of attack vectors, adversarial TTPs (Tactics, Techniques, and Procedures), and defensive security controls.
Skills
Required
Python Programming
Proficiency writing production-quality Python code for security automation, tool integration, and data analysis. Experience with libraries like pandas, requests, and security-focused frameworks.
Endpoint Security Operations
Expert-level understanding of endpoint security deployment, configuration, monitoring, and tuning across Windows, macOS, and Linux systems. Ability to optimize security tool performance and detection accuracy.
Incident Investigation & Forensics
Experience investigating security incidents on endpoints, analyzing suspicious activities, conducting root cause analysis, and developing preventive controls. Familiarity with forensic methodologies and evidence preservation.
Security Architecture & Design
Ability to design scalable, resilient security architectures considering performance, reliability, and usability tradeoffs. Experience conducting threat modeling and implementing defense-in-depth security strategies.
Zero-Trust Security Principles
Understanding and practical application of zero-trust security models, continuous verification mechanisms, least-privilege access control, and microsegmentation strategies for modern enterprises.
Threat Intelligence & Analysis
Capability to research emerging threats, analyze adversarial behaviors, and translate threat intelligence into detection rules and preventive controls. Familiarity with threat modeling frameworks like MITRE ATT&CK.
Preferred
Go or C++ Development
Nice to haveExperience developing systems-level software in Go or C++ for performance-critical security applications. Knowledge of low-level system programming and kernel-mode security implementations.
Enterprise SaaS Platform Security
Nice to haveExperience securing complex multi-SaaS enterprise environments including identity providers (Okta, Entra ID), collaboration tools (Slack, Microsoft Teams), and enterprise applications. Knowledge of API security and SaaS-specific threat models.
Machine Learning in Security
Nice to haveFamiliarity with machine learning approaches applied to security (behavioral analytics, anomaly detection, threat classification). Experience with ML frameworks and building data pipelines for security use cases.
Industry Security Certifications
Nice to haveProfessional security certifications such as CISSP (Certified Information Systems Security Professional), CEH (Certified Ethical Hacker), Security+, GIAC GUEN, or OSCP demonstrating deep security expertise.
Executive Communication Skills
Nice to haveProven ability to translate complex security concepts, technical risks, and remediation strategies for executive and non-technical stakeholders. Experience presenting security roadmaps and business cases to leadership.
Master's Degree in Security or Computer Science
Nice to haveAdvanced degree in Information Security, Computer Science, Cybersecurity, or related field demonstrating depth of theoretical and practical security knowledge.
Tech stack
Languages
Frameworks
Databases
Tools
Other
Compensation
Pay and benefits.
Base·USD 211,000 – 303,600
Full posting
Original listing.
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done.
We are hiring a Staff Security Engineer for our Enterprise Security team. The threats facing modern organizations are evolving at an unprecedented pace — driven by AI, cloud complexity, and an ever-expanding attack surface. Our Enterprise Security team is responsible for protecting Snowflake, our employees, and our customers by designing, implementing, and maintaining robust endpoint security solutions at enterprise scale, defending not just endpoints and identities, but the AI-assisted workflows and intelligent systems that define how the modern enterprise operates.
AS A STAFF SECURITY ENGINEER AT SNOWFLAKE, YOU WILL:
Develop, maintain, and scale Snowflake's endpoint security solutions while actively contributing to architecture and strategy. This includes EDR, DLP, secure browser, MDM, and AI security solutions across a complex multi-cloud, multi-SaaS enterprise environment. Own the technical roadmap for endpoint security tooling as Snowflake rapidly grows.
Build intelligent security platforms and automate security operations using AI and robust software engineering. Identify opportunities to reduce toil, increase detection fidelity, and accelerate response through thoughtful, scalable automation.
Monitor security events, investigate incidents, and build real-time detection and prevention systems to protect against endpoint compromise and data exfiltration. Develop threat intelligence pipelines that keep us ahead of the adversary.
Conduct regular risk and threat analyses to proactively identify and remediate vulnerabilities end-to-end. Apply zero-trust principles to continuously reduce the attack surface across the endpoint fleet.
Develop and implement unified security policies, procedures, and standards for endpoint protection. Ensure alignment with relevant regulatory and compliance frameworks.
Partner across Security, Engineering, IT, and Product to define endpoint security strategy, drive secure engineering practices, and provide technical guidance to staff and end-users. Champion security culture through enablement and education.
Establish and uphold the highest standards for security engineering — from threat modeling and secure design to detection quality and incident response rigor. Mentor engineers, introduce new techniques and adversarial perspectives, and continuously advance the team's craft.
OUR IDEAL STAFF SECURITY ENGINEER WILL HAVE:
5+ years of hands-on experience in information security — including security engineering, threat intelligence or detection, or incident response — with a strong focus on endpoint security.
Proficiency in software development using Python, Go, Java, C, C++, or JavaScript, alongside strong experience with AI-assisted development.
Hands-on experience designing, deploying, and maintaining endpoint security tools (e.g., EDR, DLP, MDM, secure browsers, AI security solutions) across Windows, macOS, and Linux environments.
Strong understanding of operating systems, network protocols, application platforms, endpoint security concepts, and best practices.
Experience leading technical projects independently, driving data-informed decisions, and executing end-to-end.
A bachelor's degree in Computer Science, Information Security, or a related technical field, or equivalent practical experience.
BONUS POINTS FOR THE FOLLOWING:
Master's degree in Information Security, Computer Science, or a related technical field.
Experience with infrastructure from major cloud providers (AWS, GCP, Azure) and enterprise SaaS platforms at scale.
Relevant industry certifications such as CISSP, CEH, or Security+.
Demonstrated ability to communicate complex security concepts to both technical and non-technical audiences, including executive stakeholders.
WHY JOIN OUR ENTERPRISE SECURITY TEAM AT SNOWFLAKE?
Snowflake is one of the fastest-growing enterprise software companies in history, and the Security Foundations team sits at the center of it — protecting not just the company, but the customers and data that power the modern data economy. You'll have the opportunity to shape the direction of our security roadmap and build foundational security primitives while working closely with Engineering, IT, and Product teams across a globally distributed, multi-cloud, multi-SaaS environment. This is a rare opportunity to build security programs from the ground up, at a scale and speed few companies match, with teammates who are among the best in the industry. If you're energized by hard problems, believe security is a product discipline as much as a defensive one, and want your work to matter at global scale — Snowflake is where you build what's next.
The application window is expected to be open until September 5, 2026. This opportunity will remain posted based on business needs, which may be before or after the specified date.
Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth. We are looking for people who share our values, challenge ordinary thinking, and push the pace of innovation while building a future for themselves and Snowflake.
How do you want to make your impact?
For jobs located in the United States, please visit the job posting on the Snowflake Careers Site for salary and benefits information: careers.snowflake.com
Redirects to Snowflake's application page.
Other roles
More at Snowflake.
Software Engineer AI Team
Mid
Staff/Principal AI Software Engineer - Snowflake CoWork
Principal
Sr Manager, Applied Field Engineering - AI/ML
Manager
Principal Data Platform Architect
Principal
Senior Software Engineer - NatSec
Senior