Staff Software Engineer, Product Security

Security Engineer · Staff · Full Time

US-CA-Menlo ParkUSD 236k – 339k1w ago
Apply for this role

Opens Snowflake's application page

Role

What you'll do.

Staff Software Engineer, Product Security at Snowflake leads the technical direction for product security across multiple engineering teams, designing security-critical services and frameworks that embed secure-by-design principles into the development lifecycle. This role owns complex security architecture decisions, threat modeling, and remediation of high-severity vulnerabilities at scale for a leading cloud data platform. You will mentor engineering teams, evaluate emerging security tooling including AI-assisted analysis, and drive foundational security systems that strengthen customer trust in Snowflake's multi-tenant SaaS platform.

Responsibilities

  • Set Technical Direction for Product Security: Define and communicate security architecture vision across multiple engineering teams, influencing critical architecture decisions before code implementation. Drive adoption of secure-by-design frameworks that become the default approach for building new products and features across Snowflake's platform.
  • Design Security-Critical Systems and Frameworks: Architect and build foundational security services, controls, and frameworks that engineering teams adopt as defaults. Ensure these systems are scalable, maintainable, and effective at securing large-scale distributed cloud infrastructure and multi-tenant environments.
  • Lead Threat Modeling and Security Design Reviews: Conduct comprehensive threat modeling exercises and security design reviews for the platform's most complex and high-risk systems. Identify architectural vulnerabilities and design flaws before they reach production, working with engineering leadership to implement preventive controls.
  • Drive Secure-by-Design Implementation: Partner with product and engineering leadership to embed security requirements directly into the development lifecycle. Shape processes, tools, and practices that make security considerations integral to product design rather than an afterthought during review phases.
  • Investigate and Remediate High-Severity Security Issues: Lead investigation of the highest-impact security vulnerabilities and incidents. Drive comprehensive remediation strategies that eliminate entire vulnerability classes and attack patterns, not just individual instances, reducing future security risk.
  • Mentor and Elevate Security Engineering Capability: Mentor senior and mid-level engineers, raising the organization's security engineering expertise and technical standards. Share security best practices, review designs and code, and develop the next generation of security leaders within Snowflake.
  • Own End-to-End Security Initiatives: Take full ownership of complex security projects from problem definition and scope through delivery and cross-team alignment. Lead efforts including security architecture projects, software supply-chain security initiatives, vulnerability management programs, and automated security review systems.
  • Evaluate and Integrate Emerging Security Technologies: Assess and implement cutting-edge security tooling and AI-assisted analysis capabilities to enhance the team's impact and scalability. Leverage machine learning and generative AI technologies to automate security analysis, threat detection, and remediation workflows.

Qualifications

What we look for.

Technical

  • Secure Distributed Systems Design

    Deep expertise designing and architecting secure, large-scale distributed systems and cloud platforms. Demonstrated ability to identify and prevent security flaws in complex multi-component architectures serving millions of users.

  • Threat Modeling and Security Design

    Hands-on proficiency in threat modeling methodologies, secure design principles, and conducting security design reviews. Experience identifying architectural vulnerabilities and designing controls that prevent entire classes of attacks.

  • Vulnerability Analysis and Remediation

    Expertise in analyzing complex vulnerability classes, understanding root causes, and designing comprehensive remediation strategies. Experience with penetration testing, code review, and security assessment techniques.

  • Programming Language Proficiency

    Strong proficiency in one or more modern programming languages such as Java, Go, Rust, C++, or Python. Ability to review security-critical code and design secure APIs and frameworks.

  • Cloud-Native Security

    Experience securing cloud-native architectures, multi-tenant SaaS platforms, and distributed systems. Understanding of cloud infrastructure security, containerization, microservices security patterns, and cloud-specific threat models.

Education

  • Computer Science Degree or Equivalent

    Bachelor's degree in Computer Science, Computer Engineering, Mathematics, or related field. Equivalent professional experience and demonstrated expertise can substitute for formal education.

Experience

  • Software Engineering Leadership

    10+ years of professional software engineering experience with significant focus on product security or application security. Demonstrated track record of influencing technical decisions and driving engineering direction across multiple teams.

  • Product Security Architecture

    Substantial hands-on experience designing and implementing security solutions for product platforms. Background in either application security, platform security, or infrastructure security at scale.

  • Cross-Functional Collaboration

    Proven ability to work effectively with product teams, engineering leadership, incident response teams, and other stakeholders. Experience framing ambiguous security problems, structuring analysis, and driving consensus across diverse technical perspectives.

  • Security Problem-Solving

    Strong track record of taking ownership of complex, ambiguous security challenges. Experience scoping problems, designing solutions, and delivering results even when requirements and constraints are unclear.

Skills

Required

  • Security Architecture

    Ability to design end-to-end security solutions and define security architecture patterns for complex systems

  • Threat Modeling

    Expertise in identifying potential threats, attack vectors, and designing controls to mitigate security risks

  • Secure Code Review

    Capability to identify security vulnerabilities in code and recommend secure implementation patterns

  • System Design

    Deep understanding of distributed systems design, scalability, and architectural patterns relevant to security

  • Technical Leadership

    Ability to influence technical direction, mentor engineers, and drive architectural decisions across teams

  • Problem Framing

    Skill in breaking down ambiguous security problems, structuring analysis, and communicating findings to stakeholders

Preferred

  • Cloud Security

    Nice to have

    Experience securing cloud-native environments, multi-tenant SaaS platforms, and cloud infrastructure (AWS, Azure, GCP)

  • Cryptography

    Nice to have

    Familiarity with cryptographic algorithms, key management, encryption protocols, and cryptographic best practices

  • Identity and Access Management

    Nice to have

    Experience designing and implementing IAM systems, authentication mechanisms, authorization frameworks, and access control policies

  • Data Security

    Nice to have

    Knowledge of data protection strategies, encryption at rest and in transit, data classification, and privacy-preserving technologies

  • AI-Assisted Security

    Nice to have

    Experience applying AI, machine learning, or generative AI workflows (such as Cortex AI) to security analysis, threat detection, and automation

  • Software Supply Chain Security

    Nice to have

    Experience securing the software development and deployment pipeline, dependency management, and vulnerability scanning

  • Open Source Contributions

    Nice to have

    Contributions to open-source security projects or published security research demonstrating deep technical expertise

  • Incident Response Collaboration

    Nice to have

    Experience partnering with detection, incident response, forensics, or offensive security teams on security investigations

Tech stack

Languages

JavaGoRustC++Python

Frameworks

Security Frameworks and PatternsCloud Security Frameworks

Databases

Distributed Data WarehousesMulti-Tenant Database Security

Tools

Threat Modeling ToolsStatic Application Security Testing (SAST)Dynamic Application Security Testing (DAST)Vulnerability Scanning ToolsSecurity Information and Event Management (SIEM)

Other

AI and Machine Learning for SecurityGenerative AI for SecurityCloud PlatformsContainer and Kubernetes SecurityAPI SecurityAuthentication and Authorization Protocols

Compensation

Pay and benefits.

Base·USD 236,000 – 339,250

Equity·Stock options

Benefits

  • Professional Development

    Access to continuous learning opportunities, security certifications (CISSP, CCSK), and conference attendance to stay current with evolving security landscapes and emerging threat models

  • Competitive Health Insurance

    Comprehensive medical, dental, and vision coverage with flexible plan options to meet diverse healthcare needs

  • Retirement and Financial Planning

    401(k) retirement plans with company matching contributions to support long-term financial security and wealth building

  • Work-Life Balance

    Flexible work arrangements, generous paid time off, and remote work options to maintain sustainable work-life integration

  • Equity and Stock Options

    Participation in company stock option programs, allowing engineers to share in Snowflake's growth and success as a publicly traded company

  • Performance Bonuses

    Annual performance bonuses tied to individual and company objectives, recognizing exceptional contributions to security initiatives

  • Mental Health and Wellness

    Employee Assistance Program (EAP), mental health resources, wellness programs, and gym membership subsidies

Process

Interview steps.

  1. 01

    Initial Recruiter Screening

    Phone or video call with a recruiter to discuss your background, security experience, and interest in the role. This call typically focuses on validating your professional experience and understanding your career motivation.

  2. 02

    Technical Assessment

    Comprehensive discussion with hiring managers covering security architecture, threat modeling approaches, vulnerability analysis methodologies, and your approach to designing secure systems. May include whiteboarding or design discussions.

  3. 03

    Security Deep-Dive Interview

    Technical interview with security team members covering specific security domains such as cryptography, cloud security, secure coding practices, or incident response. Expect questions about real-world security challenges and your solutions.

  4. 04

    Architecture and System Design

    Detailed discussion of how you would architect security solutions for complex distributed systems, handle secure-by-design principles in product development, and scale security practices across multiple engineering teams.

  5. 05

    Leadership and Collaboration

    Conversation with engineering leadership about your experience mentoring engineers, influencing technical decisions, cross-functional collaboration, and driving organizational change around security practices.

  6. 06

    Executive Round

    Meeting with senior engineering or security leadership to discuss your vision for product security, ability to drive high-impact initiatives, and alignment with Snowflake's technical culture and values.

Full posting

Original listing.

At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done.

We are hiring a Staff Software Engineer, Product Security for our Security Foundations team. Product security sits at the center of the trust customers place in the Snowflake platform, and this role owns the hard technical problems that keep that trust intact. You will drive security architecture and secure-by-design practices across engineering teams, shaping how new products are built rather than reviewing them after the fact.

AS A STAFF SOFTWARE ENGINEER, PRODUCT SECURITY AT SNOWFLAKE, YOU WILL:

  • Set the technical direction for product security across multiple engineering teams, influencing architecture decisions before code is written

  • Design and build security-critical services, frameworks, and controls that other engineering teams adopt as defaults

  • Lead threat modeling and security design reviews for the platform's most complex and high-risk systems

  • Partner with product and engineering leaders to embed secure-by-design principles into the development lifecycle

  • Investigate and drive resolution of the highest-severity security issues, then eliminate the underlying class of problem, not just the instance

  • Mentor senior and mid-level engineers, raising the security engineering bar across the organization

  • Own initiatives end to end, from problem framing and scoping through delivery and cross-team alignment

  • Evaluate and integrate emerging security tooling, including AI-assisted analysis and automation, to scale the team's impact

OUR IDEAL STAFF SOFTWARE ENGINEER, PRODUCT SECURITY WILL HAVE:

  • 10+ years of software engineering experience, with a significant focus on product or application security

  • Deep expertise designing and building secure, large-scale distributed systems or platforms

  • Strong track record of driving cross-team technical decisions and influencing engineering direction

  • Hands-on experience with threat modeling, secure design review, and remediation of complex vulnerability classes

  • Proficiency in one or more modern programming languages (for example Java, Go, Rust, C++, or Python) as a supporting capability, not the definition of the role

  • Ability to frame ambiguous security problems, structure the analysis, and drive alignment across stakeholders

  • A Bachelor's degree in Computer Science or a related field, or equivalent experience

BONUS POINTS FOR THE FOLLOWING:

  • Experience securing cloud-native or multi-tenant SaaS platforms

  • Familiarity with cryptography, identity and access management, or data security at scale

  • Experience applying AI or GenAI workflows (for example Cortex AI) to security analysis, detection, or automation

  • Contributions to open-source security projects or published security research

  • Experience partnering with detection, incident response, or offensive security teams

WHY JOIN OUR ENGINEERING TEAM AT SNOWFLAKE?

The Product Security team builds the frameworks, services, and controls that make secure-by-design practices the default across Snowflake’s products and engineering lifecycle. We tackle complex problems spanning security architecture, automated security reviews, software supply-chain security, vulnerability management, and AI-assisted security at Snowflake’s scale. Engineers on the team have the opportunity to shape foundational security systems used across the company and directly strengthen the trust customers place in the Snowflake platform.

Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth. We are looking for people who share our values, challenge ordinary thinking, and push the pace of innovation while building a future for themselves and Snowflake.

How do you want to make your impact?

For jobs located in the United States, please visit the job posting on the Snowflake Careers Site for salary and benefits information: careers.snowflake.com

Redirects to Snowflake's application page.

Other roles

More at Snowflake.

View all 78 roles