
Staff Software Engineer, Product Security
Job description
About the role
You will set the technical direction for product security across multiple engineering teams at Snowflake, shaping architecture decisions before a single line of code is written. You will design and build security-critical services and frameworks that become the default foundation for other teams building on Snowflake. You will lead threat modeling and security design reviews for the platform's most complex and high-risk systems, ensuring trust is engineered in from the start. You will partner with product and engineering leaders to embed secure-by-design principles into the development lifecycle, moving security left and preventing issues early. You will investigate and drive resolution of the highest-severity security issues, then eliminate the underlying class of problem so it cannot recur. You will mentor senior and mid-level engineers, raising the security engineering bar and fostering a culture of shared responsibility across the organization. You will own initiatives end to end, from problem framing and scoping through delivery, cross-team alignment, and long-term operationalization. You will evaluate and integrate emerging security tooling, including AI-assisted analysis and automation, to scale the team's impact as the enterprise accelerates.
Key facts
What you'll do
- Set the technical direction for product security across multiple engineering teams, influencing architecture decisions before code is written.
- Design and build security-critical services, frameworks, and controls that other engineering teams adopt as defaults.
- Lead threat modeling and security design reviews for the platform's most complex and high-risk systems.
- Partner with product and engineering leaders to embed secure-by-design principles into the development lifecycle.
- Investigate and drive resolution of the highest-severity security issues, then eliminate the underlying class of problem, not just the instance.
- Mentor senior and mid-level engineers, raising the security engineering bar across the organization.
- Own initiatives end to end, from problem framing and scoping through delivery and cross-team alignment.
- Evaluate and integrate emerging security tooling, including AI-assisted analysis and automation, to scale the team's impact.
- Define and maintain security standards and best practices tailored to Snowflake's product and multi-tenant architecture.
- Collaborate with cross-functional teams to establish secure development patterns and integrate them into engineering workflows.
- Drive the implementation of secure coding practices and controls through automated guardrails and developer-friendly tooling.
- Work closely with architecture teams to ensure security controls are designed into platforms and services from the ground up.
- Track and analyze security metrics and trends to identify systemic risks and drive measurable improvements.
- Represent product security in cross-company forums, working groups, and incident response discussions to align on priorities.
- Explore and prototype new security approaches, including the application of AI and automation, to address emerging threats.
Requirements
- 10+ years of software engineering experience, with a significant focus on product or application security.
- Deep expertise designing and building secure, large-scale distributed systems or platforms.
- Strong track record of driving cross-team technical decisions and influencing engineering direction.
- Hands-on experience with threat modeling, secure design review, and remediation of complex vulnerability classes.
- Proficiency in one or more modern programming languages (for example Java, Go, Rust, C++, or Python) as a supporting capability, not the definition of the role.
- Ability to frame ambiguous security problems, structure the analysis, and drive alignment across stakeholders.
- A Bachelor's degree in Computer Science or a related field, or equivalent experience.
- Demonstrated experience delivering security at scale in complex, fast-paced environments.
- Proven ability to communicate technical concepts clearly to both technical and non-technical audiences.
- Comfort operating in an environment with high ambiguity, evolving priorities, and rapid experimentation.
- Willingness to work closely with detection, incident response, and offensive security teams during investigations and escalations.
- Commitment to following and improving security processes, policies, and controls across the organization.
- Understanding of the shared responsibility model in cloud and multi-tenant environments.
Nice to have
- Experience securing cloud-native or multi-tenant SaaS platforms.
- Familiarity with cryptography, identity and access management, or data security at scale.
- Experience applying AI or GenAI workflows (for example Cortex AI) to security analysis, detection, or automation.
- Contributions to open-source security projects or published security research.
- Experience partnering with detection, incident response, or offensive security teams.
Practical notes
- This role is based in Menlo Park, California, and requires authorization to work in the United States.
- Snowflake is an equal opportunity employer and values diversity in our teams.
- New graduates and entry-level candidates are not eligible for this role due to the experience requirements outlined above.
- Only candidates who meet the hard requirements and demonstrate relevant experience will be contacted for the next steps.
- The selected candidate will be required to complete any applicable background checks as part of the hiring process.
- This position is full-time and eligible for standard Snowflake benefits as applicable to the role and location.
- Compensation details will be discussed in later stages of the hiring process with a recruiter.
- Applicants should be prepared to discuss their experience securing large-scale, distributed systems and their approach to security architecture.
- Candidates should highlight examples of mentoring engineers and driving security initiatives across multiple teams.
- This role is not focused on endpoint security, identity and access management for corporate systems, or internal tooling for security operations.
- The day-to-day work will involve significant collaboration with product teams, security peers, and engineering leadership.
- Travel is not expected as part of this role, and remote or hybrid arrangements will be determined by policy and team needs.
- Visa sponsorship may be considered for eligible candidates depending on role and business needs.
- Applicants are encouraged to move quickly in their application if they are a strong match, as high-performing roles like this may fill rapidly.
- You are encouraged to tailor your application materials to highlight how your experience aligns with the outlined responsibilities and requirements.
- This job description is intended to describe the general nature and level of work performed and does not constitute an exhaustive list of all responsibilities, skills, or requirements.