604,099open jobs
31,594companies
86,696added this week
Browse all
Salary
$143k – $275k per year (Estimated)
Location
Remote (United States)
Seniority
Staff · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Formerly known as Brookfield Properties, BGRE is a leading global real estate developer and operator headquartered in New York, United States. Serving as the primary real estate operating platform for Brookfield Corporation, the company manages an extensive international portfolio spanning office, retail, logistics, hospitality, and residential sectors. Leveraging decades of operational expertise, it provides integrated asset management and property development solutions across major gateway markets worldwide.

Location

US TN - Remote

Job Description

The Staff Security Engineer, Cloud & AI Platform is a deeply technical, hands-on role responsible for making Brookfield Real Estate’s cloud and AI platforms secure by design. You will lead security architecture and implementation across AWS, Infrastructure as Code, software delivery, internally developed applications, and AI/agent systems.

This is a builder role. You will threat-model a design, review the underlying Terraform and application code, implement the control, instrument it, and help teams adopt it without unnecessary friction. Security requirements become reusable modules, automated checks, secure defaults, and clear engineering guidance rather than documents and findings lists.

You will partner closely with Cloud Solutions, application engineering, AI engineering, Identity, CyberOps, and GRC/Privacy. Platform engineering continues to own general platform uptime, capacity, and deployment mechanics, and CyberOps continues to own alert triage; this role owns the architecture, controls, tooling, and assurance mechanisms that make those systems safe.

Role & Responsibilities:

Leadership & Security Architecture

  • Help define security architecture for the cloud and AI platforms: set direction, write specs, and steward secure-by-default patterns across teams

  • Define security engineering standards and paved roads, document important decisions, and communicate risk and trade-offs to engineering and business leadership

  • Review infrastructure and application designs for authorization, network, data-protection, secrets, and tenant-isolation risks

  • Mentor engineers and raise the organization’s ability to make sound security decisions independently

  • Partner with Cloud Solutions, application engineering, AI engineering, Identity, CyberOps, and GRC/Privacy to prioritize work and drive adoption

Cloud & Identity Security

  • Own and evolve security architecture for a multi-account AWS organization - account boundaries, service control policies, IAM Identity Center, delegated security services, KMS, VPC controls, and WAF

  • Design least-privilege human and workload access across AWS, Okta, GitHub Actions, and Infrastructure as Code platforms using federation and short-lived credentials

  • Build and maintain reusable security controls in Terraform or OpenTofu, with safe rollout, testing, monitoring, and recovery patterns

  • Strengthen centralized logging and evidence - CloudTrail, Config, GuardDuty, Security Hub, Macie, and CloudWatch - and keep guardrails current as the environment grows

Secure Software Delivery

  • Establish secure GitHub Actions and runner patterns, including OIDC trust, environment separation, workflow protection, action pinning, artifact integrity, and least-privilege deployment roles

  • Integrate practical security checks into developer workflows - secrets detection, dependency and container scanning, SBOMs, Infrastructure as Code analysis, code scanning, and risk-based release gates

  • Support vulnerability management for internally developed software, from detection and prioritization through remediation evidence and exception handling. Partner with the Vulnerability Manager to establish prioritization and reduce false positives

  • Improve controls with engineers rather than around them, avoiding noisy or easily bypassed gates

Application & AI Security

  • Lead threat modeling and security design reviews for web applications, APIs, data ingestion, authentication and authorization flows, and agentic systems

  • Define secure patterns for Amazon Bedrock and other model platforms, including model access, guardrail lifecycle, invocation logging, usage attribution, and sensitive-data controls

  • Harden agent tools, MCP servers, gateways, sandboxes, and code-execution environments against prompt injection, confused-deputy attacks, excessive agency, secret disclosure, data exfiltration, and cross-tenant access

  • Build repeatable security evaluations and adversarial tests for AI-enabled features and connect findings to engineering remediation

Detection, Response & Assurance

  • Translate cloud and application telemetry into actionable detections, runbooks, ownership, and escalation paths in partnership with CyberOps

  • Lead technical response and root-cause remediation for cloud, identity, software supply chain, and AI security incidents

  • Establish severity and ownership standards for cloud findings, software vulnerabilities, and AI security issues, with clear remediation expectations

  • Produce the control evidence GRC and Privacy need, without turning engineering work into manual reporting

Your Qualifications:

  • 8+ years Experience

  • Demonstrated senior or Staff-level ownership of production security or platform systems, including architecture decisions others build on

  • Deep AWS security experience across IAM, multi-account or AWS Organizations environments, logging and detection, KMS, networking, and service-to-service authorization

  • Strong Terraform or OpenTofu skills, including modular design, remote execution, policy controls, and safe state-aware changes

  • Experience securing CI/CD systems such as GitHub Actions, including OIDC federation, runner trust boundaries, secrets, artifacts, and deployment permissions

  • Working knowledge of application security fundamentals: threat modeling, authentication and authorization, secure API design, secrets handling, dependency risk, and vulnerability remediation

  • Ability to read and write production-quality automation or application code in Python, Go, Ruby, or a comparable language

  • Demonstrated ability to influence teams you do not manage, make pragmatic risk decisions, and turn ambiguous security needs into implemented controls

Nice to Have

  • Experience with Amazon Bedrock, AgentCore, MCP, LLM gateways, AI guardrails, or production agentic systems

  • Container and orchestration security - ECS/Fargate or EKS, image supply chains, runtime isolation, and egress control

  • Identity platform depth: IAM Identity Center, Okta, Delinea, SAML, OIDC, OAuth, SCIM, ABAC, and enterprise entitlement systems

  • Experience with Scalr, Terraform Cloud, or another remote Infrastructure as Code platform

  • Familiarity with CrowdStrike Falcon Cloud Security, Datadog, CloudWatch, or comparable security and observability tooling

  • Data platform and sensitive-data controls involving S3, Snowflake, PostgreSQL/Aurora, or vendor data ingestion

  • AI threat modeling, red teaming, or security evaluation experience

Your Career @ Brookfield:

At Brookfield, your career progression is important to us. As a successful employee, you will have the opportunity to grow within your team, department, and across the Brookfield organization. Our leadership teams are dedicated to the accomplishments of their employees. We also invest time into training and developing our people.

End your job search and find your career today, at Brookfield.

Why Brookfield?

We imagine, create, and operate on a foundation of values to build a better world, together. Brookfield strives to create spaces where going to work never feels routine. As a Brookfield employee, you will enjoy many benefits such as 401K matching, tuition reimbursement, summer Fridays, paid maternity leave and more. There is also a generous employee referral program because we want our existing team members to help us build a more diverse workplace through their networks.

We are proud to create a diverse environment and are proud to be an equal opportunity employer. We are grateful for your interest in this position, however, only candidates selected for pre-screening will be contacted.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
604,099 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
United States
$131k – $312k per year (Estimated) • Equity • In office • Full-Time • Sydney
Python
AI/ML
Model Context Protocol
AI Agents
Agentic Workflows
DevOps
Terraform
GCP
AWS
Cybersecurity
Zero Trust
Design
Canva
Apply
$26k – $65k per year (Estimated) • Equity • Remote/Hybrid • 2+ years exp • Mexico City
Python
JavaScript
TypeScript
AI/ML
Claude
Model Context Protocol
AI Agents
LLM
LLM Guardrails
DevOps
Splunk
Terraform
GCP
CI/CD
AWS
Kubernetes
Cloudflare
IAM
Cybersecurity
SonarQube
Semgrep
ISO 27001
PCI DSS
SOC 2
Auth0
Management
Google Workspace
Apply
In office • 8+ years exp
Python
JavaScript
TypeScript
Python
FastAPI
AI/ML
Model Context Protocol
Prompt Engineering
Multimodal AI
RAG
OpenAI
Agentic Workflows
Frontend
React.js
DevOps
Rest API
Azure
CI/CD
Apply
$150k – $225k per year • Remote/Hybrid • 3+ years exp • Bachelor's Degree • San Mateo
Go
Databases
Redis
Aerospike
Cassandra
DynamoDB
Apache Kafka
DevOps
Terraform
Ansible
GCP
AWS
Kubernetes
SRE
Platform Engineering
Apply
In office
Python
AI/ML
Copilot
DevOps
CI/CD
Jenkins
Git
GitHub
Apply
Leasing Consultant 2 days ago
$41k – $92k per year (Estimated) • In office • Full-Time • 1+ year exp • High School Diploma • Chandler
Apply
$54k – $108k per year (Estimated) • In office • Full-Time • 5+ years exp • High School Diploma • Charlotte
Apply
Maintenance Manager 2 days ago
$45k – $80k per year (Estimated) • In office • Full-Time • 3+ years exp • High School Diploma • Charlotte
Apply
$37k – $64k per year (Estimated) • In office • Full-Time • 1+ year exp • Calgary
Apply
$40k – $58k per year • In office • Internship • High School Diploma • Oakland
Apply
$162k – $318k per year (Estimated) • In office • Full-Time • Bachelor's Degree • United States
Apply
Meat Lead 9 hours ago
$44k – $60k per year • In office • Full-Time • 1+ year exp • Bachelor's Degree • United States
Apply
$68k – $92k per year • In office • Full-Time • 2+ years exp • High School Diploma • United States
Apply
$42k – $58k per year • In office • Full-Time • Bachelor's Degree • United States
Apply
Equity • In office • Full-Time • United States
Apply
See all jobs
This is one of many
604,099 more open roles from verified company boards, updated every day.