371,660open jobs
9,621companies
49,388added this week
Browse all
Salary
$146k – $304k per year (Estimated)
Location
In office (Sunnyvale)
Seniority
Staff · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
GRAIL is a healthcare and biotechnology company headquartered in Menlo Park, California, and founded in 2016. The company develops and commercializes the Galleri multi-cancer early detection test, which uses next-generation sequencing and machine learning to identify signals from over 50 types of cancer through a single blood draw. It operates as an independent publicly traded entity following its spin-off from Illumina, focusing on clinical research and partnerships with healthcare systems and biopharmaceutical companies primarily in the United States and United Kingdom.

GRAIL is seeking a mission-driven and high-impact Staff Cloud Security Engineer to help secure the cloud platforms that power one of healthcare's most innovative early cancer detection technologies. Reporting to the Director of Product Security, this role serves as a technical leader responsible for shaping cloud security strategy, enabling secure product delivery, and helping protect the systems that support GRAIL's life-saving mission.

As a Staff-level individual contributor, you will lead the technical execution of the Cloud Security roadmap, partnering closely with Engineering, Platform, Infrastructure, DevOps, and Product teams to drive secure cloud transformation initiatives. You will provide guidance to other engineers while influencing cloud architecture, DevSecOps practices, and secure development decisions across the product and infrastructure lifecycle.

This role will help teams navigate an evolving threat landscape by implementing scalable AWS security controls, automation, and cloud-native security best practices while maintaining engineering agility and delivery velocity in a highly regulated environment.

This role is based in Sunnyvale, California. GRAIL offers a flexible work arrangement, with the ability to work from GRAIL's office or from home. Our current flexible work arrangement policy requires that a minimum of 60%, or 24 hours, of your total work week be on-site. Your specific schedule, determined in collaboration with your manager, will align with team and business needs and could exceed the 60% requirement for the site.

Responsibilities

  • Lead the design, implementation, and continuous improvement of cloud security architectures across AWS environments, ensuring product security, and secure-by-design principles throughout the infrastructure and application lifecycle.
  • Partner with Platform, and Cloud Engineering team to design, implement, and manage AWS-native security services including IAM, KMS, GuardDuty, Security Hub, Inspector, Macie, WAF, Shield, CloudTrail, Config, and CloudWatch for proactive threat detection and risk management.
  • Develop and enforce cloud security standards, guardrails, and governance frameworks across AWS accounts, containers, Kubernetes/EKS, serverless, and hybrid cloud workloads.
  • Automate security monitoring, compliance validation, vulnerability management, and incident response workflows using Infrastructure as Code (IaC), scripting, and cloud-native automation tools.
  • Conduct cloud threat modeling, architecture risk assessments, and security reviews for AWS-hosted applications, APIs, infrastructure, and enterprise-integrated systems.
  • Secure DevOps platforms and cloud-native application environments by implementing least-privilege access controls, secrets management, secure network segmentation, encryption, and workload protection.
  • Manage and enhance continuous cloud security posture management (CSPM), container security, and runtime protection capabilities across AWS environments.
  • Scope, coordinate, and review penetration testing, vulnerability assessments, and advanced security testing activities across cloud infrastructure, applications, and DevOps tooling.
  • Serve as a cloud security subject matter expert during security incidents, forensic investigations, root cause analysis, and remediation activities.
  • Partner with Engineering, Platform, Infrastructure, Compliance, and Product teams to align cloud security strategies with regulatory, privacy, and industry cybersecurity requirements.
  • Define, track, and report cloud security metrics, operational KPIs, and compliance status to provide visibility into organizational security posture and risk trends.
  • Mentor and guide engineers on AWS security best practices, DevSecOps methodologies, automation strategies, and secure cloud engineering principles to strengthen organizational security maturity at GRAIL.
  • These responsibilities summarize the role’s primary responsibilities and are not an exhaustive list. They may change at the company’s discretion.

Required Qualifications

  • 8+ years of experience in product security, cybersecurity, Cloud Security, application security, or related technical security roles.
  • Hands-on experience leading threat modeling, security risk assessments, and vulnerability management for complex software products.
  • Experience embedding security into modern software development environments, including CI/CD and DevSecOps practices.
  • Experience supporting security incident response and conducting root cause analysis in production environments.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent practical experience.
  • GRAIL Values & Leadership Expectations

  • This Staff-level role is expected to model GRAIL’s core values and LEAD leadership attributes by leading through influence, collaborating across boundaries, driving results with integrity, and continuously improving how product security enables patient impact.

Preferred Qualifications

  • Experience working in regulated environments, including medical devices, healthcare, life sciences, or similarly regulated industries.
  • Knowledge of relevant standards and frameworks such as IEC 62304, ISO 14971, ISO 80001-2, NIST, and FDA pre- and post-market cybersecurity guidance.
  • Experience securing AI/ML systems, including mitigating risks such as data poisoning, model manipulation, and unauthorized access.
  • Demonstrated experience delivering cybersecurity programs, including tabletop exercises and cross-functional incident simulations.
  • Professional security and cloud certifications such as AWS Certified Security - Specialty, AWS Certified Solutions Architect - Professional/Associate, OSCP, GPEN, GCIH, GWAPT, CISSP, CCSP, or equivalent certifications preferred.
  • Strong ability to translate technical security risks into business and patient-impact considerations for senior stakeholders.
  • Experience working with globally distributed teams or international stakeholders.

Physical Demands and Working Environment

  • Ability to work in an office and remote environment under a flexible hybrid arrangement.
  • Occasional travel may be required based on business needs.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
371,660 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Sunnyvale
$38k – $91k per year (Estimated) • Remote • Full-Time • 8+ years exp • PhD • Guadalajara
PowerShell
Python
Databases
Amazon Aurora
DynamoDB
AI/ML
Amazon SageMaker
AWS Bedrock
AWS Bedrock AgentCore
Ray
DevOps
Amazon CloudWatch
Amazon EC2
Amazon ECS
Amazon EKS
Amazon EventBridge
Amazon S3
AWS
AWS Lambda
AWS Step Functions
Azure
CI/CD
Datadog
FinOps
GCP
Git
GitLab
GitLab CI
IAM
Jenkins
JFrog Artifactory
Kubernetes
New Relic
Service Mesh
Splunk
Terraform
Cybersecurity
HIPAA
ISO 27001
PCI DSS
SOC 2
Apply
$173k – $314k per year • In office • Full-Time • 12+ years exp • Bachelor's Degree • San Francisco
Apex
JavaScript
Node JS
Python
SQL
TypeScript
Apex
Lightning Web Components
AI/ML
Agentforce
AI Agents
Claude
Claude Code
Copilot
Cursor
LLM
RAG
DevOps
AWS
Azure
CI/CD
Docker
GCP
GitHub
Grafana
gRPC
Kubernetes
New Relic
Prometheus
Splunk
Marketing
Salesforce
QA
Cypress
JMeter
k6
Locust
Playwright
Postman
Rest-Assured
Selenium
Apply
$96k – $134k per year • Remote/Hybrid • Full-Time • Bachelor's Degree • New York
JavaScript
Swift
TypeScript
Java
Java
Spring Framework
Databases
Apache Kafka
PostgreSQL
AI/ML
AI Agents
Claude
Copilot
Fine-tuning
Flink
LangChain
LangGraph
Llama
LlamaIndex
Prompt Engineering
PyTorch
RAG
TensorFlow
Transformers
Devin
Hugging Face
OpenAI
Frontend
Angular
React.js
Mobile
MVC
DevOps
AWS
CI/CD
Docker
Kubernetes
OpenShift
Splunk
Vector
GitHub
Analytics
Tableau
Apply
In office • Full-Time • PhD • Guadalajara
Python
SQL
Databases
Amazon Redshift
Snowflake
Trino
AI/ML
dbt
DevOps
AWS
AWS Lambda
CI/CD
Git
GitHub Actions
Terraform
GitHub
Apply
Senior ML Engineer 1 day ago
$149k – $224k per year • In office • Full-Time • 5+ years exp • Master's Degree • San Francisco • Washington • Palo Alto
Python
Python
pySpark
Databases
Apache Kafka
AI/ML
AI Agents
Agentforce
Airflow
Anomaly Detection
Feature Store
Flink
Ray
Red Teaming
Spark
DevOps
CI/CD
Docker
Kubernetes
Cybersecurity
MITRE ATT&CK
Marketing
Salesforce
Apply
$83k – $186k per year (Estimated) • In office • Full-Time • 1+ year exp • Bachelor's Degree • Durham
C++
Python
Rust
SQL
Databases
Amazon Redshift
Snowflake
AI/ML
dbt
AI Agents
DevOps
AWS
Git
Amazon S3
Analytics
ETL/ELT
Apply
$94k – $125k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Washington
PowerShell
Python
DevOps
Ansible
AWS
CI/CD
Configuration Management
Datadog
Git
New Relic
Platform Engineering
Terraform
VMWare
Apply
$177k – $337k per year (Estimated) • In office • Full-Time • 15+ years exp • Bachelor's Degree • Sunnyvale
Java
Java
Spring Boot
Spring MVC
Databases
Apache Iceberg
Databricks
ElasticSearch
Snowflake
AI/ML
LLM
RAG
Semantic Search
Spark
Semantic Search
DevOps
Ansible
AWS
CI/CD
Jenkins
Platform Engineering
Terraform
Cybersecurity
GDPR
HIPAA
Analytics
ETL/ELT
Apply
$136k – $180k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Washington
Go
Python
DevOps
AWS
Docker
Kubernetes
Apply
$93k – $195k per year (Estimated) • In office • 4+ years exp • Bachelor's Degree • Sunnyvale
Go
Java
Python
TypeScript
C++
Java
Gradle
C++
CMake
DevOps
AWS
Bazel
CI/CD
GitHub Actions
GitLab CI
Jenkins
Kubernetes
Platform Engineering
GitHub
GitLab
Apply
$183k – $276k per year • Equity • In office • Full-Time • 8+ years exp • Sunnyvale • Alpharetta
DevOps
AWS
Azure
GCP
Kubernetes
Cybersecurity
Snort
Suricata
Tcpdump
Wireshark
Zero Trust
Apply
$105k – $195k per year • Remote • Sunnyvale
Management
Jira
Apply
$127k – $185k per year • Equity • In office • Full-Time • 7+ years exp • Bachelor's Degree • Sunnyvale
AI/ML
AI Agents
LLM
Apply
Sr. SDET 1 day ago
$109k – $163k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Sunnyvale
Java
Python
SQL
Java
Spring Framework
Mobile
JUnit
DevOps
CI/CD
Kubernetes
QA
Cypress
JMeter
Postman
Apply
$168k – $356k per year • In office • Full-Time • 8+ years exp • Master's Degree • Sunnyvale
Python
AI/ML
AI Agents
ChatGPT
Gemini
LLM
NLP
RAG
Recommender Systems
Semantic Search
Semantic Search
Vertex AI
Apply
See all jobs
This is one of many
371,660 more open roles from verified company boards, updated every day.