368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$192k – $230k per year
Location
In office (Boston)
Seniority
Senior
Employment
Full-Time
Overview
Company
Impact
Profile match
Snyk is a developer security company headquartered in Boston, Massachusetts, and founded in 2015 in London. The company builds tools that scan source code, open source dependencies, containers, and infrastructure as code for vulnerabilities inside the normal developer workflow. It maintains its own vulnerability database, integrates with common source control and continuous integration systems, and serves enterprise engineering teams worldwide.

Snyk is the leader in secure AI software development, helping millions of developers develop fast and stay secure as AI transforms how software is built. Our AI-native Developer Security Platform integrates seamlessly into development and security workflows, making it easy to find, fix, and prevent vulnerabilities - from code and dependencies to containers and cloud.

Our mission is to empower every developer to innovate securely in the AI era - boosting productivity while reducing business risk. We’re not your average security company - we build Snyk on One Team, Care Deeply, Customer Centric, and Forward Thinking.

It’s how we stay driven, supportive, and always one step ahead as AI reshapes our world.

Job Summary

Snyk's Product Security team works consultatively with the engineering teams that build and run our cloud platform: we identify the security requirements, agree together on what needs to change, and the owning teams implement it. As a Senior Product Security Engineer (Platform), you'll pair deep GCP and AWS infrastructure experience with AI coding agents to turn threat models into concrete Terraform, Kubernetes, and pipeline fixes, then work directly with platform teams to get those fixes merged. The goal is simple to state and hard to do well: make the secure option the easy option for the engineers building Snyk's platform.

About the Team

You'll join Snyk's Product Security team, which operates as an advisor rather than an owner: the cloud infrastructure teams retain ownership and operation of their systems, and Product Security's job is to find what needs to change and make that change easy to ship. The team sits close to Snyk's platform and infrastructure organization and is increasingly built around AI agents doing real infrastructure work, not just reviewing someone else's.

What You’ll Do

  • Threat model Snyk's cloud infrastructure across GCP and AWS to identify the security requirements platform teams need to meet, then negotiate the resulting changes directly with the teams that own the systems.
  • Use AI coding agents (for example Claude Code) to draft the Terraform, Kubernetes, and pipeline changes that fix identified security gaps, and raise them for the owning team to review and merge.
  • Run agent-driven fixes at scale across many repositories, scoping every change so the owning platform team can review and merge it with confidence.
  • Write and maintain the guidance AI agents rely on (skills, prompts, instruction files, security baselines) so agent output consistently matches Snyk's standards.
  • Connect agents to live cloud, CSPM, and ticketing data through MCP servers, command-line tools, and provider APIs so their fixes are grounded in the real environment.
  • Review AI-generated infrastructure changes critically: catch invented resources, unsafe defaults, and IAM permissions scoped wider than they need to be.
  • Harden GCP identity and access management, including the resource hierarchy, IAM roles and conditions, service accounts and workload identity federation, and organization policy constraints, plus the AWS IAM equivalent.
  • Improve Kubernetes and container security, primarily on GKE: cluster hardening (private clusters, Autopilot), RBAC, admission control, workload identity, network policy, and secure container image pipelines (Artifact Registry, Binary Authorization).
  • Add automated security testing and CSPM tooling to CI/CD and GitOps pipelines, then help teams triage and fix what those tools surface.
  • Benchmark infrastructure against secure configuration baselines such as the CIS Google Cloud Foundation Benchmark, and against the infrastructure controls in frameworks like ISO 27001 and NIST 800-53.
  • Limit the risks AI agents themselves introduce: prompt injection, over-broad permissions, leaked secrets, and changes made without review.
  • Measure whether agent-driven fixing is actually working across teams, and improve the approach as you learn what does and doesn't land.

What you’ll bring

  • 5-8 years running or securing cloud infrastructure, ideally having built and operated production platforms on GCP or AWS before moving into security.
  • Deep, hands-on GCP knowledge, including its security services, plus a good working knowledge of AWS; equivalent AWS IAM depth is a bonus.
  • Strong grasp of GCP IAM: resource hierarchy (organization, folders, projects), IAM roles and conditions, service accounts and workload identity federation, organization policy constraints, and least privilege design.
  • Practical Kubernetes and container experience, primarily GKE: cluster hardening (private clusters, Autopilot), RBAC, admission control, workload identity, network policy, and secure container images. EKS experience is also welcome.
  • Comfort with infrastructure as code (for example Terraform) and automated deployment: CI/CD pipelines and GitOps.
  • Solid DevSecOps practice: threat modeling, early shift-left testing, and continuous monitoring, plus the judgment to turn that into concrete infrastructure changes.
  • Confidence using AI coding agents (for example Claude Code) day to day, including writing the guidance and prompts that keep their output reliable at scale.
  • A critical eye for AI-generated infrastructure output: able to spot invented resources, unsafe defaults, and overly broad IAM permissions before anything ships.
  • Comfort working consultatively: influencing and negotiating changes with teams who own and run the infrastructure, rather than owning it yourself.
  • Nice to have: application security knowledge (for example code review, OWASP Top 10), or experience with Snyk's products or similar security testing tools.

Compensation

Annual Base Salary Range: $192,000 - $230,000

Snyk is committed to equal pay for equal work and carefully considers a wide range of compensation factors. Actual compensation may vary based on prior experience, skills, location, internal equity, and other job-related factors.

We care deeply about the warm, inclusive environment we’ve created and we value diversity - we welcome applications from those typically underrepresented in tech. If you like the sound of this role but are not totally sure whether you’re the right person, do apply anyway!

About Snyk

Snyk is committed to creating an inclusive and engaging environment where our employees can thrive as we rally behind our common mission to make the digital world a safer place. From Snyk employee resource groups, to global benefits that help our employees prioritize their health, wellness, financial security, and a work/life blend, we aim to support our employees along their entire journeys here at Snyk.

Benefits & Programs

  • Prioritize health, wellness, financial security, and life balance with programs tailored to your location and role.

  • Flexible working hours, work-from home allowances, in-office perks, and time off for learning and self development

  • Generous vacation and wellness time off, country-specific holidays, and 100% paid parental leave for all caregivers

  • Health benefits, employee assistance plans, and annual wellness allowance

  • Country-specific life insurance, disability benefits, and retirement/pension programs, plus mobile phone and education allowances

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Boston
$100k – $200k per year • Equity 0.5–5% • In office • Full-Time • 1+ year exp • New York
Python
TypeScript
JavaScript
Python
FastAPI
Databases
DynamoDB
PostgreSQL
AI/ML
Claude
LLM
OpenAI
AI Agents
Frontend
Next.js
Tailwind CSS
React.js
DevOps
AWS
Docker
Vercel
GitHub
Management
Slack
Apply
$230k – $300k per year • Equity 0.1–0.2% • In office • Full-Time • 3+ years exp • PhD • New York
TypeScript
Databases
PostgreSQL
AI/ML
AI Agents
Claude
Claude Code
Cursor
Devin
OpenAI Codex
Frontend
Next.js
tRPC
DevOps
Platform Engineering
Vercel
Apply
$25k – $42k per year • Equity 0–0.2% • Remote • Full-Time • 3+ years exp
Bash
Go
JavaScript
Python
TypeScript
DevOps
AWS
Azure
CI/CD
Datadog
Docker
GCP
GitHub Actions
GitLab CI
Grafana
Incident Management
Kubernetes
Platform Engineering
Prometheus
Terraform
Amazon CloudWatch
GitHub
GitLab
IAM
Cybersecurity
Least Privilege
Apply
$100k – $210k per year • Equity 0–0.5% • Remote • Full-Time • 3+ years exp • San Francisco
Bash
Go
JavaScript
Python
TypeScript
DevOps
AWS
Azure
CI/CD
Datadog
Docker
GCP
GitHub Actions
GitLab CI
Grafana
Incident Management
Kubernetes
Platform Engineering
Prometheus
Terraform
Amazon CloudWatch
GitHub
GitLab
IAM
Cybersecurity
Least Privilege
Apply
Team Lead DevOps 1 day ago
$23k – $62k per year (Estimated) • Remote • 5+ years exp • Moscow
Bash
Python
Erlang
Erlang
EMQX
Databases
Apache Kafka
ClickHouse
PostgreSQL
RabbitMQ
Redis
Redpanda
Trino
DevOps
Ansible
AWS
AWX
FinOps
HAProxy
Hetzner
Kubernetes
SLI/SLO/SLA
Terraform
Yandex Cloud
Amazon S3
Apply
$105k – $205k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Boston
DevOps
Jenkins
GitHub
Cybersecurity
Snyk
Management
Jira
Apply
In office • Full-Time • Bucharest
AI/ML
Claude
AI Agents
DevOps
CI/CD
Jenkins
GitHub
Cybersecurity
SBOM
Snyk
Threat Modeling
Management
Jira
Apply
$74k – $161k per year (Estimated) • In office • Full-Time • 2+ years exp • Boston
Go
JavaScript
TypeScript
AI/ML
Claude
Copilot
DevOps
Docker
Kubernetes
GitHub
Cybersecurity
Snyk
Apply
$82k – $168k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • London
DevOps
Jenkins
GitHub
Cybersecurity
Snyk
Management
Jira
Apply
$109k – $221k per year (Estimated) • In office • Full-Time • Ottawa
AI/ML
Claude
AI Agents
DevOps
CI/CD
Jenkins
GitHub
Cybersecurity
SBOM
Snyk
Threat Modeling
Management
Jira
Apply
$96k – $163k per year • Equity • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Boston
C#
JavaScript
Python
TypeScript
DevOps
Azure AKS
CI/CD
Kubernetes
Rest API
Azure
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
$94k – $294k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Portland • Milwaukee • Dallas • Columbus
Apply
$111k – $218k per year (Estimated) • In office • Boston
Python
SQL
Databases
Databricks
AI/ML
dbt
DevOps
AWS
Azure
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.