Talent.com
Senior Security Engineer, Cloud Platform

Senior Security Engineer, Cloud Platform

CelerData, Inc.Menlo Park, CA, United States
1 day ago
Job type
  • Full-time
Job description

About CelerData

At CelerData, our mission is to empower organizations to fully leverage their data. We achieve this with our cutting-edge, cloud-native, high-performance analytical database, specifically designed for modern lakehouse architectures. We're challenging established solutions like Snowflake, ClickHouse, and Trino by delivering unmatched query performance and a simplified architecture to enterprises globally. Join us as we help our customers convert their data into practical insights and attain outstanding technical achievements.

Job Overview

As a Product Security Engineer at CelerData, you'll embed with our platform and cloud teams to design and build secure-by-default features for StarRocks and CelerData Cloud. You will drive threat modeling, security assurance, and automation across our control plane, data plane, and BYOC (bring-your-own-cloud) deployments. Your work will span identity, secrets and key management, container / Kubernetes hardening, operating security tooling, and vulnerability management-scaling security through paved roads, tooling, and code.

Key Responsibilities

  • Secure design & threat modeling : Partner with PM / engineering to review architectures and data flows (SaaS, on-prem, BYOC). Define security requirements and mitigations for features such as multi-tenant isolation, row / column-level security, auditing, and encryption.
  • Security Process : Develop processes, tooling and automation to scale security processes and mitigate risks to the business
  • Cloud & Kubernetes hardening : Establish secure baselines for AWS / Azure / GCP; least-privilege IAM; network segmentation and private connectivity (e.g., PrivateLink / Private Endpoint); runtime policies (e.g., Cilium / Calico), admission controls, and secrets handling for K8s.
  • Identity & secrets : Advance SSO / MFA for customers and internal systems; standardize OIDC / SAML flows; engineer passwordless and m2m auth; manage KMS / HSM-backed key lifecycles; integrate with Vault for automated rotation.
  • Data protection : Ensure encryption in transit / at rest for object stores (S3 / ADLS / GCS) and internal services; define data classification and tokenization / obfuscation patterns where appropriate.
  • Vulnerability management & assurance : Run coordinated scanning / fuzzing (including C++ components), triage reports (bug bounty / responsible disclosure), drive fixes to closure with clear SLAs, and commission targeted pentests.
  • Detection enablement : Improve security telemetry across control and data planes; contribute product-centric detections / runbooks for abuse, exfiltration, or privilege misuse.
  • Incident readiness : Maintain product incident playbooks; participate in investigations affecting CelerData products and customers; lead post-mortems and drive durable remediation.
  • Developer enablement : Provide clear guidance, examples, and "paved road" modules (Terraform / K8s manifests, SDK patterns). Deliver practical, lightweight training on secure coding and secrets hygiene.

Qualifications

Minimum Requirements

  • 5+ years in product / application, platform, or cloud security supporting engineering teams shipping distributed systems at scale (or comparable impact).
  • Hands-on with at least one major cloud (AWS / Azure / GCP) and Kubernetes security (RBAC, admission, PSP replacements, runtime policies, image signing).
  • Proficiency in at least one of : Python or Go for automation; plus the ability to read and review C++ and / or Java for security implications.
  • Solid grasp of authN / Z patterns (OIDC / SAML, OAuth2, service-to-service auth), secrets and key management (KMS / HSM, Vault), and TLS mTLS fundamentals.
  • Experience designing controls for multi-tenant SaaS or BYOC architectures (isolation, network egress controls, private connectivity, least-privilege IAM).
  • Clear, pragmatic communicator who can influence design, document decisions, and drive cross-team execution.
  • Preferred Qualifications

  • Fuzzing experience (e.g., libFuzzer / AFL / OSS-Fuzz) or sanitizers for native code; prior work securing OLAP / DB, storage engines, or high-performance C++ services.
  • IaC security (Terraform + Conftest / OPA checks), cloud org guardrails, SCP / Config / Policy, and drift detection.
  • Familiarity with data security features (RLS / CLS, masking, audit / eventing) in analytics platforms.
  • Contributions to open-source projects (StarRocks / ClickHouse / Trino ecosystems a plus).
  • Relevant certifications (AWS / Azure / GCP security, CNCF / K8s), or equivalent demonstrable experience
  • #J-18808-Ljbffr

    Create a job alert for this search

    Senior Security Engineer Security • Menlo Park, CA, United States

    Related jobs
    • Promoted
    Principal Cloud Security Engineer

    Principal Cloud Security Engineer

    NevroRedwood City, CA, United States
    Full-time
    Nevro (NYSE : NVRO) is a global medical device company headquartered in Redwood City, California.We are focused on delivering comprehensive, life-changing solutions that continue to set the standard...Show moreLast updated: 2 days ago
    • Promoted
    Senior Software Security Engineer — Cloud & DevSecOps

    Senior Software Security Engineer — Cloud & DevSecOps

    Cadence Design SystemsSan Jose, CA, United States
    Full-time
    A leading electronic design automation company is seeking a Sr.Software Security Engineer in San Jose.The role emphasizes software security for both cloud and on-premise systems, involving tasks su...Show moreLast updated: 2 days ago
    • Promoted
    Principal Platform Security Engineer (Cloud / K8S)

    Principal Platform Security Engineer (Cloud / K8S)

    GeminiSan Francisco, CA, United States
    Full-time
    Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and in...Show moreLast updated: 30+ days ago
    • Promoted
    Senior / Staff Cloud Security Engineer

    Senior / Staff Cloud Security Engineer

    The Rundown AI, Inc.San Francisco, CA, United States
    Full-time
    Abridge was founded in 2018 with the mission of powering deeper understanding in healthcare.Our AI-powered platform was purpose-built for medical conversations, improving clinical documentation eff...Show moreLast updated: 10 days ago
    • Promoted
    Lead Security Engineer, Cloud Infrastructure

    Lead Security Engineer, Cloud Infrastructure

    KlaviyoSan Francisco, CA, United States
    Full-time
    At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair sh...Show moreLast updated: 13 days ago
    • Promoted
    Senior Infrastructure Security Engineer - DGX Cloud

    Senior Infrastructure Security Engineer - DGX Cloud

    NVIDIASanta Clara, CA, United States
    Full-time
    NVIDIA is looking for a Sr Infrastructure Security Engineer who will design and implement security best practices for on-premise and cloud access, keeping in mind boundaries that securely enable NV...Show moreLast updated: 13 days ago
    • Promoted
    Security Engineer, Product and Cloud

    Security Engineer, Product and Cloud

    Modular ServicesLos Altos, CA, United States
    Full-time
    At Modular, we're on a mission to revolutionize AI infrastructure by systematically rebuilding the AI software stack from the ground up. Our team, made up of industry leaders and experts, is buildin...Show moreLast updated: 2 days ago
    • Promoted
    Senior Cloud Security Engineer

    Senior Cloud Security Engineer

    DelineaRedwood City, CA, United States
    Full-time
    Delinea is a pioneer in securing human and machine identities through intelligent, centralized authorization, empowering organizations to govern interactions across the modern enterprise.It leverag...Show moreLast updated: 27 days ago
    • Promoted
    Senior Security Engineer — Cloud & App Platform

    Senior Security Engineer — Cloud & App Platform

    SentrySan Francisco, CA, United States
    Full-time
    A leading software monitoring company is seeking a Senior Security Engineer in San Francisco to enhance its cloud security posture. In this role, you will lead security initiatives, collaborate with...Show moreLast updated: 2 days ago
    • Promoted
    Senior Security Engineer : Hybrid Cloud & App Security

    Senior Security Engineer : Hybrid Cloud & App Security

    SentrySan Francisco, CA, United States
    Full-time
    A leading software monitoring company is seeking a Senior Security Engineer in San Francisco to enhance its cloud security posture. In this role, you will lead security initiatives, collaborate with...Show moreLast updated: 2 days ago
    • Promoted
    • New!
    Senior / Staff Cloud Security Engineer

    Senior / Staff Cloud Security Engineer

    The Rundown AI, Inc.San Francisco, CA, United States
    Full-time
    About Abridge Abridge was founded in 2018 with the mission of powering deeper understanding in healthcare.Our AI-powered platform was purpose-built for medical conversations, improving clinical doc...Show moreLast updated: 11 hours ago
    • Promoted
    • New!
    Senior Enterprise Security Engineer - Cloud & App Security

    Senior Enterprise Security Engineer - Cloud & App Security

    SalesforceSan Francisco, CA, United States
    Full-time
    A global technology company is seeking a Senior Enterprise Engineer in San Francisco, CA.This role focuses on application and network security, involving full stack security assessments and collabo...Show moreLast updated: 11 hours ago
    • Promoted
    Vulnerability Management Engineer - Cloud & Apps Security

    Vulnerability Management Engineer - Cloud & Apps Security

    Cooley LLPSan Francisco, CA, United States
    Full-time
    A leading law firm in San Francisco is seeking a Technology Vulnerability Management Engineer to manage the full vulnerability lifecycle across various environments. This role requires at least 2 ye...Show moreLast updated: 1 day ago
    • Promoted
    Cloud Security Engineer

    Cloud Security Engineer

    MetaMenlo Park, CA, United States
    Full-time
    We are seeking a Security Engineer who specializes in designing and implementing new systems and tools to enhance the security of Meta’s products and infrastructure. This role is ideal for individua...Show moreLast updated: 2 days ago
    • Promoted
    Senior Cloud Security Engineer

    Senior Cloud Security Engineer

    Avant Digital Inc.San Francisco, CA, United States
    Full-time
    Senior Cloud Security Engineer.Contract type - Contract / C2C.Juniper Networks Cyber Fusion is looking for a certified cybersecurity professional to join our highly collaborative and diverse team o...Show moreLast updated: 2 days ago
    • Promoted
    Senior Cloud Security Engineer - Platform & DevSecOps

    Senior Cloud Security Engineer - Platform & DevSecOps

    CelerData, Inc.Menlo Park, CA, United States
    Full-time
    A technology company is looking for a Product Security Engineer to design secure features for their cloud platform.The role involves threat modeling, security assurance, and managing vulnerabilitie...Show moreLast updated: 1 day ago
    • Promoted
    Senior Software Engineer, Cloud Security

    Senior Software Engineer, Cloud Security

    Otter.aiMountain View, CA, United States
    Permanent
    We are seeking an experienced Cloud Security Engineer to join our team.The successful candidate will be responsible for designing, implementing, and maintaining the security of our cloud infrastruc...Show moreLast updated: 30+ days ago
    • Promoted
    AWS Cloud Security Engineer

    AWS Cloud Security Engineer

    AI Technologies LLC.Redwood City, CA, United States
    Permanent
    AWS Cloud Security Architecture : .Deep hands-on expertise in securing AWS environments, including cloud landing zones, guardrails, and multi-account or subscription setups.Identity and Access Manage...Show moreLast updated: 30+ days ago