Cloud Security Engineer
Braze
| Company | Braze |
| Category | Engineering |
| Location | São Paulo |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 21 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
At Braze, we have found our people. We’re a genuinely approachable, exceptionally kind, and intensely passionate crew.
We seek to ignite that passion by setting high standards, championing teamwork, and creating work-life harmony as we collectively navigate rapid growth on a global scale while striving for greater equity and opportunity – inside and outside our organization.
To flourish here, you must be prepared to set a high bar for yourself and those around you. There is always a way to contribute: Acting with autonomy, having accountability and being open to new perspectives are essential to our continued success.
Our deep curiosity to learn and our eagerness to share diverse passions with others gives us balance and injects a one-of-a-kind vibrancy into our culture.
If you are driven to solve exhilarating challenges and have a bias toward action in the face of change, you will be empowered to make a real impact here, with a sharp and passionate team at your back. If Braze sounds like a place where you can thrive, we can’t wait to meet you. WHAT YOU'LL DO
Braze is a modern, cloud-first SaaS company running on cloud-native infrastructure across AWS and GCP. We're looking for a Cloud Security Engineer to join our Security Engineering function - a hands-on role focused on keeping our security operations running well day to day. You'll respond to incidents, review changes and access for security risk, operate the security tooling that protects our environment (endpoint/EDR, SIEM, cloud posture, and vulnerability scanners), manage identity and access, and drive vulnerabilities to remediation.
This is an individual-contributor role that works within priorities set by senior members of the team. You don't need to have set security strategy or led a team - but you should operate tools with real judgment (knowing a genuine finding from noise, and why it matters), be reliable at driving issues to closure, and want to grow deeper in cloud security. It sits one level below our Senior Cloud Security Engineer.
Key job responsibilities:
1) Incident response & investigations:
Respond to security alerts and events - triage, contain, and help investigate - with support from senior engineers on higher-severity incidents
Follow and help improve our incident-response playbooks, and capture what you learn so the next response goes faster
Pull the right data (cloud logs, endpoint telemetry) to reconstruct what happened and support the response
2) Security reviews & IAM:
Review changes, designs, and cloud configurations for security issues, and give practical, specific feedback to the teams making them
Operate and improve identity and access across AWS and GCP: handle access requests, run least-privilege reviews, and keep access hygiene high
Reason about IAM policies and permissions - spotting risky or over-broad access and proposing tighter alternatives
3) Operate the security stack:
Run and tune our security tooling day to day - CrowdStrike (EDR/CSPM), SIEM, cloud-native security services, and vulnerability scanners such as Tenable
Triage the alerts these tools produce: separate real signal from noise, tune out false positives, and escalate what matters
Keep tooling healthy - coverage, agent deployment, integrations, and configuration
Write small scripts (Python) to automate repetitive work and reduce manual toil
4) Vulnerability management & remediation:
Run vulnerability scanning across cloud assets, and triage and prioritize findings by real risk, not just severity score
Drive remediation to closure: partner with Infrastructure, SRE, and Product Engineering to get fixes shipped, and track them until they're done
Spot recurring issues and suggest the guardrail or config change that stops them coming back
WHO YOU ARE
You're a hands-on engineer who's curious about how attacks and cloud systems work - not someone who just clicks through consoles. You oper
You found the opening. Now track it.Tracker, radar and AI drafts in one place.erioun.com →