WFH.teamOpen app
Back to remote jobs
Remote job detail

Senior Security Engineer, Incident Response

Snowflake

LocationUnited States
Senioritysenior
CompanySnowflake
Verified recentlyChecked today
Compensation

$176k-$253k

Salary details are shown when available from the source listing. Sign in before applying so the role can be reviewed against your resume, salary goals, seniority, timezone, and location eligibility.

Requirements and working style

Decision details from the source listing

Experience

5+ years stated

Education

Bachelor's degree in Computer Science or related field or equivalent experience

Work authorization

Authorized to work in United States

Schedule

fixed

Required overlap

Not specified

Benefits stated
Not specified

These fields are normalized from the employer's text. Confirm details on the employer site before applying.

WFH.team analysis

What this posting tells you

Senior Security Engineer position at Snowflake focused on Product Security Incident Response with emphasis on AI and LLM security. Role is remote within the US. Requires 5+ years experience in security incident response and engineering, strong cloud platform knowledge (AWS, Azure, GCP), and proficiency in security for AI systems. Salary range provided from $176,000 to $253,000. Bachelor's degree or equivalent experience required. Employment is full-time. The job stresses incident response leadership, threat modeling for AI-specific attack vectors, and integration of security in AI product pipelines.

Role lane

Backend, Customer success, Data, Design and creative, DevOps, Marketing, Product, QA and testing, Security, Software

Where you can work

United States

Working hours

America/New_York, America/Chicago, America/Denver, America/Los_Angeles

Arrangement

senior · full_time

Required signals
information securityincident responsesecurity engineeringproduct securityAI securityAWSAzureGCPSQLPython
Preferred signals
GoRustthreat modelingsecurity testing AI systemsCI/CDGCIAGCIHGCSAGDATCISSPGISPcloud certifications
Market context

Backend hiring on WFH.team

3,520active related roles
1,733new in the latest period
166.6jobs per 100 candidates
$211kmedian of comparable listed ranges

This role's listed pay is near the median among 200 comparable roles shown here. Category counts come from WFH.team's latest published remote job market snapshot.

Explore the remote job market
Skills and signals
information securityincident responsesecurity engineeringproduct securityAI securityAWSAzureGCPSQLPythonGoRustthreat modelingsecurity testing AI systemsCI/CDGCIAUS-USA-Remote
Job description

Senior Security Engineer, Incident Response at Snowflake

At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done.

We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect Snowflake's product-integrated Incident Response strategy, with a primary focus on AI and LLM security. You'll design, plan, and drive the implementation of incident response capabilities across Snowflake's AI product surface - including Cortex AI, Cortex Agents, Snowflake Intelligence, and the data pipelines that power them.

AS A SENIOR SECURITY ENGINEER, INCIDENT RESPONSE AT SNOWFLAKE, YOU WILL:

  • Lead incident response for product-level security events, with deep focus on AI-specific threat vectors including prompt injection, model abuse, agent hijacking, and data exfiltration through AI workloads.
  • Integrate IR into AI product pipelines - work directly with teams shipping Cortex features, Snowflake Intelligence, and AI-powered developer experiences to embed security requirements from design through deployment.
  • Develop and codify our AI abuse response strategy - defining detection, containment, and remediation playbooks for LLM misuse, adversarial inputs, and AI-assisted attacks targeting Snowflake customers.
  • Address tech debt across the AI product stack, ensuring that new Cortex and agentic architectures meet IR readiness requirements from the ground up.
  • Represent the IR team to cloud engineering, AI platform teams, corporate security, and customer-facing business units.
  • Secure modern AI-native codebases operating across multi-cloud environments - including container-based inference services, RAG pipelines, vector stores, and agent orchestration layers.
  • Partner with world-class AI and security engineering teams, providing expert guidance on secure architecture for high-impact AI features and customer-facing AI capabilities.
  • Design and manage response capabilities built into Snowflake's AI operational infrastructure - from model serving endpoints to Cortex Search indexes and Snowpark ML pipelines.
  • Lead with data, code, and automation - build tooling that accelerates detection and response for product security incidents at Snowflake scale.
  • Drive meaningful security outcomes for the customers and enterprises trusting Snowflake with their most sensitive data and AI workloads.

OUR IDEAL SENIOR SECURITY ENGINEER WILL HAVE

  • 5+ years of experience in information security, primarily in incident response, security engineering, or product/application security (preferred).
  • Direct experience serving as incident commander for product focused security incidents.
  • Experience leading or actively building an application or security engineering program, with a clear point of view on securing AI/ML systems.
  • Experience with threat modeling and security testing across AI attack surfaces, including prompt injection, indirect injection, model inversion, embedding extraction, and supply chain attacks on AI dependencies.
  • Familiarity with the unique data governance and security challenges introduced by LLMs, RAG architectures, and agentic systems.
  • Working knowledge of cloud-native environments (AWS, Azure, GCP) and the threat landscape specific to SaaS and AI platforms.
  • SQL proficiency, plus experience building automation and tools with common programming languages (Python preferred).
  • Strong communication skills, with the ability to translate security risk into actionable guidance for product teams.
  • Empathy for developer experience, helping AI engineers ship securely rather than slowing them down.
  • Bachelor's degree in Computer Science or a related field, or equivalent experience.

BONUS POINTS FOR THE FOLLOWING

  • Experience securing AI/ML infrastructure, including model serving, vector databases, embedding pipelines, API gateways, and LLM-integrated application architectures.
  • Experience building agentic incident response capabilities, including skills, agents, and pipelines.
  • Understanding of current attacker TTPs, including emerging AI-specific techniques such as adversarial ML, agent manipulation, and LLM jailbreaking in enterprise contexts.
  • Familiarity with CI/CD and secure release lifecycle patterns, with an emphasis on building security into AI feature pipelines.
  • Preferred certifications: GCIA, GCIH, GCSA, GDAT, CISSP/GISP, or cloud certifications (AWS, Azure, GCP).

WHY JOIN OUR SECURITY INCIDENT RESPONSE TEAM AT SNOWFLAKE?

This is a chance to do incident response at the frontier of AI security, on products that thousands of enterprises rely on. You will work alongside strong AI and security engineering teams, shape how Snowflake responds to novel LLM and agentic threats, and build the tooling and playbooks that define response for AI-native systems. The work is high-impact and highly visible, with direct influence on the trust customers place in Snowflake's AI capabilities.

The application window is expected to be open until September 11, 2026. This opportunity will remain posted based on business needs, which may be before or after the specified date.

Every Snowflake employee is expected to follow the company’s confidentiality and security standards for handling sensitive data. Snowflake employees must abide by the company’s data security plan as an essential part of their duties. It is every employee's duty to keep customer information secure and confidential.

Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth. We are looking for people who share our values, challenge ordinary thinking, and push the pace of innovation while building a future for themselves and Snowflake.

How do you want to make your impact?

For jobs located in the United States, please visit the job posting on the Snowflake Careers Site for salary and benefits information: careers.snowflake.com http://careers.snowflake.com

Company context

Working remotely at Snowflake

Snowflake’s cloud data platform shatters the barriers that have prevented organizations of all sizes from unleashing the true value from their data.

Headquarters
Australia, United States, Germany, Singapore, Japan, India, New Zealand, United Kingdom, France, Sweden, Netherlands, Spain, Switzerland, and Poland
Team size
1001-5000
Founded
2012
Remote policy

Remote hiring signal is inferred from active confirmed-remote job listings.

Application process

Review current openings on Snowflake's official careers page before applying.

FoundationJavaScriptPythonHTML5JavaCSS 3PHPGoC++Linux
Research Snowflake