Logo for Snowflake

Staff Security Engineer - Threat Detection

Role overview

Qualifications

  • 8+ years of security engineering experience across one or more of threat detection, incident response, threat hunting, product security, or corporate security
  • Strong coding ability in a high-level language such as Python or Go
  • Experience handling data programmatically (SQL, Python), ideally with large-scale log and telemetry datasets
  • Hands-on experience with at least one major cloud provider (AWS, Azure, or GCP)

Responsibilities

  • Develop and deploy detections using modern engineering practices
  • Mature threat detection program by analyzing coverage gaps and mitigating risks
  • Make data-driven recommendations for detective and preventative controls
  • Design and build automations and AI-driven workflows that strengthen our security posture

About the company

Snowflake logo

Snowflake

Computer Software / SaaS

Snowflake delivers the AI Data Cloud β€” a global network where thousands of organizations mobilize data with near-unlimited scale, concurrency, and performance. Inside the AI Data Cloud, organizations unite their siloed data, easily discover and securely share governed data, and execute diverse analytic workloads. Wherever data or users live, Snowflake delivers a single and seamless experience across multiple public clouds. Snowflake’s platform is the engine that powers and provides access to the AI Data Cloud, creating a solution for data warehousing, data lakes, data engineering, data science, data application development, and data sharing. Join Snowflake customers, partners, and data providers already taking their businesses to new frontiers in the AI Data Cloud.

Company details

Company typeLarge
IndustryComputer Software / SaaS
Company size5001 - 10000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset β€” who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done.

We are hiring a Staff Security Engineer, Threat Detection for our Security team. This is a fully remote role open to candidates across the United States. As Snowflake scales globally, we are investing heavily in AI-powered threat detection and response to protect our customers and our environment at cloud scale. This role helps enhance and extend the reach of Snowflake's Threat Detection Program, with AI and automation as core primitives in how we detect, triage, and respond to threats. You will combine deep security expertise with strong engineering skills to build, maintain, and evolve detections and the pipelines that support them, partnering with stakeholders across Security and Engineering to make informed, data-driven decisions grounded in threat models, proactive threat hunts, and exploration of logs and telemetry.

AS A STAFF SECURITY ENGINEER, THREAT DETECTION AT SNOWFLAKE, YOU WILL:

  • Develop and deploy detections using modern engineering practices (testing and validation, CI/CD pipelines, detections as code, and a full detection development lifecycle), spanning both rules-based and AI-assisted detections.

  • Mature our threat detection program by analyzing coverage gaps and mitigating risks through detective controls, experimenting with AI/ML approaches where they improve signal-to-noise ratio or analyst efficiency.

  • Make data-driven recommendations for detective and preventative controls based on threat models, proactive threat hunts, and data science-oriented exploration of logs and telemetry.

  • Design and build automations and AI-driven workflows that strengthen our security posture and reduce mean time to detect and respond.

  • Build and maintain strong partnerships with stakeholders to deliver detection as a service, including self-service patterns, reusable components, and AI-enhanced detections that support their domains.

  • Continuously measure and improve detection quality across coverage, precision and recall, false positive rate, and latency.

OUR IDEAL STAFF SECURITY ENGINEER WILL HAVE:

  • 8+ years of security engineering experience across one or more of threat detection, incident response, threat hunting, product security, or corporate security, or equivalent experience.

  • Strong coding ability in a high-level language such as Python or Go, with a track record of building software, data tooling, or automations, and a desire to apply those skills to AI/ML-powered detection and response.

  • Experience handling data programmatically (SQL, Python), ideally including large-scale log and telemetry datasets used for detection logic or analytics.

  • Experience writing production code, including unit tests, version control, and CI/CD integration.

  • Experience developing and operating agent-based or agentic workflows (for example, LangGraph or similar orchestration frameworks).

  • Hands-on experience with at least one major cloud provider (AWS, Azure, or GCP) and a solid understanding of its native logging, monitoring, and security services.

  • Familiarity with the risks that impact SaaS products and workstations, such as account compromise, data exfiltration, phishing, and supply chain attacks.

  • A risk-based approach that helps prioritize key security initiatives and judge when AI provides meaningful value over traditional rules and heuristics, paired with a humble, team-oriented mindset in a zero-ego environment.

BONUS POINTS FOR THE FOLLOWING:

  • Computer Science degree or equivalent practical experience.

  • Experience applying GenAI and LLM-based approaches to security workflows, such as detection engineering, alert triage, enrichment, or summarization.

  • Experience with infrastructure as code (Terraform, CloudFormation) and/or detections-as-code frameworks.

  • Experience building and maintaining production software or platforms that process high-volume data streams (logs, metrics, traces) or power security analytics.

  • Experience deploying detections at global scale.

  • Experience with Snowflake or equivalent cloud data platforms, including building data pipelines or analytics that support security workloads, and interest in Snowflake Cortex AI or similar in-platform AI capabilities.

WHY JOIN OUR SECURITY TEAM AT SNOWFLAKE?

We are laser focused on doing security in the agentic era, and we do not tolerate the status quo. We have strong demand from our customers and strong support from the business for security, which gives us both the mandate and the runway to invest in next-generation, AI-driven detection and response capabilities. You will join a team with a diverse set of backgrounds and skills, excited to add engineers who want to push the frontier of AI in security and solve threat detection at global scale, leveraging Snowflake's own data platform and AI capabilities to build detections and workflows that meaningfully raise the bar for defenders. And did we mention we are one of the fastest-growing software companies ever? The opportunity for impact, on both Snowflake and the broader security ecosystem, is enormous.

Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth. We are looking for people who share our values, challenge ordinary thinking, and push the pace of innovation while building a future for themselves and Snowflake.

How do you want to make your impact?

For jobs located in the United States, please visit the job posting on the Snowflake Careers Site for salary and benefits information: careers.snowflake.com

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
Β·

Security Engineer Related jobs

Other jobs at Snowflake

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.