Senior Red Team Engineer
Job Description
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. The Red Team in the Security Foundations org is responsible for conducting security assessments against Snowflake’s diverse cloud environment and finding vulnerabilities in software, systems, and networks. In this role, you will execute security assessments across Snowflake’s corporate and product environments. You will partner with cross-functional teams to communicate gaps discovered during engagements and help drive remediation. You will develop tools, perform security research, and build infrastructure to augment the Red Team’s capabilities. Our ideal candidate wakes up each morning thinking about different parts of the business that can benefit from security assessments. Their goal is to identify relevant security risks and help the business understand them so they can build effective defenses and protect Snowflake customers and their data. RESPONSIBILITIES - Develop tools, methodologies, and infrastructure to support Red Team engagements in a variety of cloud environments and novel platforms - Participate in security assessments against a diverse cloud environment and find vulnerabilities in software, systems, and networks - Set scope, objectives, and timelines for security assessments and leverage data to create meaningful metrics - Work with security and engineering teams to communicate findings, recommendations, and knowledge to key stakeholders - Play a critical role in building a Red Team that has a wide scope and impact MINIMUM QUALIFICATIONS - 4+ years experience working in an information security discipline, preferably with a focus in offensive security - You have a continuously learning mindset with a desire to dive and explore a wide range of security domains - Strong communications skills to comfortably work cross-functionally across the organization - Ability to document findings from engagements and create a narrative for technical and executive audiences - Knowledge of common bugs or misconfigurations in software and cloud infrastructure (AWS, GCP, and Azure) - Experience reading and writing code in one of the following languages: - Golang, Python, Java, JavaScript, C++, C PREFERRED QUALIFICATIONS - 6+ years experience working in an information security discipline, preferably with a focus in offensive security - Prior experience executing Red Teams in a high growth, cloud native technology company - Contributions to the security community, such as open source tools, research, papers, conference talks, etc.
- You can demonstrate a strong background in one of the following languages: - Golang, Python, Java, JavaScript, C++, C Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth.
How to Stand Out
- Show AI‑augmented threat modeling: In your résumé and interview, detail a recent red‑team engagement where you used LLM‑based tools (e.g., Prompt‑Engineered ChatGPT, Claude, or open‑source models) to generate exploit hypotheses, automate credential‑dump parsing, or prioritize attack paths. Bring a 1‑page “AI‑Assist Playbook” that lists the prompts, model version, and measurable time‑savings (e.g., 30% faster pivot identification).
- Demonstrate Snowflake‑specific cloud expertise: Prepare a short (5‑minute) demo or slide deck of a penetration test you performed on a multi‑tenant Snowflake environment—highlighting data‑sharing misconfigurations, misuse of Snowflake’s external functions, or privilege‑escalation via ROLE hierarchy. Include CloudTrail/CloudWatch logs, SnowSQL queries you crafted, and the remediation steps you recommended.
- Build a concise, reproducible Red Team artifact repo: Create a public GitHub (or private with a share link) containing modular scripts/tools you authored for cloud‑native attack surfaces (e.g., Terraform‑based infrastructure “kill‑chain” generators, PowerShell‑encoded payloads, or custom Snowflake UDF exploit code). Ensure each repo has a README that explains the problem, the AI‑driven approach, and results, and reference it in your application.
- Prepare for the “low‑ego, experimental mindset” interview: Expect scenario‑based questions where interviewers will ask you to iterate on a partially‑failed exploit in real time. Practice thinking aloud, proposing at least three alternative hypotheses, and explicitly referencing how you would A/B test a new AI‑generated payload versus a classic technique. Highlight willingness to discard ideas quickly when evidence disproves them.
- Negotiate with data‑driven compensation insight: Research recent Snowflake senior engineering offers (e.g., base salary $190–210 k + RSU grant 0.1–0.2% of total equity, remote‑work stipend). In your negotiation email, reference specific market benchmarks (Radford, Levels.fyi) and tie your AI‑augmented red‑team results to quantifiable business impact (e.g., “identified 3 critical misconfigurations that could have exposed $50 M in data assets”). This shows you understand Snowflake’s value‑based compensation philosophy.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.