Senior Engineer II, Cloud Security
Lila Sciences · Cambridge, Massachusetts, United States · $108K–$163K/yr
Technology, Information and Internet · 201-500 employees
About the role
The Senior Engineer will own cloud and SaaS security posture management, including configuring tooling and driving remediation across infrastructure. They will also lead incident response efforts and design security guardrails to prevent insecure deployments while maintaining developer velocity.
What they look for
Requirements
Candidates must have extensive hands-on experience in information security with deep expertise in AWS security and cloud-native workload protection. Proficiency in scripting, automation, and translating technical risk into actionable business outcomes is essential for this role.
Benefits
Full description
Your Impact at LILA
Lila is hiring a Senior Engineer II, Cloud Security to strengthen cloud and SaaS security across our infrastructure, platforms, and AI-enabled systems. This role owns hands-on security work across cloud posture management, detection and response, container and workload security, identity and privileged access, and security automation.
This role sits within IT & Security and partners closely with infrastructure, platform, data, DevSecOps, and AI teams. The person in this role will turn cloud and SaaS security findings into prioritized remediation work, build guardrails that reduce risk before deployment, and improve Lila’s ability to detect and respond to threats.
The ideal candidate brings deep cloud security experience, strong operational judgment, and the ability to translate technical risk into clear action across engineering and security stakeholders.
What You'll Be Building
- Own cloud and SaaS security posture management across AWS, IaaS/PaaS, and core SaaS platforms.
- Configure, operate, and tune CSPM, CNAPP, and SSPM tooling to surface and prioritize risk.
- Partner with infrastructure and platform teams to drive remediation of cloud, SaaS, and workload findings.
- Build and tune high-fidelity detections across SIEM, EDR, CSPM, and related security systems.
- Lead incident response triage, containment, recovery, and post-incident review for cloud security events.
- Strengthen cloud-native workload and container security across AWS, Kubernetes, hardened AMIs, and network controls.
- Design policy-as-code and guardrails that prevent insecure deployments without slowing developer velocity.
- Partner with AI, data, and platform teams to mature security controls for MLOps pipelines and AI-enabled platforms.
What You'll Need to Succeed
- Extensive hands-on experience in information security, with deep cloud and SaaS security ownership.
- Strong AWS security knowledge, including IAM, SCPs, VPC/networking, KMS, CloudTrail, GuardDuty, Security Hub, and Config.
- Hands-on experience with CSPM or CNAPP tooling such as Wiz or comparable platforms.
- Experience operating detection and response workflows across SIEM, EDR, CSPM, or related security tooling.
- Practical incident response experience, including triage, containment, recovery, and post-incident review.
- Strong understanding of workload, container, and Kubernetes security.
- Proficiency with scripting and automation using Python, PowerShell, Bash, or similar tools.
- Experience securing infrastructure-as-code and CI/CD workflows using Terraform, CloudFormation, ARM, OPA, Sentinel, or native cloud policies.
- Strong grasp of IAM, identity federation, least-privilege access, SaaS permission models, and privileged access management practices.
- Ability to translate technical findings into business risk and partner cross-functionally with cloud, DevOps, AppSec, and platform teams.
Bonus Points For
- Deep experience securing MLOps pipelines, AI-enabled platforms, or AI Security Posture Management practices.
- Experience with Azure-native security services, including Defender for Cloud.
- Depth in CWPP, EDR/XDR, SOAR, or DSPM tooling.
- Experience supporting SOC 2, ISO 27001, HIPAA, FedRAMP, PCI-DSS, or similar compliance programs.
- Certifications such as CISSP, CCSP, AWS Security, Azure Security, GCIH, GCFA, GCDA, or OSCP.
Compensation
We offer competitive base compensation with bonus potential and generous early-stage equity. Your final offer will reflect your background, expertise, and expected impact.
U.S. Benefits. Full-time U.S. employees receive a comprehensive benefits program including medical, dental, and vision coverage; employer-paid life and disability insurance; flexible time off with generous company wide holidays; paid parental leave; an educational assistance program; commuter benefits, including bike share memberships for office based employees; and a company subsidized lunch program.
International Benefits. Full-time employees outside the U.S. receive a comprehensive benefits program tailored to their region. USD salary ranges apply only to U.S.-based positions; international salaries are set to local market.
Expected Base Salary Range
$108,000—$163,333 USD
About LILA
Lila Sciences is building Scientific Superintelligence™ to solve humankind's greatest challenges. We believe science is the most inspiring frontier for AI. Rather than hard-coding expert knowledge into tools, LILA builds systems that can learn for themselves.
LILA combines advanced AI models with proprietary AI Science Factory™ instruments into an operating system for science that executes the entire scientific method autonomously, accelerating discovery at unprecedented speed, scale, and impact across medicine, materials, and energy. Learn more at www.lila.ai.
Guided by our core values of truth, trust, curiosity, grit, and velocity, we move with startup speed while tackling problems of historic importance. If this sounds like an environment you'd love to work in, even if you don't meet every qualification listed above, we encourage you to apply.
We’re All In
Lila Sciences is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status.
Information you provide during your application process will be handled in accordance with our Candidate Privacy Policy.
A Note to Agencies
Lila Sciences does not accept unsolicited resumes from any source other than candidates. The submission of unsolicited resumes by recruitment or staffing agencies to Lila Sciences or its employees is strictly prohibited unless contacted directly by Lila Science’s internal Talent Acquisition team. Any resume submitted by an agency in the absence of a signed agreement will automatically become the property of Lila Sciences, and Lila Sciences will not owe any referral or other fees with respect thereto.