Shopify logo

Staff Security Engineer, Infrastructure Security

Shopify
Posted 7 hours ago
Latin America, North AmericaRemoteEngineering & Development
Is this job info correct?

Shopify is looking for a Staff Security Engineer to lead the security of cloud infrastructure and production runtimes at scale. You’ll set direction across cloud platforms, infrastructure as code, identity and access management, and Kubernetes—reducing risk while helping engineering teams ship quickly and securely. Our mission is to proactively defend Shopify’s production runtimes and build scalable, reproducible security solutions.

About you

You’ll be effective in this role if you’re comfortable navigating ambiguity, exercising independent judgment, and turning complex security problems into practical, scalable solutions. You communicate clearly with technical and non-technical partners and engage constructively with disagreement.

Your Key Areas of Ownership

  • Cloud and infrastructure security posture — Set direction for securing Shopify’s production runtimes at scale, identify meaningful gaps in our security posture, and drive measurable risk reduction. Use data to quantify control effectiveness, detection outcomes, and engineering velocity, then use those signals to set priorities and communicate progress.

  • Scalable security controls and operational readiness — Build, operate, and validate controls that reduce manual work and unnecessary complexity; lead threat hunts, tabletop exercises, and post-incident reviews, turning findings into improved playbooks and repeatable practices.

  • Cross-company security leadership — Trailblaze Shopify’s approach to emerging cloud and infrastructure security risks, represent the domain in cross-company strategy, and set the pace for secure delivery while raising the bar for the security discipline.

You Will

  • Identify material gaps in cloud-security capabilities, provide architectural guidance and security reviews, and drive prioritized remediation from proposal through adoption.

  • Design, implement, and validate infrastructure security controls in production; turn recurring guidance into reusable, self-service patterns, tooling, and documentation.

  • Initiate complex security projects, involve stakeholders at the appropriate level, ship iteratively, and prioritize high-leverage improvements.

  • Maintain meticulous documentation for security controls, architecture decisions, incident learnings, and playbooks so teams can operate and improve systems without losing context.

  • Stay ahead of changes in the threat landscape, perform threat hunts, research emerging technologies, and translate findings into practical improvements.

  • Communicate security concepts and tradeoffs clearly to technical partners, non-technical stakeholders, and senior leadership.

  • Mentor engineers through pairing, code reviews, technical guidance, and knowledge sharing.

To Be Successful

  • You have been a technical security leader in a large-scale, complex, cloud-based environment and can use analytical and data-literacy skills to shape a security roadmap.

  • You have deep expertise securing cloud infrastructure at scale, with experience applying security principles to infrastructure as code, identity and access management, and Kubernetes environments.

  • You have designed and operated infrastructure security controls from implementation through production adoption, and can measure their effectiveness.

  • You have experience building and operating production security tooling, with fluency in at least one programming language and the ability to work effectively with infrastructure as code, cloud APIs, and Kubernetes configuration.

  • You can assess attack surfaces as an adversary would and use proactive techniques to build detections and close gaps before they are exploited.

  • You have a track record of independently delivering complex security initiatives, influencing senior stakeholders, and integrating security roadmaps with broader company priorities.

  • You can collaborate across teams during high-stress situations, manage competing priorities, and use good judgment to establish order.

  • You use AI reflexively to accelerate cloud-risk analysis, infrastructure-as-code review, security-control design, and scalable infrastructure-security solutions—applying sound judgment to validate its outputs.

  • You demonstrate a strong sense of accountability: taking responsibility for the quality, adoption, and outcomes of security controls and initiatives, surfacing risks early, and driving them to resolution.

Nice to Have

  • Familiarity with application-security practices and security threats related to e-commerce.

Similar jobs