Staff Security Engineer, Cloud & AI Platform

🏢 Brookfield Asset Management · all Brookfield Asset Management jobs
📍 United States
📅 Posted 2026-09-03 · via Himalayas
🏷 Cloud-Security-Engineering,Security-Architecture,AI-Security,Platform-Engineering,DevSecOps,Cloud-Security-Engineer,Staff-Security-Engineer,Senior-Cloud-Infrastructure-Security-Engineer,Platform-Security-Engineer,Senior-Cloud-Security-Software-Engineer,Sr.-Infrastructure-Security-Engineer,Senior-Cloud-Security-Architect,Security-Platform-Engineer,Security-Engineer
Apply on original site ↗

Location
US TN - Remote Business - Real Estate

Brookfield Real Estate Group is one ofBrookfield’s primary operating groups. The Real Estate Group is one of the world's largest investors in real estate, with a global portfolio that includes office, retail, multifamily, logistics, hospitality and alternative real estate assets on five continents. The Group owns and operates approximately $268 billion of assets representing the most iconic properties in the world’s most dynamic markets. We seek to generate value by leveraging our operating expertise and focusing on our core real estate capabilities of leasing, financing, development, design and construction as well as property and facilities management. For more information, visit .
Brookfield Culture

Brookfield has a unique and dynamic culture. We seek team members who have a long-term focus and whose values align with our Attributes of a Brookfield Leader: Entrepreneurial, Collaborative and Disciplined. Brookfield is committed to the development of our people through challenging work assignments and exposure to diverse businesses.
Job Description

The Staff Security Engineer, Cloud & AI Platform is a deeply technical, hands-on role responsible for making Brookfield Real Estate’s cloud and AI platforms secure by design. You will lead security architecture and implementation across AWS, Infrastructure as Code, software delivery, internally developed applications, and AI/agent systems.

This is a builder role. You will threat-model a design, review the underlying Terraform and application code, implement the control, instrument it, and help teams adopt it without unnecessary friction. Security requirements become reusable modules, automated checks, secure defaults, and clear engineering guidance rather than documents and findings lists.

You will partner closely with Cloud Solutions, application engineering, AI engineering, Identity, CyberOps, and GRC/Privacy. Platform engineering continues to own general platform uptime, capacity, and deployment mechanics, and CyberOps continues to own alert triage; this role owns the architecture, controls, tooling, and assurance mechanisms that make those systems safe.
Role & Responsibilities:

Leadership & Security Architecture

-
Help define security architecture for the cloud and AI platforms: set direction, write specs, and steward secure-by-default patterns across teams

-
Define security engineering standards and paved roads, document important decisions, and communicate risk and trade-offs to engineering and business leadership

-
Review infrastructure and application designs for authorization, network, data-protection, secrets, and tenant-isolation risks

-
Mentor engineers and raise the organization’s ability to make sound security decisions independently

-
Partner with Cloud Solutions, application engineering, AI engineering, Identity, CyberOps, and GRC/Privacy to prioritize work and drive adoption

Cloud & Identity Security

-
Own and evolve security architecture for a multi-account AWS organization — account boundaries, service control policies, IAM Identity Center, delegated security services, KMS, VPC controls, and WAF

-
Design least-privilege human and workload access across AWS, Okta, GitHub Actions, and Infrastructure as Code platforms using federation and short-lived credentials

-
Build and maintain reusable security controls in Terraform or OpenTofu, with safe rollout, testing, monitoring, and recovery patterns

-
Strengthen centralized logging and evidence — CloudTrail, Config, GuardDuty, Security Hub, Macie, and CloudWatch — and keep guardrails current as the environment grows

Secure Software Delivery

-
Establish secure GitHub Actions and runner patterns, including OIDC trust, environment separation, workflow protection, action pinning, artifact integrity, and least-privilege deployment roles

-
Integrate practical security checks into developer workflows — secrets detection, dependency and containe

← All remote jobs

Similar for you