GRAIL is seeking a mission-driven and high-impact Staff Cloud Security Engineer to help secure the cloud platforms that power one of healthcare's most innovative early cancer detection technologies. Reporting to the Director of Product Security, this role serves as a technical leader responsible for shaping cloud security strategy, enabling secure product delivery, and helping protect the systems that support GRAIL's life-saving mission.
As a Staff-level individual contributor, you will lead the technical execution of the Cloud Security roadmap, partnering closely with Engineering, Platform, Infrastructure, DevOps, and Product teams to drive secure cloud transformation initiatives. You will provide guidance to other engineers while influencing cloud architecture, DevSecOps practices, and secure development decisions across the product and infrastructure lifecycle.
This role will help teams navigate an evolving threat landscape by implementing scalable AWS security controls, automation, and cloud-native security best practices while maintaining engineering agility and delivery velocity in a highly regulated environment.
This role is based in Menlo Park, California, and will move to Sunnyvale, California in Fall 2026. GRAIL offers a flexible work arrangement, with the ability to work from GRAIL's office or from home. Our current flexible work arrangement policy requires that a minimum of 60%, or 24 hours, of your total work week be on-site. Your specific schedule, determined in collaboration with your manager, will align with team and business needs and could exceed the 60% requirement for the site.
Responsibilities
Lead the design, implementation, and continuous improvement of cloud security architectures across AWS environments, ensuring product security, and secure-by-design principles throughout the infrastructure and application lifecycle.
Partner with Platform, and Cloud Engineering team to design, implement, and manage AWS-native security services including IAM, KMS, GuardDuty, Security Hub, Inspector, Macie, WAF, Shield, CloudTrail, Config, and CloudWatch for proactive threat detection and risk management.
Develop and enforce cloud security standards, guardrails, and governance frameworks across AWS accounts, containers, Kubernetes/EKS, serverless, and hybrid cloud workloads.
Automate security monitoring, compliance validation, vulnerability management, and incident response workflows using Infrastructure as Code (IaC), scripting, and cloud-native automation tools.
Conduct cloud threat modeling, architecture risk assessments, and security reviews for AWS-hosted applications, APIs, infrastructure, and enterprise-integrated systems.
Secure DevOps platforms and cloud-native application environments by implementing least-privilege access controls, secrets management, secure network segmentation, encryption, and workload protection.
Manage and enhance continuous cloud security posture management (CSPM), container security, and runtime protection capabilities across AWS environments.
Scope, coordinate, and review penetration testing, vulnerability assessments, and advanced security testing activities across cloud infrastructure, applications, and DevOps tooling.
Serve as a cloud security subject matter expert during security incidents, forensic investigations, root cause analysis, and remediation activities.
Partner with Engineering, Platform, Infrastructure, Compliance, and Product teams to align cloud security strategies with regulatory, privacy, and industry cybersecurity requirements.
Define, track, and report cloud security metrics, operational KPIs, and compliance status to provide visibility into organizational security posture and risk trends.
Mentor and guide engineers on AWS security best practices, DevSecOps methodologies, automation strategies, and secure cloud engineering principles to strengthen organizational security maturity at GRAIL.
These responsibilities summarize the role’s primary responsibilities and are not an exhaustive list. They may change at the company’s discretion.
Required Qualifications
8+ years of experience in product security, cybersecurity, Cloud Security, application security, or related technical security roles.
Hands-on experience leading threat modeling, security risk assessments, and vulnerability management for complex software products.
Experience embedding security into modern software development environments, including CI/CD and DevSecOps practices.
Experience supporting security incident response and conducting root cause analysis in production environments.
Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent practical experience.
GRAIL Values & Leadership Expectations
This Staff-level role is expected to model GRAIL’s core values and LEAD leadership attributes by leading through influence, collaborating across boundaries, driving results with integrity, and continuously improving how product security enables patient impact.
Preferred Qualifications
Experience working in regulated environments, including medical devices, healthcare, life sciences, or similarly regulated industries.
Knowledge of relevant standards and frameworks such as IEC 62304, ISO 14971, ISO 80001-2, NIST, and FDA pre‑ and post‑market cybersecurity guidance.
Experience securing AI/ML systems, including mitigating risks such as data poisoning, model manipulation, and unauthorized access.
Demonstrated experience delivering cybersecurity programs, including tabletop exercises and cross‑functional incident simulations.
Professional security and cloud certifications such as AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional/Associate, OSCP, GPEN, GCIH, GWAPT, CISSP, CCSP, or equivalent certifications preferred.
Strong ability to translate technical security risks into business and patient-impact considerations for senior stakeholders.
Experience working with globally distributed teams or international stakeholders.
Physical Demands and Working Environment
Ability to work in an office and remote environment under a flexible hybrid arrangement.
Occasional travel may be required based on business needs.
The expected, full-time, annual base pay scale for this position is $169kK-$224K
GRAIL Menlo Park, California, USA Office

GRAIL is headquartered in Menlo Park, California, with locations in Washington, D.C., North Carolina, and the United Kingdom. We also have a number of employees who are working remotely. Our bay area office has a employees working in our labs, software engineering, clinical development and more.
Similar Jobs at GRAIL
What you need to know about the San Francisco Tech Scene
Key Facts About San Francisco Tech
- Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Google, Apple, Salesforce, Meta
- Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
- Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
- Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine



.png)