Senior Cloud Security Engineer
About the role
BackOps AI is transforming supply chain operations with agentic AI solutions that automate complex workflows, freeing operations teams to focus on what matters most. Headquartered in the San Francisco Bay Area with flexible remote-friendly options, we foster a culture of innovation, ownership, and measurable impact.
Responsibilities
Design, build, and maintain robust cloud security controls across AWS/GCP infrastructure, Kubernetes, and serverless environments
Architect and implement fine-grained IAM policies, least privilege access models, and automated secrets management to minimize the attack surface
Develop and integrate automated security scanning and guardrails into CI/CD pipelines (SAST, DAST, and container vulnerability scanning)
Lead network security hardening, including VPC architecture, security groups, and cloud-native monitoring/alerting strategies
Operationalize vulnerability management and threat modeling for cloud-native applications and AI-driven workflows
Partner with engineering teams on secure development practices and provide technical guidance for securing complex AI agent architectures
Requirements
Experience: 5+ years in cloud security engineering, infrastructure security, or DevSecOps within a modern SaaS environment
Cloud Platforms: Deep technical proficiency in AWS and/or GCP, including networking, IAM, and managed services
DevSecOps & Automation: Proven experience with Infrastructure as Code (Terraform/CloudFormation) and automating security within CI/CD pipelines
Container Security: Strong understanding of securing containerized workloads and orchestration platforms like Kubernetes (EKS/GKE)
Risk Mindset: Strong judgment in identifying material risks, prioritizing remediation, and balancing speed with practical security outcomes
Communication: Can write clear policies, standards, procedures, risk summaries, and customer-facing responses; able to work effectively across technical and non-technical teams
Execution: You are organized, hands-on, and able to independently drive programs from requirement to implementation to review
Startup Fit: Comfortable operating in a fast-moving environment where you may define structure while also doing the work directly
Programming Proficiency: Strong coding skills in Python, Go, or a similar language to automate security tasks and interact with cloud APIs
Qualifications
Experience with Vanta, Drata, or similar compliance automation tooling
Experience supporting SOC 2 Type I/II, SOC 3, ISO 27001 certification, or similar audits end-to-end
Familiarity with cloud environments such as AWS and/or GCP
Experience with vendor risk management, security questionnaires, and enterprise customer diligence workflows
Familiarity with privacy operations and data governance practices in B2B SaaS environments
Experience with security awareness programs, endpoint/device management, or identity lifecycle management
Exposure to secure SDLC, application security reviews, or vulnerability management programs
Experience working in AI, automation, or operationally sensitive product environments
Skills
Strong coding skills in Python, Go, or a similar language to automate security tasks and interact with cloud APIs
Benefits
Equity & Ownership: Competitive equity so you grow alongside the company
Impact & Visibility: Direct access to leadership; your work directly improves customer trust and company readiness
Collaborative Culture: Tight-knit team of seasoned operators and AI experts
Flexible Work: Hybrid with core Bay Area presence and remote flexibility
Pay
TBD
Schedule
Flexibility