Senior Security Engineer
CSC Generation · San Jose, CA · Today
HybridInformation TechnologyFull-time
About the role
Backcountry needs a senior security engineer to protect and harden the multi-cloud platforms, Kubernetes workloads, and CI/CD pipelines that power its digital commerce ecosystem. The role spans AWS, GCP, Azure Entra ID, Microsoft Defender XDR, and GitOps tooling — with a growing mandate to govern secure AI adoption across engineering and business teams.
Within your first six months, you will have measurably improved pipeline security posture, tightened identity and access controls, and established governance guardrails for AI tooling.
Responsibilities
- Protect and monitor infrastructure hosted in AWS and GCP; configure and maintain AWS WAF/CDN and GCP Cloud Armor rules;
- Review Infrastructure as Code for security best practices;
- Secure containerized workloads across EKS and GKE clusters; implement Istio mesh policies (mTLS, authorization, traffic controls); manage GitOps delivery security through ArgoCD (RBAC, secrets, drift detection);
- Integrate security into CI/CD pipelines using GitHub Actions; manage dependency and supply-chain risk via Dependabot; collaborate with engineering teams on secure development practices;
- Administer and secure Azure Entra ID and SSO configurations; enforce least-privilege access across cloud, Kubernetes, and SaaS platforms; conduct periodic access reviews;
- Manage Microsoft Defender XDR for endpoint and identity security; monitor alerts, investigate incidents, and lead incident response efforts across cloud, Kubernetes, and identity layers;
- Secure the Microsoft 365 environment (Exchange Online, SharePoint, OneDrive, Teams); implement Data Loss Prevention (DLP) policies and email security controls;
- Define and enforce secure baselines for Linux and Windows VMs, including patching, configuration management, and vulnerability remediation;
- Evaluate and govern the secure use of AI tools (Claude, OpenAI) and automation platforms (n8n) across the organization, including data handling, access controls, and leakage risks.
Requirements
- 5+ years of experience in SecDevOps, Cybersecurity, or related roles;
- Hands-on, production-level experience with AWS and GCP security configurations;
- Practical AI experience with tools such as Claude, OpenAI, or similar in production or automation workflows;
- Demonstrated experience managing Kubernetes and containerized workloads;
- Demonstrated experience in at least 3 of the following: Identity and Access Management (Azure Entra ID, SSO); service mesh technologies (Istio or similar); GitOps tooling (ArgoCD or similar); Endpoint Detection and Response (EDR) / XDR solutions; OAuth, OIDC, SSO; IaC (Terraform preferred) and Git/GitHub workflows;
- Solid understanding of networking fundamentals (TCP/IP, DNS, firewalls, VPNs);
- Scripting and automation skills (Python, PowerShell, or Bash);
- Strong analytical, problem-solving, and communication skills;
Preferred Qualifications
- Security certifications such as CISSP, CISM, AWS Security Specialty, GCP Security Engineer, CKS, SC-200, OSCP, or CEH;
- Background in compliance frameworks (SOC 2, ISO 27001, PCI-DSS, GDPR);
- Experience with workflow-automation platforms such as n8n.