Lead design and implementation of cloud security controls across AWS/GCP, Kubernetes, and serverless environments. Harden infrastructure, automate IAM and secrets management, integrate security scanning into CI/CD, operationalize vulnerability management and threat modeling, and partner with engineering to embed DevSecOps practices across AI-driven workflows.
BackOps AI is transforming supply chain operations with agentic AI solutions that automate complex workflows, freeing operations teams to focus on what matters most. Headquartered in the San Francisco Bay Area with flexible remote-friendly options, we foster a culture of innovation, ownership, and measurable impact.
As a Cloud Security Engineer, you will lead the technical design and implementation of security controls across our cloud infrastructure and platform. You will work at the intersection of engineering and DevOps to build resilient architectures, automate security guardrails, and secure our cloud-native services. This is a hands-on technical role for someone who can drive DevSecOps practices and take direct ownership of our security posture in a fast-paced AI environment.
In this role, you will be the primary technical owner for cloud security, focusing on infrastructure hardening, container security, and automated response. While you will support our compliance goals, your core mission is building and maintaining the technical safeguards that protect our platform and customer data.
- Design, build, and maintain robust cloud security controls across AWS/GCP infrastructure, Kubernetes, and serverless environments
- Architect and implement fine-grained IAM policies, least privilege access models, and automated secrets management to minimize the attack surface
- Develop and integrate automated security scanning and guardrails into CI/CD pipelines (SAST, DAST, and container vulnerability scanning)
- Lead network security hardening, including VPC architecture, security groups, and cloud-native monitoring/alerting strategies
- Operationalize vulnerability management and threat modeling for cloud-native applications and AI-driven workflows
- Partner with engineering teams on secure development practices and provide technical guidance for securing complex AI agent architectures
- Experience: 5+ years in cloud security engineering, infrastructure security, or DevSecOps within a modern SaaS environment
- Cloud Platforms: Deep technical proficiency in AWS and/or GCP, including networking, IAM, and managed services
- DevSecOps & Automation: Proven experience with Infrastructure as Code (Terraform/CloudFormation) and automating security within CI/CD pipelines
- Container Security: Strong understanding of securing containerized workloads and orchestration platforms like Kubernetes (EKS/GKE)
- Risk Mindset: Strong judgment in identifying material risks, prioritizing remediation, and balancing speed with practical security outcomes
- Communication: Can write clear policies, standards, procedures, risk summaries, and customer-facing responses; able to work effectively across technical and non-technical teams
- Execution: You are organized, hands-on, and able to independently drive programs from requirement to implementation to review
- Startup Fit: Comfortable operating in a fast-moving environment where you may define structure while also doing the work directly
- Programming Proficiency: Strong coding skills in Python, Go, or a similar language to automate security tasks and interact with cloud APIs.
- Experience with Vanta, Drata, or similar compliance automation tooling
- Experience supporting SOC 2 Type I/II, SOC 3, ISO 27001 certification, or similar audits end-to-end
- Familiarity with cloud environments such as AWS and/or GCP
- Experience with vendor risk management, security questionnaires, and enterprise customer diligence workflows
- Familiarity with privacy operations and data governance practices in B2B SaaS environments
- Experience with security awareness programs, endpoint/device management, or identity lifecycle management
- Exposure to secure SDLC, application security reviews, or vulnerability management programs
- Experience working in AI, automation, or operationally sensitive product environments
- Our controls are not just documented they are actually operating, measurable, and sustainable
- Audit readiness improves with less scramble and clearer ownership
- Security and compliance become embedded into engineering and business workflows instead of bolted on later
- Enterprise customers gain confidence in our maturity through strong security posture and clear responses
- Risk is identified earlier, prioritized better, and remediated faster
- Equity & Ownership: Competitive equity so you grow alongside the company
- Impact & Visibility: Direct access to leadership; your work directly improves customer trust and company readiness
- Collaborative Culture: Tight-knit team of seasoned operators and AI experts
- Flexible Work: Hybrid with core Bay Area presence and remote flexibility
BackOps AI San Francisco, California, USA Office
San Francisco, CA, United States
BackOps AI San Ramon, California, USA Office
San Ramon, United States
Similar Jobs
Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Leads teams designing and deploying AI-driven enterprise and cloud security solutions. Responsibilities include developing machine learning systems, integrating data infrastructure and pipelines, performing advanced modeling and analysis, and building AI applications with Python, Java, and C++. The role involves client engagement, strategic problem-solving, stakeholder validation, coaching, process innovation, and operational excellence while addressing complex cybersecurity and privacy challenges.
Top Skills:
Ai SystemsAWSC++Cloud SecurityData EngineeringData PipelinesDatabricksGCPJavaMachine LearningAzurePythonScikit-LearnSnowflakeTensorFlow
Artificial Intelligence • Computer Vision • Hardware • Robotics • Metaverse
Lead the design, deployment, and operation of network security infrastructure across hybrid on-premise and multi-cloud environments. Manage firewalls, load balancers, IDS/IPS, IAM controls, monitoring, vulnerability remediation, compliance, and incident response. Partner with architecture, security, and operations teams to improve observability, threat detection, resilience, and operational readiness across hyperscale networks.
Top Skills:
AristaAWSAzureBgpCiscoClaude CodeCumulus OsCursorFortigateFortimanagerGCPGrafanaIds/IpsIs-IsMellanoxOciOspfPythonShell ScriptingSplunkVrfsVxlan
Fintech • Financial Services
Own AWS cloud security posture and vulnerability management using Wiz and AWS-native services. Build Infrastructure as Code guardrails, secure CI/CD pipelines, automate vulnerability workflows, and operate WAF protections. Partner with DevOps and engineering on IAM, network segmentation, containers, secrets, data exposure, telemetry, threat modeling, and application security. Drive projects independently while reducing organizational risk.
Top Skills:
AWSAws Secrets ManagerCi/CdCloudflareContainer OrchestrationGithub Advanced SecurityGoIamInfisicalInfrastructure As CodeKeeperOwasp Top 10PythonRuby On RailsSpaceliftTerraformWafWiz
What you need to know about the San Francisco Tech Scene
San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.
Key Facts About San Francisco Tech
- Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Google, Apple, Salesforce, Meta
- Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
- Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
- Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine



