Senior Cloud Security Engineer

Theory Ventures

San Francisco (CA)

On-site

USD 150,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity & Ownership
Impact & Visibility
Collaborative Culture
Flexible Work

Job summary

The Theory Ventures team is seeking a Cloud Security Engineer to own security across our cloud and AI-enabled platform. You will shape security controls, design resilient cloud architectures, and drive guardrails in a fast-paced environment.

You will partner with engineering to implement secure development practices, automate vulnerability management, and manage identity and access across AWS/GCP, Kubernetes, and serverless services. This role is hands-on and impact-driven.

Qualifications

  • 4+ years of cloud security engineering or DevSecOps experience.
  • Deep proficiency in AWS and/or GCP, including networking and IAM.
  • Experience with Infrastructure as Code (Terraform/CloudFormation) and automating security in CI/CD pipelines.
  • Strong container security for Kubernetes (EKS/GKE) workloads.
  • Strong risk judgment to prioritize remediation and balance speed with security outcomes.
  • Ability to write clear policies, standards, and risk summaries for technical and non-technical audiences.
  • Hands-on, organized, and able to drive programs from requirement to implementation.
  • Experience in AI/automation security within a SaaS environment.

Responsibilities

  • Design, build, and maintain cloud security controls across AWS/GCP, Kubernetes, and serverless.
  • Architect IAM policies with least privilege and automated secrets management.
  • Integrate automated security scanning into CI/CD (SAST/DAST and container scans).
  • Lead network security hardening, including VPCs, security groups, and monitoring.
  • Operationalize vulnerability management and threat modeling for cloud-native apps and AI workflows.
  • Collaborate with engineering on secure development practices and secure AI architectures.

Skills

Cloud security engineering
DevSecOps
Python
Go
Communication

Tools

Terraform
CloudFormation
Kubernetes
AWS
GCP

Job description

Location: San Francisco

Job type: Full-time

Work arrangement: In office

BackOps AI is transforming supply chain operations with agentic AI solutions that automate complex workflows, freeing operations teams to focus on what matters most. Headquartered in the San Francisco Bay Area with flexible remote-friendly options, we foster a culture of innovation, ownership, and measurable impact.

Role Overview

As a Cloud Security Engineer, you will lead the technical design and implementation of security controls across your cloud infrastructure and platform. You will work at the intersection of engineering and DevOps to build resilient architectures, automate security guardrails, and secure your cloud-native services. This is a hands-on technical role for someone who can drive DevSecOps practices and take direct ownership of our security posture in a fast-paced AI environment.

In this role, you will be the primary technical owner for cloud security, focusing on infrastructure hardening, container security, and automated response. While you will support our compliance goals, your core mission is building and maintaining the technical safeguards that protect our platform and customer data.

What You’ll Do
  • Design, build, and maintain robust cloud security controls across AWS/GCP infrastructure, Kubernetes, and serverless environments
  • Architect and implement fine-grained IAM policies, least privilege access models, and automated secrets management to minimize the attack surface
  • Develop and integrate automated security scanning and guardrails into CI/CD pipelines (SAST, DAST, and container vulnerability scanning)
  • Lead network security hardening, including VPC architecture, security groups, and cloud-native monitoring/alerting strategies
  • Operationalize vulnerability management and threat modeling for cloud-native applications and AI-driven workflows
  • Partner with engineering teams on secure development practices and provide technical guidance for securing complex AI agent architectures
What We’re Looking For
  • Experience: 4+ years in cloud security engineering, infrastructure security, or DevSecOps within a modern SaaS environment
  • Cloud Platforms: Deep technical proficiency in AWS and/or GCP, including networking, IAM, and managed services
  • DevSecOps & Automation: Proven experience with Infrastructure as Code (Terraform/CloudFormation) and automating security within CI/CD pipelines
  • Container Security: Strong understanding of securing containerized workloads and orchestration platforms like Kubernetes (EKS/GKE)
  • Risk Mindset: Strong judgment in identifying material risks, prioritizing remediation, and balancing speed with practical security outcomes
  • Communication: Can write clear policies, standards, procedures, risk summaries, and customer-facing responses; able to work effectively across technical and non-technical teams
  • Execution: You are organized, hands-on, and able to independently drive programs from requirement to implementation to review
  • Startup Fit: Comfortable operating in a fast-moving environment where you may define structure while also doing the work directly
  • Programming Proficiency: Strong coding skills in Python, Go, or a similar language to automate security tasks and interact with cloud APIs.
Nice to Have
  • Experience with Vanta, Drata, or similar compliance automation tooling
  • Experience supporting SOC 2 Type I/II, SOC 3, ISO 27001 certification, or similar audits end-to-end
  • Familiarity with cloud environments such as AWS and/or GCP
  • Experience with vendor risk management, security questionnaires, and enterprise customer diligence workflows
  • Familiarity with privacy operations and data governance practices in B2B SaaS environments
  • Experience with security awareness programs, endpoint/device management, or identity lifecycle management
  • Exposure to secure SDLC, application security reviews, or vulnerability management programs
  • Experience working in AI, automation, or operationally sensitive product environments
What Success Looks Like
  • Our controls are not just documented they are actually operating, measurable, and sustainable
  • Audit readiness improves with less scramble and clearer ownership
  • Security and compliance become embedded into engineering and business workflows instead of bolted on later
  • Enterprise customers gain confidence in our maturity through strong security posture and clear responses
  • Risk is identified earlier, prioritized better, and remediated faster
What We Offer
  • Equity & Ownership: Competitive equity so you grow alongside the company
  • Impact & Visibility: Direct access to leadership; your work directly improves customer trust and company readiness
  • Collaborative Culture: Tight-knit team of seasoned operators and AI experts
  • Flexible Work: Hybrid with core Bay Area presence and remote flexibility
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer
Senior Cloud Security Engineer

BackOps AI • San Francisco (CA)

Hybrid
USD 150,000 - 210,000
Hybrid work model
Remote-friendly options
Equity opportunity
Senior Security Engineer, Platforms & AI
Senior Security Engineer, Platforms & AI

Triwill Group • United States

On-site
USD 140,000 - 200,000
Remote-first
Competitive salary
Unlimited PTO
+2
Cloud Security Engineer
Cloud Security Engineer

Braintrust • San Francisco (CA)

On-site
USD 130,000 - 180,000
Medical, dental, and vision insurance
Daily lunch, snacks, and beverages
Flexible time off
+2
Senior Security Engineer – Hybrid (4649)
Senior Security Engineer – Hybrid (4649)

Hireclout • Los Angeles (CA)

On-site
USD 180,000 - 200,000
Competitive compensation package
Equity participation
100% covered medical, dental, and vision coverage
+5
Cloud Application Security Engineer
Cloud Application Security Engineer

Tactical Edge • Washington

Hybrid
USD 140,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Staff Cloud Security Engineer
Staff Cloud Security Engineer

Randalls • Pleasanton (CA)

On-site
USD 140,000 - 170,000
Weekly pay
Early wage access
Associate discounts
+4
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Med-Metrix • Parsippany-Troy Hills (NJ)

On-site
USD 140,000 - 190,000
Security Engineer, Cloud
Security Engineer, Cloud

Vercel • United States

Hybrid
USD 208,000 - 312,000
Competitive compensation package including equity
Flexible Time Off
Work-from-home budget for equipment
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Benchmark Analytics • Chicago (IL)

On-site
USD 110,000 - 140,000