Cloud Security Engineer
Summary
Designs and implements cloud security controls for a SaaS platform using AWS/GCP, Kubernetes, and CI/CD automation to protect AI-driven supply chain workflows.
Role Overview
What You’ll Do
- Design, build, and maintain robust cloud security controls across AWS/GCP infrastructure, Kubernetes, and serverless environments
- Architect and implement fine-grained IAM policies, least privilege access models, and automated secrets management to minimize the attack surface
- Develop and integrate automated security scanning and guardrails into CI/CD pipelines (SAST, DAST, and container vulnerability scanning)
- Lead network security hardening, including VPC architecture, security groups, and cloud-native monitoring/alerting strategies
- Operationalize vulnerability management and threat modeling for cloud-native applications and AI-driven workflows
- Partner with engineering teams on secure development practices and provide technical guidance for securing complex AI agent architectures
What We’re Looking For
- Experience: 4+ years in cloud security engineering, infrastructure security, or DevSecOps within a modern SaaS environment
- Cloud Platforms: Deep technical proficiency in AWS and/or GCP, including networking, IAM, and managed services
- DevSecOps & Automation: Proven experience with Infrastructure as Code (Terraform/CloudFormation) and automating security within CI/CD pipelines
- Container Security: Strong understanding of securing containerized workloads and orchestration platforms like Kubernetes (EKS/GKE)
- Risk Mindset: Strong judgment in identifying material risks, prioritizing remediation, and balancing speed with practical security outcomes
- Communication: Can write clear policies, standards, procedures, risk summaries, and customer-facing responses; able to work effectively across technical and non-technical teams
- Execution: You are organized, hands-on, and able to independently drive programs from requirement to implementation to review
- Startup Fit: Comfortable operating in a fast-moving environment where you may define structure while also doing the work directly
- Programming Proficiency: Strong coding skills in Python, Go, or a similar language to automate security tasks and interact with cloud APIs.
Nice to Have
- Experience with Vanta, Drata, or similar compliance automation tooling
- Experience supporting SOC 2 Type I/II, SOC 3, ISO 27001 certification, or similar audits end-to-end
- Familiarity with cloud environments such as AWS and/or GCP
- Experience with vendor risk management, security questionnaires, and enterprise customer diligence workflows
- Familiarity with privacy operations and data governance practices in B2B SaaS environments
- Experience with security awareness programs, endpoint/device management, or identity lifecycle management
- Exposure to secure SDLC, application security reviews, or vulnerability management programs
- Experience working in AI, automation, or operationally sensitive product environments
What Success Looks Like
- Our controls are not just documented they are actually operating, measurable, and sustainable
- Audit readiness improves with less scramble and clearer ownership
- Security and compliance become embedded into engineering and business workflows instead of bolted on later
- Enterprise customers gain confidence in our maturity through strong security posture and clear responses
- Risk is identified earlier, prioritized better, and remediated faster
What We Offer
- Equity & Ownership: Competitive equity so you grow alongside the company
- Impact & Visibility: Direct access to leadership; your work directly improves customer trust and company readiness
- Collaborative Culture: Tight-knit team of seasoned operators and AI experts
- Flexible Work: Hybrid with core Bay Area presence and remote flexibility