Engineering Manager, Infrastructure and Security
Summary
Lead the Infrastructure and Security team at BackOps AI, focusing on multi-cloud/on-prem deployment, reliability, and security posture including SOC 2 compliance. Manage engineers, implement guardrails, and oversee risk management for agentic AI supply-chain operations.
- Lead, mentor, and grow a high-performing team of infrastructure and security engineers. Hire, coach, and develop the talent on it, and set the bar for who joins.
- Own our infrastructure: multi-cloud and on-prem deployment, reliability and SLOs, private networking, and the cost of running all of it.
- Own our security posture: identity and least-privilege access, secrets management, vulnerability management, and the controls behind SOC 2.
- Build security into how engineering already works rather than bolting it on afterward. Guardrails in CI/CD, and paved roads teams take because they are the easiest path.
- Set a high bar for what done means: tested code, observability, operational readiness, and runbooks someone who did not build the system can work from. AI-assisted work ships with a human owning it.
- Run a planning rhythm where the team commits to an outcome and the reason it matters. We measure the risk we remove, not the tickets we close.
- Protect a sustainable pace. Heroics are a signal that a system needs fixing, not something to celebrate.
- Translate a fast-moving risk picture into something leadership and customers can act on, including enterprise security reviews.
- 5+ years managing engineers, on top of a strong hands-on infrastructure or security engineering background.
- Deep grounding in cloud-native architecture: AWS and/or GCP, Kubernetes, infrastructure as code, and CI/CD.
- Real depth in security engineering: identity and access, least-privilege models, secrets management, and vulnerability management. Enough to build it, not only to review it.
- A track record of taking a loosely defined, high-stakes mandate and turning it into sequenced, measurable delivery.
- Experience shipping through teams you do not own, where relationships rather than org charts decide whether the work lands.
- Experience putting risk in front of executives and customers, including saying clearly what is still unknown.
- Comfortable when requirements change week to week and the right answer is not known yet.
- Clear written and verbal communication with engineers, executives, and customers.
- SOC 2 Type I/II, ISO 27001, or similar audits taken end to end.
- Compliance automation tooling such as Vanta or Drata.
- Multi-tenant SaaS, or on-prem and customer-hosted deployment.
- Security or platform capabilities delivered as an internal product with real adoption numbers behind them.
- Standing up a function where none existed: charter, practices, and the culture around it.
- Growing a team quickly while the bar went up rather than down.
- Securing AI or agentic systems, where the software takes actions on its own.
- Our controls are operating and measurable, not just documented.
- Enterprise security reviews stop being a scramble and stop holding up deals.
- Engineers take the paved road because it is the fastest path, not because a policy says to.
- Access is least-privilege by default, and nobody needs standing production access to do their job.
- Incidents get shorter, and the same one does not come back.
- The team grows and the bar goes up at the same time.
- Own the infrastructure and security of an AI-native company while both are still being shaped.
- Our agents take real actions in customer operations, which makes this work matter more here than it does in most places.
- Small team with real autonomy and direct access to founders and customers.
- Backed by exceptional investors and advisors.
- Competitive salary and meaningful equity.
- Comprehensive health, dental, and vision coverage.
- 401(k) plan, disability insurance, and life insurance.
- Flexible time off.
- Daily meals in the office, and regular team events and offsites.
