Security and Compliance Engineer
BackOps
Security & Compliance Engineer
San Francisco • Hybrid • Full-time
BackOps AI is transforming supply chain operations with agentic AI solutions that automate complex workflows, freeing operations teams to focus on what matters most. Headquartered in the San Francisco Bay Area with flexible remote-friendly options, we foster a culture of innovation, ownership, and measurable impact.
Role Overview
As a Security & Compliance Engineer, you will own and strengthen the operational security, compliance, and privacy foundations of our company and platform. You will work across engineering, infrastructure, and business operations to design practical controls, reduce risk, improve audit readiness, and help us meet the expectations of enterprise customers. This is a hands-on individual contributor role for someone who can translate frameworks into working processes and technical safeguards without slowing down delivery. This role is not an SRE role. While you will partner closely with infrastructure and engineering teams, your primary focus will be security posture, control effectiveness, compliance execution, privacy coordination, and customer trust.
What You'll Do
- Own and improve our security and compliance program across frameworks such as SOC 2 TYPE I/II, SOC 3, ISO 27001, COBIT, and GDPR
- Translate control requirements into practical technical and operational implementations across engineering, cloud infrastructure, access management, vendor management, and internal business processes
- Partner with engineering and infrastructure teams to strengthen areas such as IAM, least privilege, secrets management, audit logging, endpoint and device controls, vulnerability management, network/security hardening, backup governance, and data retention/deletion
- Drive audit readiness by maintaining evidence, control mappings, policies, procedures, risk registers, and remediation tracking
- Lead recurring access reviews, control reviews, and risk assessments across systems, vendors, and internal workflows
- Own or coordinate security policy development and lifecycle management, including periodic review and updates
- Support privacy and data governance processes, including data classification, retention, deletion, handling of customer data, and coordination on GDPR-related requirements
- Run vendor and subprocessor security reviews, due diligence, and ongoing monitoring
- Help define and operationalize incident response governance, including response procedures, roles, escalation paths, and post-incident follow-up from a security perspective
- Partner with product and engineering teams on secure development practices, change management, and control design early in the lifecycle
- Respond to customer-facing security and compliance requests, including security questionnaires, due diligence reviews, and trust documentation
- Build scalable security/compliance workflows so that controls are automated, repeatable, and measurable wherever possible
- Promote a strong security culture through lightweight training, clear guidance, and practical enablement for engineers and cross-functional teams
What We're Looking For
- Experience: 4+ years in security, compliance, GRC, cloud security, security engineering, or a similar hands-on role in a modern SaaS or cloud-native environment
- Framework Depth: Working knowledge of one or more major frameworks such as SOC 2 TYPE I/II, SOC 3, ISO 27001, COBIT, GDPR, and the ability to map controls across frameworks
- Technical Fluency: Comfortable working with engineering and infrastructure teams on cloud security fundamentals such as IAM, logging, secrets, vulnerability remediation, endpoint controls, and secure configuration
- Audit & Evidence Discipline: Able to maintain clean documentation, control evidence, remediation plans, and audit artifacts without turning the role into pure paperwork
- Risk Mindset: Strong judgment in identifying material risks, prioritizing remediation, and balancing speed with practical security outcomes
- Communication: Can write clear policies, standards, procedures, risk summaries, and customer-facing responses; able to work effectively across technical and non-technical teams
- Execution: You are organized, hands-on, and able to independently drive programs from requirement to implementation to review
- Startup Fit: Comfortable operating in a fast-moving environment where you may define structure while also doing the work directly
Nice to Have
- Experience with Vanta, Drata, or similar compliance automation tooling
- Experience supporting SOC 2 Type I/II, SOC 3, ISO 27001 certification, or similar audits end-to-end
- Familiarity with cloud environments such as AWS and/or GCP
- Experience with vendor risk management, security questionnaires, and enterprise customer diligence workflows
- Familiarity with privacy operations and data governance practices in B2B SaaS environments
- Experience with security awareness programs, endpoint/device management, or identity lifecycle management
- Exposure to secure SDLC, application security reviews, or vulnerability management programs
- Experience working in AI, automation, or operationally sensitive product environments
What Success Looks Like
- Our controls are not just documented — they are actually operating, measurable, and sustainable
- Audit readiness improves with less scramble and clearer ownership
- Security and compliance become embedded into engineering and business workflows instead of bolted on later
- Enterprise customers gain confidence in our maturity through strong security posture and clear responses
- Risk is identified earlier, prioritized better, and remediated faster
What We Offer
- Equity & Ownership: Competitive equity so you grow alongside the company
- Impact & Visibility: Direct access to leadership; your work directly improves customer trust and company readiness
- Collaborative Culture: Tight-knit team of seasoned operators and AI experts
- Flexible Work: Hybrid with core Bay Area presence and remote flexibility
- A dynamic tech firm in San Francisco is seeking a Security & Compliance Engineer to enhance operational security and compliance. The ideal candidate will have over 4 years of experience in security roles, working closely with engineering and infrastructure teams. Focus...SuggestedFull timeRemote workFlexible hours
$130k - $160k
Decisive Point is looking for a Security Risk and Compliance Analyst in San Francisco. This role focuses on maturing Asana’s compliance and certification program, involving SOC 2, ISO 27001, and FedRAMP certifications. You will enhance control frameworks and manage audit...Suggested$128.6k
...that serve both wireless and wired connectivity needs for customers and businesses across the globe. The Sr. HW Regulatory Compliance engineer ensures that our products meet all relevant regulations. This role requires deep technical knowledge of international...SuggestedPermanent employmentLocal areaWorldwide$137k - $188k
...and leads government relations. Based out of our San Francisco headquarters, and reporting to the Forensic Engineering Manager, the Senior Compliance Engineer is a key member of the technical team responsible for global compliance and enforcement. The role works...SuggestedFull timeWork at officeLocal areaRemote workWorldwide$190k - $235k
...leading cybersecurity firm is seeking a Senior Threat Research Engineer to enhance detection capabilities for email-based threats. This... ...authoring detection rules, and collaborating with engineers to improve security posture. Compensation ranges from $190,000 to $235,000,...SuggestedRemote work$320k - $405k
...Offensive Security Research Engineer, Safeguards San Francisco, CA About Anthropic Anthropic's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a...Work at officeVisa sponsorshipFlexible hours- ...modern civilization - yet vulnerabilities threaten its integrity, security, and resilience. We are on a mission to solve security.... ...Infrastructure. About this role We’re seeking an experienced Research Engineer to join our effort in building and training AI agents for...Full timeWork at office
- ...complexity and friction with seamless automation. As a Research Engineer at Capably, you’ll help define how intelligent systems operate... ...deploying highly customised AI workflows in production, with built‑in security, governance, and auditability. Success in this role means...
$9.7k - $19k
...AI issues with a mix of technical, societal and policy solutions. As a research engineer intern here, you will work very closely with our researchers on projects in areas such as AI security, machine ethics, AI alignment, and benchmarking AI risks. We will assign you a...Full timeInternshipLocal area$117.2k - $176.7k
...Salesforce. Overview of Role The Global Compliance and Certification (GCC) team is responsible... ...the GCC org, a division within the Product Security Organization and you will play a pivotal role in partnering with engineering, translating complex mandates into...$100k - $150k
A technology venture firm is seeking a Founding Member of Technical Staff (Security) in San Francisco. In this hybrid role, you will lead security research and vulnerability testing on real-world software. Ideal candidates should have strong skills in web application vulnerabilities...$272k - $336k
...billions in simulation across 15+ U.S. states. Waymo's Systems Engineering team works together to blend software and hardware systems in... ...g., UNECE requirements and Type Approval processes) to close compliance gaps. Represent technical teams and concepts accurately and...Odd jobFull timeRemote work- A leading research organization in AI is seeking a full-time fall intern to assist with projects in AI security and alignment. The position offers a stipend of $9,700 - $19,000 annually to help with living expenses. Interns will work closely with researchers, plan and...Full timeInternship
$166k - $225k
...solve the world’s toughest problems, from security threat detection to cancer drug... ...available to all. Job Description As a research engineer on the Scaling team, you will be... ...status, and other protected characteristics. Compliance If access to export‑controlled technology...Worldwide$120k - $250k
...for experimentation, training, and production inference, with security, observability, and control built in. We serve solo researchers... ...WE'RE LOOKING FOR We are seeking a highly skilled Research Engineer to help optimize training and inference workloads running on Lightning...Full timeWork at officeWork from homeFlexible hours2 days per week$70k - $90k
...Bitwarden is the trusted identity security leader for millions of users worldwide, empowering enterprises, developers, and individuals... ...located across the globe. Learn more at bitwarden.com . As a QA Engineer at Bitwarden, you will contribute directly to the future of the...Remote workWorldwide$160k - $200k
...Infrastructure Operations Engineer Lightning AI is the company behind PyTorch Lightning. Founded in 2019, we build an end-to-end platform... ...for experimentation, training, and production inference, with security, observability, and control built in. We serve solo...Remote workWork from homeFlexible hours$134k - $205k
...Senior Security Operations Engineer Austin | Chicago | New York City | Salt Lake City | San Francisco Gong harnesses the power of AI to transform how revenue teams win. The Gong Revenue AI Operating System unifies data, insights, and workflows into a single, trusted...Remote workWork from homeFlexible hoursShift workDay shift$192k - $240k
...Security Operations Engineer Brex is the intelligent finance platform that enables companies to spend smarter and move faster in more than 200 markets. By combining global corporate cards and banking with intuitive spend management, bill pay, and travel software, Brex...Work experience placementWork at officeRemote workWork from home$190k - $282k
...Senior Security Production Engineer Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA / San Francisco, CA CoreWeave is The Essential... ...please contact: ****@*****.***. Export Control Compliance This position requires access to export controlled...Permanent employmentTemporary workCasual workWork at officeRemote workFlexible hours$200k - $240k
...financial tools to help consumers achieve financial security. We're a profitable, high growth FinTech... ..., YOU WILL Lead & Hire Build your quality engineering team from the ground up Collaborate with InfoSec Manager on compliance testing (SOC 2, PCI-DSS) Advise Core...Contract workLocal area$77k - $202k
...to 60% At PwC, our people in risk and compliance focus on maintaining regulatory... ...threat detection, risk management, and security operations automation - Implement and... ...experience in software development or AI/ML engineering What Sets You Apart - Master's Degree...Full timeH1b- A global professional services firm based in San Francisco seeks a Senior Associate in Cybersecurity to develop innovative AI-driven solutions. You will leverage your skills in software development and AI/ML to address complex cybersecurity challenges, mentor team members...
- DepthFirst in San Francisco is seeking an experienced Research Engineer. You will build and train AI agents for discovering and remediating... ..., health benefits, and office meals are provided. Join us to redefine security in software development. #J-18808-Ljbffr DepthFirstWork at office
- A pioneering AI compliance firm in San Francisco seeks a candidate to deploy compliance solutions at banks and fintechs. You will ingest data, configure rules, and deliver accurate audit findings. The ideal candidate has strong SQL skills, a background in data pipeline...Flexible hours
$124k - $280k
...to 60% At PwC, our people in risk and compliance focus on maintaining regulatory... ...and manage strategy, transformation and engineering projects and teams Design and architect... ...as CISSP (Certified Information Systems Security Professional), CISM (Certified Information...Full timeH1b- Careers at Drata are seeking a Senior IT Engineer in San Francisco who will play a key role in managing security and improving internal operations. You will leverage... ...and enhance our infrastructure to ensure compliance and security as Drata continues to scale. The...Work at office
- You’ll be the force multiplier for a security team that needs to operate like it's three... ...‑of‑concept scripts Strong software engineering skills in Python, TypeScript, or Go - you... ...GitOps patterns Experience automating compliance evidence collection (SOC 2, ISO 27001)...Work at officeImmediate startRemote workRelocation package
- A technology firm in San Francisco is seeking a Corporate Security Engineer to lead initiatives ensuring the safety of its corporate environment. The ideal candidate will have over 4 years of experience in Corporate Security, familiarity with Identity and Access Management...
- A cybersecurity technology firm in San Francisco is seeking an AI Research Engineer to enhance security operations. You will develop new AI agents, refine existing frameworks, and apply reinforcement learning techniques. Ideal candidates have 4+ years of engineering experience...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security and Compliance Engineer. Be the first to apply!
- staff security engineer San Francisco, CA
- senior application security engineer San Francisco, CA
- sr information security engineer San Francisco, CA
- security engineering manager San Francisco, CA
- cloud security engineer San Francisco, CA
- endpoint security engineer San Francisco, CA
- physical security engineer San Francisco, CA
- product security engineer San Francisco, CA
- principal security engineer San Francisco, CA
- security engineer San Francisco, CA

