Home › Companies › Braintrust › Cloud Security Engineer
Cloud Security Engineer
Braintrust · San Francisco · On Site · Active · Ashby
Job facts
| Field | Value |
|---|---|
| Company | Braintrust |
| Title | Cloud Security Engineer |
| Normalized title | - |
| Department / team | Engineering / Engineering |
| Location | San Francisco, CA, United States |
| Work model | On Site |
| Employment type | Full Time |
| Salary | - |
| Status | active |
| ATS provider | Ashby |
| Posted / first seen | — / 2026-05-29 |
| Changed / last seen | 2026-05-29 / 2026-06-06 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Braintrust. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through Ashby. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| City jobs | Active postings in San Francisco. | Open |
| Department jobs | Active postings in Engineering. | Open |
| Work model jobs | Active On Site postings. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Braintrust |
| Source | 83a2cdae-40c3-4751-9876-eb52400fbe0f |
| ATS provider | Ashby |
Description
About the company Braintrust is the AI observability platform. By connecting evals and observability in one workflow, Braintrust gives builders the visibility to understand how AI behaves in production and the tools to improve it.
Teams at Notion, Stripe, Zapier, Vercel, and Ramp use Braintrust to compare models, test prompts, and catch regressions — turning production data into better AI with every release.
About the role We're looking for a hands-on Cloud Security Engineer to own the security posture of our multi-cloud infrastructure and customer hosted data planes. You'll work across AWS, Azure, and GCP, harden our Kubernetes and Terraform stack, and keep the platform secure without slowing engineering down.
This is a senior IC role. You'll write code, build paved-road controls, ship detections, and partner with customers on deployment. If you're excited to use agentic coding tools to operate at the pace of a much larger team, we'd love to work with you.
What you'll do Own the security architecture for our internal AWS environment and the customer-deployed stacks running in AWS, Azure, and GCP
Write Terraform modules and policy code that make the secure path the default path for every team shipping infra
Harden our Kubernetes footprint: admission controllers, network policies, workload identity, runtime detections, secrets handling
Build and tune detections across cloud control planes, identity providers, and workload telemetry; own the alert pipeline end-to-end and keep signal-to-noise high
Help run incident response when something fires, and turn every incident into durable controls and codified runbooks
Help push cloud compliance initiatives.
Partner with customers in Slack on self-hosting, network architecture, key management, and tenancy questions
Use agentic coding workflows to automate the repeatable parts of security work: control validation, evidence collection, drift detection, and IR triage
Ideal candidate credentials 5+ years in cloud security, infrastructure security, or security engineering with a heavy hands-on bent — you ship code and configuration, not just policy
Deep AWS expertise (IAM, VPC, KMS, GuardDuty, CloudTrail) and working fluency in at least one of Azure or GCP
Strong Terraform skills and a track record of making security guardrails the default in IaC pipelines
Production Kubernetes security experience: you've run admission controllers, debugged a cluster compromise, or written a network policy that mattered
Proficient in modern backend technologies and comfortable writing real code in Python, TypeScript, or Go
Production incident response experience; you've owned a real incident end-to-end and made the next one less painful
Familiarity with one or more compliance regimes (SOC 2, ISO 27001, HIPAA, FedRAMP) and the discipline to make them work without becoming busywork
Active user of agentic coding tools, with a clear point of view on how AI is changing security engineering — both offense and defense
Bonus: experience securing self-hosted enterprise software, multi-tenant SaaS, or LLM-heavy workloads (data exfiltration via prompts, model proxy abuse, agent sandboxing)
Benefits include Medical, dental, and vision insurance
Daily lunch, snacks, and beverages
Flexible time off
Competitive salary and equity
AI Stipend
Equal opportunity Braintrust is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.
Full job record
| Job ID | a98e4b611e15adceaa3c6950bd64612983d771fd |
| Org ID | 29f0bc1c-6b67-47f5-b0d0-4ffd3d02cefc |
| Source ID | 83a2cdae-40c3-4751-9876-eb52400fbe0f |
| Board ID | 83a2cdae-40c3-4751-9876-eb52400fbe0f |
| Provider | ashby |
| Provider Job Key | 954b72dc-b5f8-4f11-8541-882c20e02fe4 |
| Title | Cloud Security Engineer |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | San Francisco |
| Department | Engineering |
| Team | Engineering |
| Employment Type | full_time |
| Workplace Type | on_site |
| Remote Policy | — |
| Country | United States |
| Region | CA |
| City | San Francisco |
| Salary Raw | — |
| Salary Min | — |
| Salary Max | — |
| Salary Currency | — |
| Salary Period | — |
| Source URL | https://jobs.ashbyhq.com/Braintrust/954b72dc-b5f8-4f11-8541-882c20e02fe4 |
| Apply URL | https://jobs.ashbyhq.com/Braintrust/954b72dc-b5f8-4f11-8541-882c20e02fe4/application |
| First Seen At | 2026-05-29 06:24:09Z |
| Last Seen At | 2026-06-06 09:25:21Z |
| Last Checked At | 2026-06-06 09:25:21Z |
| Last Changed At | 2026-05-29 06:24:09Z |
| Inactive At | — |
| Source Posted At | — |
| Source Updated At | — |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=ashby/board=Braintrust/date=2026-06-06/2026-06-06T09-25-00-318Z-0c680b0f8853b73849c45393c2606e43e89c62c5605765e516f9cad32e508b8e.json |
Event Fields
{
"content_hash": "7b13c693b350b62eacc0f1941d9089092fce84843807a705f2d3de5c94ae0cd3",
"source_hash": "daf73bea6d5a96afbcd9a68a6e04cf69b685d05d2aa11b00bfabeaf072d2c326",
"last_changed_at": "2026-05-29T06:24:09.247Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "San Francisco",
"city": "San Francisco",
"region": "CA",
"country": "United States",
"is_remote": false,
"confidence": 0.75
},
"salary_max": null,
"salary_min": null,
"inferred_at": "2026-06-06T09:25:21.201Z",
"launch_scope": {
"reason": "english_us_canada",
"included": true,
"language": "en",
"location": {
"raw": "San Francisco",
"city": "San Francisco",
"region": "CA",
"country": "United States",
"is_remote": false,
"confidence": 0.75
},
"countries": [
"United States"
]
},
"remote_policy": null,
"salary_period": null,
"workplace_type": "on_site",
"salary_currency": null
}Extensions
{}Native Structured
{
"id": "954b72dc-b5f8-4f11-8541-882c20e02fe4",
"team": "Engineering",
"title": "Cloud Security Engineer",
"jobUrl": "https://jobs.ashbyhq.com/Braintrust/954b72dc-b5f8-4f11-8541-882c20e02fe4",
"address": null,
"applyUrl": "https://jobs.ashbyhq.com/Braintrust/954b72dc-b5f8-4f11-8541-882c20e02fe4/application",
"isListed": true,
"isRemote": false,
"location": "San Francisco",
"updatedAt": null,
"apiVersion": "ashby-non-user-graphql-v1",
"department": "Engineering",
"publishedAt": null,
"workplaceType": "OnSite",
"employmentType": "FullTime",
"secondaryLocations": [
{
"location": "New York City"
},
{
"location": "Seattle"
}
]
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/a98e4b611e15adceaa3c6950bd64612983d771fd?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/29f0bc1c-6b67-47f5-b0d0-4ffd3d02cefcJSONGET https://api.bluedoor.sh/job-postings/v1/sources/83a2cdae-40c3-4751-9876-eb52400fbe0fJSONGET https://api.bluedoor.sh/job-postings/v1/jobs/a98e4b611e15adceaa3c6950bd64612983d771fd/eventsJSON