SlipstreamJobsFresh Startup & VC-Backed Jobs

Product Security Engineer

Backops Ai - San Francisco, CA, United States - Hybrid

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

BackOps AI is seeking a Product Security Engineer to own security across their agentic AI platform that automates supply-chain operations. This is the first dedicated product security hire and a hands-on role where you will build the product security practice from the ground up while the company scales. You will own product security end-to-end, including authentication, authorization, multi-tenant isolation, APIs, and the data model. Key responsibilities include threat modeling the agent platform to define and enforce boundaries on what agents can do in customer systems, building a secure development lifecycle with design reviews and code review standards, running application vulnerability management, and setting security standards for AI-assisted code generation. You will also secure the software supply chain, manage enterprise security reviews and penetration tests, and extend controls to customer-hosted and on-premises deployments. The role requires 5+ years in product or application security engineering, or a software engineer with deep security expertise who remains hands-on. You need strong coding skills in Python, Go, TypeScript, or similar languages, with real depth in authentication, authorization, and multi-tenant isolation patterns. Deep knowledge of OWASP Top 10 vulnerabilities, web and API security, and hands-on experience with SAST, DAST, SCA, and secrets scanning in CI pipelines is essential. Familiarity with OWASP Top 10 for Agentic Applications and LLM Applications is required, as prompt injection and excessive agency are live concerns in the product. You should be comfortable with threat modeling that produces actionable engineering work, have judgment about risk prioritization, and communicate clearly with engineers, executives, and customers. Nice-to-have skills include hands-on experience securing LLM or agentic systems, SOC 2 or ISO 27001 audit experience, enterprise security review expertise, and experience standing up product security functions from scratch. BackOps is a seed-stage company headquartered in the San Francisco Bay Area, backed by exceptional investors. The role offers competitive salary, meaningful equity, comprehensive health coverage, 401(k), flexible time off, and daily meals in the office.

Similar roles