Veo is a global leader in AI-based sports camera technology. Our innovative, fully automatic camera solution enables sports teams to record matches and training sessions without a camera operator. We’re democratizing the world of sports by granting video analysis for teams on all levels—a privilege that used to be only for the few. More than 40,000 clubs in 90+ countries record their games every week.
But what truly sets us apart? Our people. We’re a diverse group of innovative thinkers, creators, and problem-solvers who believe in delivering an incredible product—and having fun while doing it.
🏢 About Veo
Veo's security surface is unusual. We train models on-premise on dedicated GPU infrastructure, run the product across AWS and GCP, and operate a fleet of tens of thousands of cameras deployed at clubs and venues worldwide. That is a scope most SaaS security engineers never touch: physical devices in the field, heavy on-prem compute, and multi-cloud production, all in one role.
We are forming a Security Enablement Team that makes it easier for every engineering and IT team at Veo to build, ship, and operate secure systems. You will own the infrastructure and cloud security slice, where office networks, data center networks, and employee access to product systems meet, partnering with the teams that own these systems so security is built in from the start. As an enablement function, the team does not run these systems day to day. We build the paved roads, tooling, and patterns that let the owning teams operate securely by default.
🎯 The Role
You will join during a pivotal moment. We are standing the team up, defining what good looks like across infrastructure, network, and workforce identity security, and rolling out the first paved roads for a unified internal network across our datacenters (GCP, AWS) and offices (Miami, Berlin, and Copenhagen), workforce identity and access, and drift checks for cloud configuration and network rules. You'll have direct impact on how 100+ engineers, and every Veo employee, work securely across our offices and clouds.
✅ Key Responsibilities
Lead the design, reviews, and tooling for our office and data center networks and the VPN that connects them, as part of the network security direction the team sets together. Day-to-day operation and firewall changes stay with the team that owns the network
Build patterns and tooling for secure cross-site connectivity and endpoint security posture that IT can adopt and run, in a way that supports how Veo engineers actually work
Build the patterns and automation for workforce identity and access, including SSO hygiene, MFA enforcement for employees, and clean joiner, mover, and leaver flows for access to product systems, with IT owning the day-to-day operation
Build automated checks that surface drift in cloud configuration and network rules, so the owning teams get a signal and can act on it
Act on infrastructure and network findings from external penetration tests, routed through the team's shared intake, with the owning teams driving remediation
Build the first version of cross-cutting capabilities, such as the cross-site VPN or the drift checks, then hand each one to a long-term owner with a written transition that covers the runbook, ownership, and escalation path
Partner with GRC to build evidence pipelines for IT and access-related controls that produce auditable output without manual follow-up
Run office hours where IT, platform, and product teams can get a network or access review
📌 Required Qualifications
Solid IT fundamentals: networking, identity, endpoint posture, MFA, and SSO at production scale
Cloud infrastructure experience: hands-on work on at least one of GCP or AWS, including IAM, networking, and basic Terraform-style IaC
Workforce identity and access: hands-on experience with SSO and identity providers (Okta, Google Workspace) and clean joiner, mover, and leaver flows
A security mindset layered on that IT and cloud depth: you instinctively look for misconfigurations, drift, and bad access patterns, without needing to be a dedicated security specialist
Cross-context comfort: you can work on an office network problem and a product cloud problem in the same week without context-switching pain
Platform-as-product mindset: you've built internal tooling that real teams adopt, with guard rails built into the tools people already use and manual review as a last resort, and you gathered feedback and measured impact
Comfort handing work back to a long-term owner once the build phase is done
Collaboration: you work through discussion and feedback to reach consensus
⭐ Desirable Experience
Experience with AWS and GCP security best practices
Knowledge of network security concepts and tools
Experience with identity and access management systems