Remote job
Security Engineer (Early Career) (Ingeniero/a de Seguridad - Carrera Temprana) - Mexico City (Remote)
Job details
About this role
Role overview This early-career security engineering position offers a rotating first-year experience across the security function of a regulated fintech operating across Latin America. The role spans AI security guardrails, multi-cloud posture management, secure code review, and detection engineering, with real ownership expected from the first month. It suits someone who wants broad, hands-on exposure across the full security surface rather than a narrow queue.
Responsibilities - Review how internal teams use LLMs, coding agents, and AI tooling, and help design guardrails that prevent data leakage or unsafe outputs without blocking adoption - Operate and tune an LLM-based investigation agent on the SIEM, validating its conclusions and refining detection prompts before they reach production - Triage findings from AWS GuardDuty, GCP Security Command Center, IAM reviews, and network configuration audits, driving fixes with owning teams - Contribute to large-scale GCP project inventory and cleanup, and keep a central findings tracker accurate - Review internal code, scripts, and pull requests for hardcoded credentials, unsafe input handling, over-broad permissions, and secrets in pipelines - Own results from static analysis and dependency-scanning tools, prioritize CVEs, and follow up with developers to close the loop - Write and refine Splunk queries to investigate alerts from identity, cloud, endpoint, and network sources, and maintain detection rules and dashboards - Reconstruct user activity timelines, document findings with evidence, and execute endpoint containment with a senior engineer - Analyze phishing reports in sandbox tools, tune email and web filtering policies, and run phishing simulations
Requirements - 1-2 years in security, IT, software engineering, or a related technical role; internships, CTFs, bug bounties, open-source work, and serious personal projects all count - Working knowledge of at least one of AWS or GCP, including IAM, security groups or VPC firewall rules, and service accounts - Comfort with bash on the command line, reading JSON and logs, and reading Python, JavaScript, or Go well enough to spot obvious security issues - Basic familiarity with a log query language such as SPL or KQL, or the drive to become fluent quickly - Conceptual understanding of OAuth, SSO, MFA, and service-to-service authentication - Hands-on experience using generative AI tools in a technical context, paired with a healthy skepticism of their outputs - A verify-before-you-conclude instinct: you never take a tool's, vendor's, or AI agent's answer at face value without evidence
Nice to have - Prior exposure to a SIEM, EDR console (CrowdStrike, SentinelOne, Defender), or email and web security platform - Python or JavaScript for scripting and automation - Experience with SAST, dependency scanning, secrets management, or CI/CD security - Experience prompting or building with LLM APIs, agents, or MCP tooling - Entry-level certifications such as Security+, AWS Cloud Practitioner, or Google Cloud Digital Leader - Portuguese language skills
Benefits and work setup - Remote-first position based in Mexico City with periodic in-person team gatherings and customer visits throughout the year - Direct work on emerging problems most security teams have not solved yet, including securing agentic AI in production - Pairing with senior engineers on investigations and reviews, with explicit room to push back when evidence does not hold - Modern tooling stack across AWS, GCP, Splunk, Auth0, Cloudflare, SonarQube, and an incident management platform - Budget and dedicated time for certifications, conferences, and participation in the security community - Competitive compensation with equity from day one and an annual learning budget - English as the working language, with Spanish and Portuguese used daily across the team