Remote job
Security Engineer (Ingeniero/a de Seguridad)
Job details
About this role
Role overview A high-growth fintech is hiring a Security Engineer to lead workstreams across the security function, mentor early-career engineers, and own outcomes end to end. The role is remote-first and blends AI security, cloud security (AWS and GCP), application security, detection and response, and compliance engineering in a regulated payments environment. The successful hire will pair hands-on technical work with influence across product, engineering, and leadership.
Responsibilities - Define and operate controls for AI systems in production, including LLMs, coding agents, agentic browsers, MCP integrations, and internal inference gateways, covering data handling, identity, permissions, and logging. - Threat-model AI as a first-class attack surface, addressing prompt injection, data exfiltration, over-privileged agents, and model and tool supply-chain risks, while enabling safe adoption by default. - Own cloud posture and detection across AWS (GuardDuty, IAM, VPC, CloudTrail) and GCP (Security Command Center, IAM, service accounts, org policies), and drive remediation with owning teams. - Build guardrails as code, including org policies, SCPs, IAM boundaries, and infrastructure-as-code policy checks, and lead a large-scale cloud project inventory and cleanup program. - Run the application security program with SAST, dependency and secrets scanning, secure-by-default libraries, PR review for sensitive changes, and coordination of pentests and vulnerability disclosure. - Engineer detections in Splunk, lead incident response (containment, root cause, post-incident review), and produce audit-ready evidence mapped to PCI DSS and ISO 27001 without slowing delivery.
Requirements - 2–4 years in security engineering, cloud security, application security, or a closely related production role. - Strong practical knowledge of AWS and/or GCP security (IAM design, network controls, logging, detection) and the ability to read and write infrastructure as code (Terraform or similar). - Solid programming ability in at least one language such as Python, Go, JavaScript, or TypeScript, with a track record of building tooling and automation. - Real secure-code experience finding and explaining injection, auth/authz, secrets handling, and supply-chain issues in code and CI/CD pipelines, plus the credibility to drive fixes. - Hands-on experience with a SIEM (Splunk preferred) and an EDR platform, including detection engineering and incident investigation. - Working understanding of LLM-based systems and agents, their failure modes, and a clear, defensible sense of risk prioritization. - Strong written and spoken Spanish and English, with the judgment to explain risk to engineers, product managers, and auditors in the same week.
Nice to have - Experience in fintech, payments, or another regulated environment (PCI DSS, ISO 27001, SOC 2). - Securing or red-teaming LLM applications, agents, or MCP tooling. - Kubernetes and container security, detection-as-code, SOAR, or security automation. - Certifications such as AWS Security Specialty, Google Professional Cloud Security Engineer, OSCP, GIAC, or CISSP. - Portuguese language skills, plus open-source contributions, conference talks, or a CTF/bug-bounty track record.
Benefits and work setup - Remote-first day to day, with in-person ramp-up and periodic team gatherings, events, and customer visits. - Competitive compensation with equity (ESOP) from day one, an annual learning budget, and time and budget for certifications, conferences, and community work. - A modern stack (AWS, GCP, Splunk, Auth0, Cloudflare, SonarQube, incident.io, Claude, internal AI tooling) with the mandate to improve it. - A culture that prizes evidence over hierarchy, expects pushback when data does not hold, and emphasizes clarity, simplicity, ownership, high standards, adaptability, and inclusivity.