← Back to jobs

Remote job

Security Engineer (Ingeniero/a de Seguridad)

Other Full-time Permanent Colombia, Mexico

Job details

Not specified Salary
Colombia, Mexico Eligibility
Lead Experience
Full-time Employment

About this role

Role overview A high-growth fintech is hiring a Security Engineer to lead workstreams across the security function, mentor early-career engineers, and own outcomes end to end. The role is remote-first and blends AI security, cloud security (AWS and GCP), application security, detection and response, and compliance engineering in a regulated payments environment. The successful hire will pair hands-on technical work with influence across product, engineering, and leadership.

Responsibilities - Define and operate controls for AI systems in production, including LLMs, coding agents, agentic browsers, MCP integrations, and internal inference gateways, covering data handling, identity, permissions, and logging. - Threat-model AI as a first-class attack surface, addressing prompt injection, data exfiltration, over-privileged agents, and model and tool supply-chain risks, while enabling safe adoption by default. - Own cloud posture and detection across AWS (GuardDuty, IAM, VPC, CloudTrail) and GCP (Security Command Center, IAM, service accounts, org policies), and drive remediation with owning teams. - Build guardrails as code, including org policies, SCPs, IAM boundaries, and infrastructure-as-code policy checks, and lead a large-scale cloud project inventory and cleanup program. - Run the application security program with SAST, dependency and secrets scanning, secure-by-default libraries, PR review for sensitive changes, and coordination of pentests and vulnerability disclosure. - Engineer detections in Splunk, lead incident response (containment, root cause, post-incident review), and produce audit-ready evidence mapped to PCI DSS and ISO 27001 without slowing delivery.

Requirements - 2–4 years in security engineering, cloud security, application security, or a closely related production role. - Strong practical knowledge of AWS and/or GCP security (IAM design, network controls, logging, detection) and the ability to read and write infrastructure as code (Terraform or similar). - Solid programming ability in at least one language such as Python, Go, JavaScript, or TypeScript, with a track record of building tooling and automation. - Real secure-code experience finding and explaining injection, auth/authz, secrets handling, and supply-chain issues in code and CI/CD pipelines, plus the credibility to drive fixes. - Hands-on experience with a SIEM (Splunk preferred) and an EDR platform, including detection engineering and incident investigation. - Working understanding of LLM-based systems and agents, their failure modes, and a clear, defensible sense of risk prioritization. - Strong written and spoken Spanish and English, with the judgment to explain risk to engineers, product managers, and auditors in the same week.

Nice to have - Experience in fintech, payments, or another regulated environment (PCI DSS, ISO 27001, SOC 2). - Securing or red-teaming LLM applications, agents, or MCP tooling. - Kubernetes and container security, detection-as-code, SOAR, or security automation. - Certifications such as AWS Security Specialty, Google Professional Cloud Security Engineer, OSCP, GIAC, or CISSP. - Portuguese language skills, plus open-source contributions, conference talks, or a CTF/bug-bounty track record.

Benefits and work setup - Remote-first day to day, with in-person ramp-up and periodic team gatherings, events, and customer visits. - Competitive compensation with equity (ESOP) from day one, an annual learning budget, and time and budget for certifications, conferences, and community work. - A modern stack (AWS, GCP, Splunk, Auth0, Cloudflare, SonarQube, incident.io, Claude, internal AI tooling) with the mandate to improve it. - A culture that prizes evidence over hierarchy, expects pushback when data does not hold, and emphasizes clarity, simplicity, ownership, high standards, adaptability, and inclusivity.

Skills detected in the listing

TypeScriptJavaScriptPythonGoAWSGCPKubernetesTerraformLLM
Detected Oct 8, 2026
Last verified Oct 8, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight