← к выдаче
безопасность

Security Engineer (Ingeniero/a de Seguridad)

ClaraCO, MX22 дн. назад

Описание от работодателя

Clara is the leading spend management platform in Latin America. More than 40,000 businesses run on our corporate cards, bill pay, financing and B2B payments, and in 2025 the Financial Times named Clara the fastest-growing company in Latin America. We're ~400 people, backed by Kaszek, monashees, Coatue, DST Global, ICONIQ, General Catalyst and Goldman Sachs, among others. Security Engineer What you'll do You will own outcomes, not a queue. You'll lead workstreams across the security function, pair with and mentor early-career engineers, and be trusted to make calls without waiting for sign-off. Own the AI security posture, enabling rather than blocking Define and operate the controls for how Clara uses LLMs, coding agents, agentic browsers, MCP integrations and internal inference gateways: data handling, identity, permissions, logging Own the LLM-based investigation agent on the SIEM: design its instructions and rules, evaluate its accuracy, catch hallucinated attributions and unsupported conclusions, and decide what it is allowed to close autonomously Threat-model AI systems as first-class attack surface: prompt injection, data exfiltration through AI tools, over-privileged agents, model and tool supply chain Build the guidance and paved paths that let product and engineering adopt AI safely by default, and be a credible voice in those decisions Cloud security on AWS and GCP Own detection and posture across AWS (GuardDuty, IAM, VPC, CloudTrail) and GCP (Security Command Center, IAM, service accounts, org policies), and drive remediation with the owning teams Design and implement guardrails as code: organization policies, SCPs, IAM boundaries, infrastructure-as-code policy checks Lead parts of our large-scale GCP project inventory and cleanup program, and turn one-off findings into automated controls Secure identity and edge: Auth0, Cloudflare, Google Workspace, SSO and service-to-service authentication Secure code, CI/CD and application security Run and evolve the application security program: SAST (SonarQube, Semgrep or similar), dependency and secrets scanning, PR review for security-sensitive changes, and CI/CD pipeline hardening Review architecture and code for new products and integrations (card issuing, payments, banking partners) and produce actionable, prioritized findings Define secure-by-default patterns and libraries for engineers, including for AI-generated code, and measure whether they're being used Coordinate pentests and vulnerability disclosure, and drive findings to closure Detection, response and incident leadership Build and tune detections in Splunk across identity/SSO, cloud, endpoint, email and network sources, with a bias toward high-signal alerts Lead incident investigation and response through incident.io: scoping, containment (EDR isolation, credential revocation, cloud access), root cause and post-incident review Own email and web protection policy and the phishing program Mentor early-career engineers on investigation technique and evidence-based reporting, and review their work Compliance as a byproduct of good engineering Map your controls to PCI DSS and ISO 27001 requirements, and produce the evidence auditors need without slowing the team down Support customer security reviews and enterprise sales when a technical voice is needed What we look for 2–4 years in security engineering, cloud security, application security or a closely related engineering role, including hands-on production experience Strong, practical knowledge of AWS and/or GCP security: IAM design, network controls, logging and detection, and the ability to read and write infrastructure as code (Terraform or similar) Solid programming ability in at least one language (Python, Go, JavaScript/TypeScript): you build tooling and automation, not just review other people's code Real secure-code experience: you can find and explain injection, auth/authz, secrets handling and supply-chain issues in code and in CI/CD pipelines, and you know how to get developers to fix them Hands-on experience with a SIEM (Splunk preferred) and an EDR platform, including detection engineering and investigation Working understanding of LLM-based systems and agents, including their failure modes, and experience using or building with them in a technical setting Sound judgment on risk: you know the difference between a finding that blocks a launch and one that ships with a follow-up, and you can defend that call Strong written and spoken communication in Spanish and English; you can explain a risk to an engineer, a product manager and an auditor in the same week Comfort with pace and ambiguity: priorities move, the stack evolves, and you'd rather build the process than wait for it Nice to have Experience in fintech, payments or another regulated environment (PCI DSS, ISO 27001, SOC 2) Experience securing or red-teaming LLM applications, agents or MCP tooling Kubernetes and container security Detection-as-code, SOAR or security automation experience Certifications such as AWS Security Specialty, Google Professional Cloud Security Engineer, OSCP, GIAC or CISSP Portuguese Contributions to open source, conference talks or CTF/bug bounty track record What you'll get Ownership of problems that matter at a unicorn fintech, with direct exposure to leadership and to the decisions that shape how Clara adopts AI Frontier work: securing agentic AI in production, in a company that is actually deploying it A modern stack and the mandate to improve it: AWS, GCP, Splunk, Auth0, Cloudflare, SonarQube, incident.io, Claude and internal AI tooling A team that values evidence over hierarchy, and expects you to push back when the data doesn't hold Budget and time for certifications, conferences and the hacker community Fast, transparent hiring: application review, a technical deep-dive on real scenarios you've handled, a practical exercise, and conversations with the team and leadership How to stand out Tell us about a control you designed that made engineers faster, not slower. Or an incident you led, a detection you built, a vulnerability you found, or something you've published. We care about how you think about risk and how you get things fixed, not about the length of your tool list. Why Clara A high talent-density team driven to make an impact in Latin America — low ego, high ownership. Competitive salary and stock options (ESOP) from day one. An annual learning budget and accelerated development paths. English is our working language, with Spanish and Portuguese every day. How we work Clarity — Open and direct communication: we say what we mean and give context where it matters. Simplicity — If it can be simpler, it should be. Ownership — We own everything we do, end to end. When something needs to happen, we don't wait. Pride — We hold ourselves to a high standard, and it shows in what we deliver. ABC (Always Be Changing) — We adapt fast, embrace change, and keep learning. Inclusivity — Diverse ideas, stories and perspectives build a better Clara. Hybrid at Clara Claridians split their time between the office, customers and home. We don't set a minimum number of office days for most roles, but we expect you to spend time there naturally, and most days during your ramp-up or when your leader asks. If you meet the must-haves, apply — the nice-to-haves are a bonus, not a requirement.