2 дня назад
Security Engineer (Early Career)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Engineer (Early Career) (AI and Cloud Security): Rotating across AI security, cloud security, secure code, detection, response, and triage for a regulated fintech platform with an accent on AWS, GCP, LLM security, identity, and security operations. Focus on investigating AI-generated findings, improving cloud and CI/CD security, writing Splunk detections, and responding to suspicious activity with senior-engineer guidance.
Location: Mexico City, Mexico; hybrid work model with regular office presence
Company
is a Latin American B2B fintech building financial infrastructure for corporate cards, bill pay, financing, and spend management.
What you will do
- Review the use of LLMs, coding agents, and AI tooling; define safeguards for data protection and investigate prompt injection, data exfiltration, and model permissions.
- Triage and remediate cloud security findings across AWS and GCP, including IAM, network configurations, project inventories, and security posture checks.
- Review code, pull requests, CI/CD changes, secrets, permissions, vulnerabilities, and dependency-scanning results.
- Write Splunk queries, maintain detection rules and dashboards, investigate activity timelines, and analyze false positives and false negatives.
- Investigate suspicious endpoints, handle phishing reports, analyze URLs and attachments, maintain filtering policies, and support incident containment and escalation.
Requirements
- 1–2 years of experience in security, IT, software engineering, or a related technical role; internships, CTFs, bug bounties, open-source work, and serious personal projects count.
- Working knowledge of AWS or GCP, including IAM, security groups or VPC firewall rules, and service accounts.
- Comfort with Bash, JSON, logs, and reading code in Python, JavaScript, or Go.
- Basic familiarity with SPL, KQL, or a similar log query language, plus an understanding of OAuth, SSO, MFA, and service-to-service authentication.
- Hands-on experience with generative AI tools in a technical context and the ability to verify tool and AI-agent output using evidence.
- Strong written communication in Spanish and English is required.
Nice to have
- Experience with SIEM, EDR, email or web security platforms, SAST, dependency scanning, secrets management, or CI/CD security.
- Python or JavaScript scripting and automation experience.
- Experience with LLM APIs, agents, or MCP tooling.
- Entry-level security or cloud certifications.
- Portuguese language skills.
Culture & Benefits
- Exposure to cloud, code, detection, response, compliance, and AI security in a regulated fintech.
- Pairing and guidance from senior security engineers, with opportunities to own investigations and reviews.
- Modern security stack including AWS, GCP, Splunk, Auth0, Cloudflare, SonarQube, incident.io, Claude, and internal AI tooling.
- Budget and time for certifications, conferences, and participation in the hacker community.
- Competitive salary, stock options, annual learning budget, flexible vacation, and a hybrid work model.
Hiring process
- Application review followed by a technical conversation about real-world scenarios.
- Practical exercise completed in a few hours.
- Conversation with the security team.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →