Назад
Company hidden
2 дня назад

Security Engineer (AI)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Mexico/Colombia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer (AI): Securing Clara’s AI systems, cloud infrastructure, applications, CI/CD pipelines, and detection and response capabilities with an accent on LLM threat modeling, AWS and GCP controls, secure coding, and incident leadership. Focus on designing guardrails, evaluating AI investigation agents, building high-signal Splunk detections, leading incident response, and translating PCI DSS and ISO 27001 controls into reliable engineering practices.

Location: Bogota, Colombia, or Mexico City, Mexico; hybrid work model with regular office presence expected

Company

hirify.global is a Latin American B2B fintech building financial infrastructure for corporate payments, cards, bill pay, financing, and spend management.

What you will do

  • Own hirify.global’s AI security posture across LLMs, coding agents, agentic browsers, MCP integrations, and internal inference gateways.
  • Secure AWS and GCP environments through detection, posture management, identity controls, organization policies, and infrastructure-as-code guardrails.
  • Run the application security program, including SAST, dependency and secrets scanning, secure architecture reviews, CI/CD hardening, penetration tests, and vulnerability disclosure.
  • Build and tune Splunk detections across identity, cloud, endpoint, email, and network sources.
  • Lead incident investigations and response, including containment, root-cause analysis, and post-incident reviews.
  • Map engineering controls to PCI DSS and ISO 27001 and support customer security reviews and enterprise sales.

Requirements

  • 2–4 years of hands-on production experience in security engineering, cloud security, application security, or a related engineering role.
  • Practical AWS and/or GCP security experience, including IAM, network controls, logging, detection, and Terraform or similar infrastructure-as-code tools.
  • Programming ability in Python, Go, or JavaScript/TypeScript for building security tooling and automation.
  • Experience identifying injection, authentication and authorization, secrets-management, and supply-chain issues in code and CI/CD pipelines.
  • Hands-on SIEM and EDR experience, including detection engineering and investigations; Splunk experience is preferred.
  • Strong written and spoken Spanish and English communication skills.

Nice to have

  • Fintech, payments, or regulated-environment experience with PCI DSS, ISO 27001, or SOC 2.
  • Experience securing or red-teaming LLM applications, agents, or MCP tooling.
  • Kubernetes and container security, detection-as-code, SOAR, or security automation experience.
  • Security certifications such as AWS Security Specialty, Google Professional Cloud Security Engineer, OSCP, GIAC, or CISSP.
  • Portuguese, open-source contributions, conference talks, or CTF and bug-bounty experience.

Culture & Benefits

  • Ownership of security problems with direct exposure to leadership and AI adoption decisions.
  • Modern security stack including AWS, GCP, Splunk, Auth0, Cloudflare, SonarQube, incident.io, Claude, and internal AI tooling.
  • Annual learning budget, accelerated development paths, and time for certifications, conferences, and the hacker community.
  • Multicultural environment with daily exposure to Portuguese, Spanish, and English.
  • Competitive salary, stock options from day one, flexible vacation, and a hybrid work model.

Hiring process

  • Application review.
  • Technical deep dive covering real security scenarios and a practical exercise.
  • Conversations with the team and leadership.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →