Security Engineer (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Security Engineer (Fintech): Laying the foundation for security operations in Brazil, spanning Application Security, SecOps, and GRC with an accent on cloud infrastructure and AI workflow security. Focus on building SIEM detection rules, hardening CI/CD pipelines, and establishing vendor security assessment frameworks.
Location: Hybrid (Brazil), must be based in Brazil with 3-4 days a week in-office
Company
is a high-growth fintech company building a leading financial application in Latin America.
What you will do
- Drive application security initiatives including threat modelling, secure code reviews, and API testing.
- Secure AI and agentic workflows by reviewing prompts and controlling data exposure.
- Build SIEM detection rules, alert pipelines, and automated response playbooks using Datadog, CrowdStrike, and Cloudflare.
- Contribute to incident response readiness, IR playbooks, tabletop exercises, and forensic procedures.
- Conduct cloud security assessments across AWS and Kubernetes environments.
- Establish and run a scalable vendor security assessment and due diligence framework for third-party onboarding.
Requirements
- 4–7 years of experience in information security, ideally in a startup or high-growth company.
- 2+ years of experience at a regulated fintech, bank, or payment company.
- Hands-on experience with cloud infrastructure security (AWS, Kubernetes).
- Proficiency in AppSec practices: threat modelling, CI/CD pipeline hardening, and API security testing.
- Ability to define practical guardrails for LLM integrations and automated AI workflows.
- Experience with SIEM platforms, EDR/XDR, and IAM tools (Okta, Cloudflare Access).
- Strong written and verbal communication in English.
Culture & Benefits
- Competitive salary, discretionary performance bonuses, and stock options.
- Access to the latest tools and technology.
- Opportunity to be the first security engineer in the region and shape the function's growth.
- Collaboration with a world-class global security team.
- Hybrid work arrangement with 3-4 days in-office.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →