Назад
Company hidden
обновлено 1 месяц назад

Lead Security Engineer

80 000 - 100 000$
Формат работы
remote (только Brazil/Mexico/Colombia)
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Mexico/Colombia/Brazil
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Security Engineer (AWS/Application Security): Building and scaling LawnStarter's security function across its PHP/Laravel and TypeScript/React marketplace, AWS infrastructure, payment flows, and customer data with an accent on application security, cloud security, compliance, and incident response. Focus on automating security controls for AI-agent-authored code, mapping PCI/SOC 2/LGPD requirements, and establishing the standards and roadmap for a future security team.

Location: Remote; Brazil, Mexico, or Colombia

Salary: $80,000–$100,000 USD annually

Company

hirify.global operates an on-demand marketplace for lawn care and outdoor services and is expanding into a broader home-services platform across three brands.

What you will do

  • Lead security across the PHP/Laravel and TypeScript/React applications, AWS infrastructure, payment systems, and customer and professional data.
  • Build application-security practices including threat modeling, secure SDLC, code review, SAST, secret scanning, dependency scanning, and vulnerability management.
  • Strengthen AWS and Kubernetes security through IAM, network controls, encryption, secrets management, and production guardrails.
  • Drive PCI scope mapping, SOC 2 and LGPD readiness, vendor risk management, and security questionnaire responses.
  • Improve detection and incident response using Datadog, Sentry, and AWS signals, including an incident runbook and MTTD/MTTR baselines.
  • Establish security standards, playbooks, and hiring plans for a small team expected to grow within approximately 12–18 months.

Requirements

  • Hands-on expertise across at least three of application security, cloud security, compliance, and incident response.
  • Experience building technical security controls, pipelines, automated scans, detections, and cloud guardrails.
  • Ability to prioritize risks pragmatically across payments, personally identifiable information, marketplace operations, and shared infrastructure.
  • Experience or strong interest in securing AI-agent-authored code through automated gates, secure-coding conventions, and review processes.
  • Strong collaboration skills with engineering delivery teams and Cloud & DevOps.

Culture & Benefits

  • Fully remote work with a US-distributed engineering organization.
  • Asynchronous work and autonomy over the working environment.
  • Claude Code and the engineering agent stack provided for security work.
  • Opportunity to define the security function and build its first dedicated team.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →