UNjobs Все вакансии →

Security Engineer (Early Career) (Ingeniero/a de Seguridad - Carrera Temprana) - Mexico City (Hybrid)

Clara · Mexico City, CMX, Mexico · по договорённости

Компания
Clara
Город
Mexico City, CMX, Mexico
Зарплата
по договорённости
Уровень
middle
Формат
full_time
Иностранная компания
нанимает русскоязычных

Ready to accelerate your career?

Clara is the fastest-growing company in Latin America. We've built the leading solution for companies to make and manage all their payments. We already help over 20,000 large and growing businesses operate with agility and financial clarity through locally issued corporate cards, bill pay, financing, and a powerful B2B platform built for scale.

Clara is backed by some of the most successful investors in the world, including top regional VCs like monashees, Kaszek, and Canary, and leading global funds like Notable Capital, Coatue, DST Global Partners, ICONIQ Growth, General Catalyst, Citi Ventures, SV Angel, Citius, Endeavor Catalyst, and Goldman Sachs - in addition to dozens of angel investors and local family offices. We’re building the financial infrastructure that powers high-performing organizations across the region. We invite you to join us if you want to be part of a fast-paced environment that will accelerate your career and support you to do some of the best work of your life alongside a passionate and committed team distributed across the Americas.

Security Engineer (Early Career)

What you'll do

You will rotate across the security function in your first year, with real ownership from the first month. Expect the mix below to shift as the business does.

Secure the AI posture, without blocking it

Review how teams use LLMs, coding agents and AI tooling (Claude, agentic browsers, internal inference gateways) and help define guardrails that protect data without killing adoption

Operate our LLM-based investigation agent on the SIEM: catch hallucinated attributions, noisy alerts and conclusions the underlying data doesn't support, and tune its instructions before they reach production

Develop the core skill of this role: knowing when to trust an AI-generated result and when to verify it by hand

Help build our view of prompt injection, data exfiltration through AI tools, and model/agent permissions as first-class risks

Cloud security on AWS and GCP

Triage findings from AWS GuardDuty, GCP Security Command Center, IAM and network configuration reviews

Run configuration and posture checks, and drive fixes with the owning teams instead of just filing tickets

Contribute to our large-scale GCP project inventory and cleanup, and keep the central findings tracker honest

Learn Auth0, Cloudflare and Google Workspace security controls as they apply to identity, edge and SaaS

Secure code and CI/CD

Review internal tools, scripts and pull requests for the classics: hardcoded credentials, unsafe input handling, over-broad permissions, secrets in pipelines

Own SonarQube and dependency-scanning results for internal repositories: prioritize CVEs, follow up with developers, close the loop

Review CI/CD changes that touch security-sensitive configuration (secrets, deployment access, IAM bindings)

Help push secure-by-default patterns into how engineers actually work, including the code they generate with AI

Detection, response and triage

Write and refine Splunk queries to investigate alerts from identity/SSO, cloud, endpoint, email and network sources

Maintain detection rules and dashboards; hunt down false positives and false negatives

Reconstruct user activity timelines across systems and document findings with evidence, not just conclusions

Monitor the EDR console, investigate suspicious endpoints, and execute containment (host isolation, quarantine) with a senior engineer

Triage phishing reports, analyze URLs and attachments in sandbox and threat-intel tools, maintain email and web filtering policies, and run phishing simulations

Escalate fast and clearly when a finding exceeds what you can close on your own, and work incidents through incident.io

What we look for

1–2 years in security, IT, software engineering or a related technical role. Internships, CTFs, bug bounties, open-source contributions and serious personal projects all count.

Working knowle

Открыть и откликнуться →

Отклик ведёт на сайт работодателя. Бесплатная регистрация открывает отклик и разбор резюме.