UNjobs Все вакансии →

Security Engineer (Ingeniero/a de Seguridad)

Clara · Bogota D.C, DC, Colombia, Mexico City, CMX, Mexico · по договорённости

Компания
Clara
Город
Bogota D.C, DC, Colombia, Mexico City, CMX, Mexico
Зарплата
по договорённости
Уровень
middle
Формат
full_time
Иностранная компания
нанимает русскоязычных

Ready to accelerate your career?

Clara is the fastest-growing company in Latin America. We've built the leading solution for companies to make and manage all their payments. We already help over 20,000 large and growing businesses operate with agility and financial clarity through locally issued corporate cards, bill pay, financing, and a powerful B2B platform built for scale.

Clara is backed by some of the most successful investors in the world, including top regional VCs like monashees, Kaszek, and Canary, and leading global funds like Notable Capital, Coatue, DST Global Partners, ICONIQ Growth, General Catalyst, Citi Ventures, SV Angel, Citius, Endeavor Catalyst, and Goldman Sachs - in addition to dozens of angel investors and local family offices. We’re building the financial infrastructure that powers high-performing organizations across the region. We invite you to join us if you want to be part of a fast-paced environment that will accelerate your career and support you to do some of the best work of your life alongside a passionate and committed team distributed across the Americas.

Security Engineer

What you'll do

You will own outcomes, not a queue. You'll lead workstreams across the security function, pair with and mentor early-career engineers, and be trusted to make calls without waiting for sign-off.

Own the AI security posture, enabling rather than blocking

Define and operate the controls for how Clara uses LLMs, coding agents, agentic browsers, MCP integrations and internal inference gateways: data handling, identity, permissions, logging

Own the LLM-based investigation agent on the SIEM: design its instructions and rules, evaluate its accuracy, catch hallucinated attributions and unsupported conclusions, and decide what it is allowed to close autonomously

Threat-model AI systems as first-class attack surface: prompt injection, data exfiltration through AI tools, over-privileged agents, model and tool supply chain

Build the guidance and paved paths that let product and engineering adopt AI safely by default, and be a credible voice in those decisions

Cloud security on AWS and GCP

Own detection and posture across AWS (GuardDuty, IAM, VPC, CloudTrail) and GCP (Security Command Center, IAM, service accounts, org policies), and drive remediation with the owning teams

Design and implement guardrails as code: organization policies, SCPs, IAM boundaries, infrastructure-as-code policy checks

Lead parts of our large-scale GCP project inventory and cleanup program, and turn one-off findings into automated controls

Secure identity and edge: Auth0, Cloudflare, Google Workspace, SSO and service-to-service authentication

Secure code, CI/CD and application security

Run and evolve the application security program: SAST (SonarQube, Semgrep or similar), dependency and secrets scanning, PR review for security-sensitive changes, and CI/CD pipeline hardening

Review architecture and code for new products and integrations (card issuing, payments, banking partners) and produce actionable, prioritized findings

Define secure-by-default patterns and libraries for engineers, including for AI-generated code, and measure whether they're being used

Coordinate pentests and vulnerability disclosure, and drive findings to closure

Detection, response and incident leadership

Build and tune detections in Splunk across identity/SSO, cloud, endpoint, email and network sources, with a bias toward high-signal alerts

Lead incident investigation and response through incident.io: scoping, containment (EDR isolation, credential revocation, cloud access), root cause and post-incident review

Own email and web protection policy and the phishing program

Mentor early-career engineers on investigation technique and evidence-based reporting, and review their work

Compliance as a byproduct of good engineering

Map your controls to PCI DSS and ISO 27001 requirements, and produce the evidence auditors need without

Открыть и откликнуться →

Отклик ведёт на сайт работодателя. Бесплатная регистрация открывает отклик и разбор резюме.