IC5 - Staff Engineer - DevSecOps

Spin Careers · México, México · Engineering

Posted 2026-09-01

Apply for this role →

Objective of the Role

As a Staff SecDevOps Engineer, you will drive the integration of security into our software development lifecycle and cloud infrastructure across our fintech B2C and B2B platforms. You will build automated security guardrails into CI/CD pipelines, harden cloud and container environments, and partner closely with engineering teams to shift security left, while ensuring the availability, integrity, and confidentiality of systems and data. Additionally, you will provide strategic guidance, mentorship, and leadership to junior engineers and cross-functional teams.

Main Responsibilities

CI/CD Security Integration: Embed automated security testing (SAST, DAST, SCA) into build and deployment pipelines across engineering teams.

Infrastructure-as-Code & Cloud Security: Define and enforce security guardrails for Terraform/CloudFormation, container images, and Kubernetes workloads.

Security Automation: Design and build tooling to automate vulnerability detection, remediation workflows, and continuous compliance checks.

Policy Development and Enforcement: Develop, implement, and enforce security policies and access controls across cloud, CI/CD, and on-premise environments.

Security Monitoring and Incident Response: Oversee security monitoring (SIEM/SOC), and lead investigation, response, and root cause analysis of security incidents.

Security Audits and Compliance: Lead internal and external security audits, ensuring alignment with NIST, ISO 27001, OWASP, and other relevant frameworks.

Mentorship and Enablement: Train and mentor engineering teams on secure coding, DevSecOps practices, tools, and technologies.

Strategic Planning and Technology Evaluation: Contribute to the security roadmap, and evaluate and recommend new security tools and technologies to enhance the platform.

Required Knowledge & Experience

Bachelor’s degree in Systems Engineering, Computer Science, Information Technology, or a related field.

8+ years in Information Security, DevOps, or Platform Engineering (preferably in fintech or tech companies).

CI/CD & DevSecOps: Hands-on experience with CI/CD platforms (Jenkins, GitHub Actions, GitLab CI) and embedding security testing (SAST, DAST, SCA) into pipelines.

Automation & Scripting: Proficiency in Python, Go, or Bash for security automation and custom tooling.

Cloud & Container Security: Experience securing cloud environments (AWS, GCP, Azure), containers, and Kubernetes, including Cloud Security Posture Management (CSPM).

IaC & Policy-as-Code: Expertise in Infrastructure-as-Code (Terraform, Ansible, CloudFormation) and IaC security scanners (e.g., Checkov, tfsec).

Secrets & Network Security: Familiarity with secrets management (HashiCorp Vault, AWS KMS), policy-as-code, and network security (firewalls, IDS/IPS, VPN, encryption, SIEM/SOC).

Frameworks & Incident Response: Strong knowledge of security frameworks (NIST, ISO 27001, OWASP) and experience in security incident management and root-cause analysis.

Relevant certifications such as CISSP, CEH, CompTIA Security+, AWS Certified Security – Specialty, or Certified Kubernetes Security Specialist (CKS).

Communication & Influence: Excellent collaboration skills to drive security best practices across engineering teams.

Problem-Solving & Adaptability: Strong analytical capabilities, a focus on continuous process improvement, and the agility to adapt quickly to evolving technologies.

Execution Under Pressure: Proven ability to manage multiple priorities simultaneously in high-pressure environments.

Language: Intermediate English proficiency.

Apply for this role →

← Back to all jobs