Security Engineer (Early Career) (Ingeniero/a de Seguridad - Carrera Temprana) - Mexico City (Hybrid)
Security Engineer (Early Career)
What you'll do
You will rotate across the security function in your first year, with real ownership from the first month. Expect the mix below to shift as the business does.
Secure the AI posture, without blocking it
Review how teams use LLMs, coding agents and AI tooling (Claude, agentic browsers, internal inference gateways) and help define guardrails that protect data without killing adoption
Operate our LLM-based investigation agent on the SIEM: catch hallucinated attributions, noisy alerts and conclusions the underlying data doesn't support, and tune its instructions before they reach production
Develop the core skill of this role: knowing when to trust an AI-generated result and when to verify it by hand
Help build our view of prompt injection, data exfiltration through AI tools, and model/agent permissions as first-class risks
Cloud security on AWS and GCP
Triage findings from AWS GuardDuty, GCP Security Command Center, IAM and network configuration reviews
Run configuration and posture checks, and drive fixes with the owning teams instead of just filing tickets
Contribute to our large-scale GCP project inventory and cleanup, and keep the central findings tracker honest
Learn Auth0, Cloudflare and Google Workspace security controls as they apply to identity, edge and SaaS
Secure code and CI/CD
Review internal tools, scripts and pull requests for the classics: hardcoded credentials, unsafe input handling, over-broad permissions, secrets in pipelines
Own SonarQube and dependency-scanning results for internal repositories: prioritize CVEs, follow up with developers, close the loop
Review CI/CD changes that touch security-sensitive configuration (secrets, deployment access, IAM bindings)
Help push secure-by-default patterns into how engineers actually work, including the code they generate with AI
Detection, response and triage
Write and refine Splunk queries to investigate alerts from identity/SSO, cloud, endpoint, email and network sources
Maintain detection rules and dashboards; hunt down false positives and false negatives
Reconstruct user activity timelines across systems and document findings with evidence, not just conclusions
Monitor the EDR console, investigate suspicious endpoints, and execute containment (host isolation, quarantine) with a senior engineer
Triage phishing reports, analyze URLs and attachments in sandbox and threat-intel tools, maintain email and web filtering policies, and run phishing simulations
Escalate fast and clearly when a finding exceeds what you can close on your own, and work incidents through incident.io
What we look for
1–2 years in security, IT, software engineering or a related technical role. Internships, CTFs, bug bounties, open-source contributions and serious personal projects all count.
Working knowledge of at least one of AWS or GCP: you know what IAM, security groups/VPC firewall rules, and a service account are, and you want to go much deeper
Comfort in the command line (bash), reading JSON and logs, and reading code in at least one common language (Python, JavaScript, Go) well enough to spot an obvious security issue
Basic familiarity with a log query language (SPL, KQL or similar), or the drive to become fluent quickly
Conceptual understanding of identity and authentication: OAuth, SSO, MFA, service-to-service auth
Hands-on experience using generative AI tools in a technical context, and a healthy skepticism about their output
A verify-before-you-conclude instinct: you never take a tool's, a vendor's or an AI agent's answer at face value without evidence
Strong written communication in Spanish and English. Much of this job is explaining findings clearly to people who aren't security engineers.
Comfort with ambiguity and pace: priorities change, the stack evolves, and you'd rather learn on the job than wait for a course
Nice to have
Prior exposure to a SIEM, EDR console (CrowdStrike, SentinelOne, Defender) or email/web security platform
Python or JavaScript for scripting and automation
Any experience with SAST/dependency scanning tooling, secrets management or CI/CD security
Experience prompting or building with LLM APIs, agents or MCP tooling
Entry-level certifications (Security+, AWS Cloud Practitioner, Google Cloud Digital Leader / Associate Cloud Engineer, or similar)
Portuguese
What you'll get
Exposure to the full security surface of a regulated fintech in your first year: cloud, code, detection, response, compliance and AI, rather than a single queue
A senior team that pairs with you on investigations and reviews, and expects you to push back when the evidence doesn't hold
Direct work on problems most security teams haven't solved yet: securing agentic AI in production
A modern stack: AWS, GCP, Splunk, Auth0, Cloudflare, SonarQube, incident.io, Claude and internal AI tooling
Budget and time for certifications, conferences and the hacker community
Fast, transparent hiring: application review, a technical conversation about real scenarios (no gotcha puzzles), a practical exercise you can do in a few hours, and a conversation with the team
How to stand out
Send us something you've built, broken or written: a repo, a CTF write-up, a bug report, a blog post, a detection rule. We care far more about how you think and how you learn than about the exact list of tools on your CV.