Senior Security Engineer
Hace 2 días
Madero municipio, Estado de Michoacán, México
Nelo Aps
Jornada completa
Gratis con email o Google
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Gratis con email o Google
Security Engineer
Nelo is a leading consumer fintech and e-commerce platform in Mexico, with $500MM in annualized GMV and $75MM in annualized revenue. Our mission is to increase the buying power of consumers in Latin America, and we are doing so by building a modern alternative to credit cards. Nelo has raised over $40M of venture capital from investors including Homebrew, Two Sigma Ventures and Susa Ventures. Nelo has additionally raised a $100M asset credit facility from Victory Park Capital. Our lean team includes experienced leaders from top technology companies including Uber, Amazon, Rappi, and DiDi. Security has been part of how Nelo builds software from day one. As we scale, we are creating a dedicated Security Engineer role with broad ownership across application security, cloud infrastructure, and internal controls. This is a hands-on role for someone who wants to define the security function rather than inherit it. You will decide where to invest, implement controls yourself, and balance risk against velocity in a fast-moving lending business. This role is in-person at our Mexico City office in Condesa. Build secure-by-default systems Design and implement security guardrails across cloud infrastructure and developer workflows
Improve IAM, secrets management, endpoint management, and access controls across production systems
Harden AWS infrastructure using Terraform and policy-as-code
Increase observability for security-relevant events and anomalies
Treat security as an engineering problem Write code, configs, and tooling to enforce controls
Replace manual reviews with automation wherever it makes sense
Run external security programs Own penetration tests and the bug bounty program end-to-end
Build automated evidence collection so compliance does not become a recurring tax on the team
Review designs and PRs with a security-first lens
You have built security programs at a startup before and know the difference between security theater and controls that actually reduce risk. Terraform, Python, Go, whatever the job calls for. You do not hand off implementation to someone else and call it done.
You have deep AWS instincts. You know where the sharp edges are in IAM, how to read CloudTrail, when GuardDuty findings matter and when they are noise.
You have taken a company through SOC 2 or a comparable certification and you know how to run it without grinding engineering to a halt. You use Claude Code or similar to move faster, and you have opinions about where they belong in a security review and where they do not.
You can hold a strong security position and still ship product on time. You see velocity and security as the same problem, not opposing ones.
You want to manage a team of security engineers. You see security as a gatekeeping function. If your instinct is to slow things down rather than redesign them, the engineering team will route around you.
Most of it does not. If you are skeptical of agentic coding tools or refuse to use them, you will be working against the grain of how engineering moves here.
Lean, fast, opinionated about quality.
This role is based in Mexico City and is expected to be in-office given the proximity required with engineering and infrastructure work.
Engineering is no exception.
Required Engineering background with substantial time spent on security in production environments
Strong hands-on experience with cloud security fundamentals, ideally on AWS
Comfortable building and modifying infrastructure with Terraform or equivalent IaC tooling
Depth in AWS security primitives such as GuardDuty, CloudTrail, IAM, VPC, KMS, and security groups
You use Claude Code or other agentic coding tools as part of your daily workflow
100% medical, dental, and vision coverage