AWS Security Engineer

Hace 2 semanas

Puebla de Zaragoza Pue, Puebla (municipio); Estado de Puebla, México Clara Jornada completa
Clara is the fastest-growing company in Latin America. We've built the leading solution for companies to make and manage all their payments. We already help over 20,000 large and growing businesses operate with agility and financial clarity through locally issued corporate cards, bill pay, financing, and a powerful B2B platform built for scale. Clara is backed by some of the most successful investors in the world, including top regional VCs like monashees, Kaszek, and Canary, and leading global funds like Notable Capital, Coatue, DST Global Partners, ICONIQ Growth, General Catalyst, Citi Ventures, SV Angel, Citius, Endeavor Catalyst, and Goldman Sachs
- in addition to dozens of angel investors and local family offices. Security Engineer

What you'll do
You will own outcomes, not a queue. You'll lead workstreams across the security function, pair with and mentor early-career engineers, and be trusted to make calls without waiting for sign-off. Own the AI security posture, enabling rather than blocking Define and operate the controls for how Clara uses LLMs, coding agents, agentic browsers, MCP integrations and internal inference gateways: data handling, identity, permissions, logging Own the LLM-based investigation agent on the SIEM: design its instructions and rules, evaluate its accuracy, catch hallucinated attributions and unsupported conclusions, and decide what it is allowed to close autonomously Threat-model AI systems as first-class attack surface: prompt injection, data exfiltration through AI tools, over-privileged agents, model and tool supply chain Cloud security on AWS and GCP Own detection and posture across AWS (GuardDuty, IAM, VPC, CloudTrail) and GCP (Security Command Center, IAM, service accounts, org policies), and drive remediation with the owning teams Design and implement guardrails as code: organization policies, SCPs, IAM boundaries, infrastructure-as-code policy checks Lead parts of our large-scale GCP project inventory and cleanup program, and turn one-off findings into automated controls Auth0, Cloudflare, Google Workspace, SSO and service-to-service authentication Secure code, CI/CD and application security Run and evolve the application security program: SAST (SonarQube, Semgrep or similar), dependency and secrets scanning, PR review for security-sensitive changes, and CI/CD pipeline hardening Build and tune detections in Splunk across identity/SSO, cloud, endpoint, email and network sources, with a bias toward high-signal alerts io: scoping, containment (EDR isolation, credential revocation, cloud access), root cause and post-incident review Own email and web protection policy and the phishing program Mentor early-career engineers on investigation technique and evidence-based reporting, and review their work Map your controls to PCI DSS and ISO 27001 requirements, and produce the evidence auditors need without slowing the team down Support customer security reviews and enterprise sales when a technical voice is needed 2–4 years in security engineering, cloud security, application security or a closely related engineering role, including hands-on production experience Strong, practical knowledge of AWS and/or GCP security: IAM design, network controls, logging and detection, and the ability to read and write infrastructure as code (Terraform or similar) Solid programming ability in at least one language (Python, Go, JavaScript/TypeScript): you build tooling and automation, not just review other people's code Hands-on experience with a SIEM (Splunk preferred) and an EDR platform, including detection engineering and investigation Strong written and spoken communication in Spanish and English; Comfort with pace and ambiguity: priorities move, the stack evolves, and you'd rather build the process than wait for it Experience securing or red-teaming LLM applications, agents or MCP tooling Kubernetes and container security Detection-as-code, SOAR or security automation experience Certifications such as AWS Security Specialty, Google Professional Cloud Security Engineer, OSCP, GIAC or CISSP Portuguese Frontier work: securing agentic AI in production, in a company that is actually deploying it A modern stack and the mandate to improve it: AWS, GCP, Splunk, Auth0, Cloudflare, SonarQube, incident.
A team that values evidence over hierarchy, and expects you to push back when the data doesn't hold Budget and time for certifications, conferences and the hacker community How to stand out Tell us about a control you designed that made engineers faster, not slower. B2B fintech for spend management Certified as one of the world's fastest-growing companies, a LinkedIn Top Startup . Product-led, high-talent-density culture — designed for builders who raise the bar. Portuguese, Spanish, and English (Annual learning budget and internal accelerated development paths hybrid work model Clara's Hybrid Policy Claridians in a hybrid mo