Senior Application Security Engineer

hace 2 semanas


Ciudad de México, Ciudad de México Félix A tiempo completo
About Us
At Félix, we're building the financial ecosystem for Latin immigrants in the U.S., starting with a revolution in remittances. Our core product is an AI-powered chatbot powered by WhatsApp, allowing our users to send money home as easily as sending a text message. We leverage cutting-edge technology like AI, blockchain, and stablecoins to make cross-border payments faster, more affordable, and more accessible than ever before. 
We are a hyper-growth Series B company, backed by over $100 million in funding from top-tier global investors, including QED, Castle Island, Switch Ventures, HTwenty, Monashees, and General Catalyst Customer Value Fund. This isn't just about the numbers; it's a testament to the trust our investors have in our vision and our team. Additionally, Félix was selected as an "Endeavour Entrepreneur" and was a recipient of the CrossTech Fintech Startups Award. We are a group of extremely talented and dedicated high-performers, united by our shared obsession with a single goal: empowering our customers. We are all owners of Félix, driven by a bias for action and a true experimentation spirit to get shit done with urgency and focus.
Joining Félix means you will be part of a team building a legacy, a company that will outlive us all. This is a rare opportunity to apply your skills to a deeply meaningful mission—serving a community that has been underserved for too long. We are a team that is fiercely loyal to each other, where radical transparency and constructive feedback are how we grow and push for excellence. We are bold, we care less about what others are doing, and more about creating sustainable value and a product that truly makes our users' lives better. We are building the future, today.
About the Role
As a Senior Application Security Engineer, you will be a critical part of our SecOps team, working alongside Damian Finol, our Head of EngOps. You will be responsible for embedding security into every stage of our software development lifecycle (SDLC). This is a hands-on role for a builder who is passionate about shifting security left and empowering developers to ship secure code, quickly and confidently. You will be instrumental in maturing our DevSecOps practices, building out our security automation, and ensuring our platform meets the stringent security and compliance requirements of the fintech landscape, including our goals for SOC 2 Type I readiness.
Responsibilities
Build and Automate Secure CI/CD Pipelines: Design, implement, and maintain security controls within our GitHub Actions CI/CD pipelines. You will be hands-on with tools for Static Application Security Testing (SAST), Software Composition Analysis (SCA), Infrastructure-as-Code (IaC) scanning, and secret detection.Drive Vulnerability Management: Take ownership of our vulnerability management program using platforms like DefectDojo. You will work closely with engineering teams to triage findings, prioritize remediation efforts, and reduce our overall risk profile.Champion Secure Development: Act as a security subject matter expert for our product engineering teams. You will conduct security architecture reviews, perform threat modeling for new features , and promote secure coding best practices across our Python-based services.Coordinate Security Assessments: Manage and support internal and external penetration testing engagements, track findings, and drive remediation efforts with the relevant teams.Develop Security Standards: Help define and document foundational security requirements for source code management, secrets management, and our CI/CD processes to ensure they are secure by design.Support Compliance Initiatives: Partner with our GRC function to implement necessary application security controls and gather evidence to support our SOC 2 and PCI compliance audits.
Requirements
Proven experience as an Application Security Engineer, Product Security Engineer, or in a similar role.Hands-on experience building, securing, and operating CI/CD pipelines, preferably with GitHub Actions.Strong proficiency with security scanning tools (e.g., SAST, DAST, SCA, secret scanning).Proficiency in a scripting or programming language, with a strong preference for Python to align with our primary tech stack.Deep understanding of web application vulnerabilities, secure architecture principles, and the OWASP Top 10.Experience working with cloud-native technologies and environments (GCP, Kubernetes/GKE, Docker).Experience in a regulated industry (Fintech, Healthcare, etc.) and familiarity with compliance frameworks like SOC 2 and PCI DSS.Experience with Infrastructure-as-Code tools like Terraform and related security scanners (e.g., Checkov).Familiarity with vulnerability management platforms like DefectDojo.These are the applicable requisites, although equivalent competencies in any of the above will also be considered.
What We Offer
Competitive salaryInitial stock options grantAnnual performance bonusHealth, dental, and vision plans Remote work environment, although we have offices in Miami and México City and would love to work in hybrid model if you are up to it.Continuous learning opportunities Unlimited PTOPaid parental leaveEmpowering opportunities for growth in a dynamic entrepreneurial environment
Equal Opportunity Employer
At Félix, we are committed to providing equal employment opportunities to all qualified employees and applicants without regard to race, religion, nationality, sex, sexual orientation, gender identity, age, or disability. This policy applies to all terms and conditions of employment, including recruitment, hiring, placement, promotion, training, compensation, benefits, and termination.
Want to learn more about our privacy practices? Check out our Privacy Policy.

  • Ciudad de México, Ciudad de México Avantor A tiempo completo

    The Opportunity:Under limited supervision, responsible for the operations of secure and highly available computing platforms, servers, and networks. Install, maintain, upgrade, and continuously improve the company's operating environment. Maintain the ongoing reliability, performance and support of the infrastructure. Deploy the release of new technologies...


  • Ciudad de México, Ciudad de México TTEC A tiempo completo

    Application Security EngineerBe the spark that brightens days and ignite your career with TTEC's award-winning employment experience. As an Application Security Engineer working remotely in Mexico, you'll be a part of creating and delivering amazing customer experiences while you also #experienceTTEC, an award-winning employment experience and company...

  • Senior Security Engineer

    hace 2 semanas


    Ciudad de México, Ciudad de México Sequoia Connect A tiempo completo

    Our client is a rapidly growing, automation-led service provider specializing in IT, business process outsourcing (BPO), and consulting services. With a strong focus on digital transformation, cloud solutions, and AI-driven automation, they help businesses optimize operations and enhance customer experiences. Backed by a global workforce of over 32,000...


  • Ciudad de México, Ciudad de México Udemy A tiempo completo

    Join Udemy. Helpdefinethe future of learning.Udemy is an AI-powered skills acceleration platform built to help people and teams grow. It's personalized, practical, and focused on real-world impact.Our mission is simple: to transform lives through learning. Your work helps people around the world build skills they can use, whether they're picking up something...

  • Security Engineer

    hace 2 semanas


    Ciudad de México, Ciudad de México Nir Yu A tiempo completo

    The Role:We collaborate with our client to assist the world's largest companies in breaking down data silos, enabling teams to make quicker, more informed decisions. Their flagship product represents the most practical application of Knowledge Graphs and semantic technology available today, allowing Fortune 1000 companies to enhance the discovery,...


  • Ciudad de México, Ciudad de México McDonald's A tiempo completo

    McDonald's new growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts, we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital and Drive Thru)....


  • Ciudad de México, Ciudad de México Lyft A tiempo completo

    At Lyft, our purpose is to serve and connect. We aim to achieve this by cultivating a work environment where all team members belong and have the opportunity to thrive.Lyft connects people to transportation to change the way we live and get around our communities. Lyft's engineering team is growing, and we are looking for Engineers  with a passion in...

  • Product Security Engineer

    hace 2 semanas


    Ciudad de México, Ciudad de México Aspen Technology A tiempo completo

    The driving force behind our success has always been the people of AspenTech. What drives us, is our aspiration, our desire and ambition to keep pushing the envelope, overcoming any hurdle, challenging the status quo to continually find a better way. You will experience these qualities of passion, pride and aspiration in many ways — from a rich set of...


  • Ciudad de México, Ciudad de México McDonald's Corporation A tiempo completo

    Company Description McDonald's new growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts, we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital...


  • Ciudad de México, Ciudad de México Stefanini Latam A tiempo completo

    DescriptionSé parte de Stefanini En Stefanini somos más de genios, conectados desde 41 países, haciendo lo que les apasiona y co-creando un futuro mejor.Seguro no te quieres quedar fueraResponsibilities We're Hiring Senior Application Packager (Latin America) Remote | USD Salary via Deel | Flexible Allocation (80 hrs/month)We are looking for an...