Security Engineer, Application Security

hace 3 días


Ciudad de México Dropbox A tiempo completo

Role Description
As part of the Application Security team, you’ll focus on reducing risk at scale by building the security infrastructure, automation, and tooling that empowers engineers to ship secure products with confidence. We work closely with engineering and product teams throughout the software development lifecycle (SDLC), embedding secure-by-default practices and delivering scalable solutions.
Application Security Engineers create impact by designing and implementing security tooling, writing custom security rules, and building frameworks that address broad classes of vulnerabilities. In addition to proactive development, we support teams through design consultations, threat modeling, documentation, and education to uplift security culture across Dropbox.
Our Engineering Career Framework is viewable by anyone outside the company and describes what’s expected for our engineers at each of our career levels. Check out our blog post on this topic and more here.

**Responsibilities**:
Build and maintain security tools, automation, and libraries to enable secure-by-default development across engineering teams.
Design and implement custom security rules (e.g., Semgrep, CodeQL) to detect and prevent common and emerging vulnerability patterns.
Conduct security consultations and threat modeling sessions, and clearly communicate risk and mitigation strategies to technical and non-technical stakeholders.
Improve and scale the Secure Development Lifecycle (SDLC) by integrating tools, checks, and processes into engineering workflows.
Perform targeted code and design reviews, and develop follow-up tooling or controls to prevent regressions.
Collaborate cross-functionally with engineering, product, GRC, and AI/ML teams to proactively address security risks, especially in fast-moving and emerging tech areas.
On-call work may be necessary occasionally to help address bugs, outages, or other operational issues, with the goal of maintaining a stable and high-quality experience for our customers.
**Requirements**:
Hands-on experience building or using security automation tools to improve developer workflows and product security.
Demonstrated ability to work across the SDLC, including supporting and interpreting findings from penetration tests and bug bounty reports.
Familiarity with modern tech stacks, including microservices, CI/CD pipelines, and cloud-native environments.
Solid understanding of common vulnerability classes (e.g., injection, XSS, authN/authZ issues) and practical mitigation strategies.
Comfortable working in cross-functional environments and supporting multiple product and engineering teamssimultaneously.
Experience participating in or supporting incident response or security on-call rotations is a plus
Preferred Qualifications
Demonstrated ability to write and maintain custom security rules and integrate them into developer workflows.
Experience with machine learning systems, particularly generative AI, and the ability to support secure development in AI-driven products.
Experience developing internal libraries or frameworks that reduce or eliminate entire classes of vulnerabilities.
Proficient in software development, with experience contributing production-level code in one or more modern languages.
Experience with data security, including tooling for data protection, access control, and encryption.
Strong communication skills and ability to build trusted partnerships with cross-functional teams.
Company Description
Dropbox isn’t just a workplace—it’s a living lab for more enlightened ways of working. We're a global community of bold visionaries and resourceful doers who are shaping the future of Dropbox—and with it the future of work. Our Virtual First model combines the autonomy of a distributed workplace with the power of human connection, making space for both meaningful work and meaningful relationships. With our start-up mindset and enterprise-level opportunities, you can be who you are and grow into who you’re meant to be. Here, you can own your impact to make work more intuitive, joyful, and human—for you as a Dropboxer and for hundreds of millions of people worldwide. If you're ready to push boundaries—and yourself— Dropbox is ready for you.
Team Description
The Dropbox Engineering Team builds the technology that creates more enlightened ways of working for hundreds of millions of people. Every day, our platforms—including Dropbox Dash, Dropbox Sign, and our core sync engine—handle over a billion files for users worldwide, creating engineering challenges as great as the opportunity for impact. Our software engineering team uses a range of technologies to solve interesting problems, including Python, React, Node.js, JavaScript, MongoDB, PostgreSQL, and Android development. We think like a startup but build for an enterprise, exploring new possibilities that transform how people work. If you're excited about turning complex technical challenges into intuitive solutions at scale, join our Eng



  • Ciudad de México TTEC A tiempo completo

    Application Security Engineer**Application Security Engineer**Be the spark that brightens days and ignite your career with TTEC’s award-winning employment experience. As an Application Security Engineer working remotely in Mexico, you’ll be a part of creating and delivering amazing customer experiences while you also #experienceTTEC, an award-winning...


  • Ciudad de México, Ciudad de México TTEC A tiempo completo

    Application Security EngineerBe the spark that brightens days and ignite your career with TTEC's award-winning employment experience. As an Application Security Engineer working remotely in Mexico, you'll be a part of creating and delivering amazing customer experiences while you also #experienceTTEC, an award-winning employment experience and company...


  • México AgileEngine A tiempo completo

    We are looking for a collaborative Application Security Engineer to join our international team of 1000+ software experts. If challenging tasks and an agile environment are your cup of tea, we'd like to get to know you.**WHAT YOU NEED TO SUCCEED**- Be agile to pick up new languages and skills and deliver new solutions to unexpected problems.- Be willing to...


  • México AgileEngine A tiempo completo

    We are looking for a collaborative Application Security Engineer to join our international team of 1000+ software experts. If challenging tasks and an agile environment are your cup of tea, we'd like to get to know you. **WHAT YOU NEED TO SUCCEED** - Be agile to pick up new languages and skills and deliver new solutions to unexpected problems. - Be willing...


  • Ciudad de México Dropbox A tiempo completo

    Role DescriptionAs part of the Application Security team, you’ll focus on reducing risk at scale by building the security infrastructure, automation, and tooling that empowers engineers to ship secure products with confidence. We work closely with engineering and product teams throughout the software development lifecycle (SDLC), embedding...

  • AWS Security Engineer

    hace 4 semanas


    Ciudad de México Tata Consultancy Services A tiempo completo

    TATA* is looking for Mid Container Security Engineer. hybrid mode. Collaborate with application and DevOps teams to analyze scan results, prioritize findings, and guide remediation. GitHub Actions, GitLab CI, Jenkins). Develop and maintain automation scripts in Python or Shell for reporting, alerting, and compliance tracking. Enforce...


  • Ciudad de México Immunotec A tiempo completo

    Immunotec is a privately held company whose mission is to offer, through a sales network, high quality nutritional and wellness products supported by scientific research that improve quality of life and performance. Immunotec has offices in Canada, United States, Dominican Republic, Mexico, Guatemala, Colombia, Peru, Ecuador, Bolivia, Ireland and Spain. The...


  • Ciudad de México TD SYNNEX A tiempo completo

    **Job Description Summary**:TD SYNNEX Corporation, a $60B global distributor is dedicated to protect the enterprise and our supply chain partners from cyber security risks. That's especially true today as new risks and complexities brought on by regulatory mandates, rapidly evolving technologies, and the digitalization of business operations are disrupting...


  • Ciudad de México, Ciudad de México Avantor A tiempo completo

    The Opportunity:Under limited supervision, responsible for the operations of secure and highly available computing platforms, servers, and networks. Install, maintain, upgrade, and continuously improve the company's operating environment. Maintain the ongoing reliability, performance and support of the infrastructure. Deploy the release of new technologies...


  • Toluca de Lerdo, México GitLab A tiempo completo

    A leading software company seeks a Senior Security Engineer to ensure application security and prevent vulnerabilities in the software development lifecycle. The ideal candidate will have over 5 years of experience in application security practices and solid programming knowledge. This remote position values a collaborative approach and effective...