Security Engineer

Hace 3 días

venustiano carranza, distrito federal, México Bright Machines Jornada completa
RETHINK MANUFACTURING  
 

The only way to ignite change is to build the best team. At Bright Machines®, we’re innovators and experts in our craft who have joined together to manufacture the AI and data center infrastructure at the edge. We believe unifying software, intelligent automation, and data is the answer to delivering quality and flexibility at scale. We deliver products to meet the demands of today while continuously investing in our Bright Factory model to take advantage of what comes next.   


Working with us means you’ll have the opportunity to make lasting, impactful changes for our company and our customers. If you’re ready to apply your exceptional skills to a brighter way of manufacturing AI infrastructure, we’d love to speak with you. 


ABOUT THE ROLE
 
As part of the IT organization, you will execute and enforce Bright Machines' day-to-day information security program—spanning platform security, application security, and information security compliance—across our corporate, product, and manufacturing environments. The Global IT Director, to whom this role reports, sets security policy and strategy; you'll partner with the Director on that strategy while owning hands-on execution, and you'll work closely with our Infrastructure Engineer, who owns network security execution, and with Platform Engineering, our closest partner on application security. You will own day-to-day maintenance of our existing ISO 27001:2022 certification and execution of the customer security requirements our commercial relationships depend on. Because you'll work daily with IT, Platform Engineering, Software Development, and Delivery, strong written and verbal English communication is essential. WHAT YOU WILL BE DOING


  • Execute day-to-day information security operations across corporate IT, platform, and product environments, in partnership with the Global IT Director, who sets security policy and strategy.




  • Maintain our existing ISO 27001:2022 certification: manage evidence collection, internal audits, and corrective actions, and support annual surveillance and recertification audits.




  • Execute customer security due diligence, completing security questionnaires (SIG, CAIQ), supporting customer audits, and tracking contractual security requirements, partnering with Legal and Sales as needed.




  • Partner with Platform Engineering to build application security into the SDLC: threat modeling support, secure code review guidance, and operation of SAST/DAST/SCA tooling.




  • Run vulnerability management across applications and platform infrastructure: scanning, triage, and driving remediation with engineering teams to SLA.




  • Coordinate third-party penetration tests and security assessments; track findings to closure.




  • Partner with the Infrastructure Engineer on the security posture of network and compute infrastructure, including our EDR/managed SOC and network IDS/IPS controls, keeping application and platform controls aligned with network security architecture.




  • Support security incident response: help maintain the IR plan, participate in investigations, and run periodic tabletop exercises.




  • Support identity and access governance for corporate and platform systems (access reviews, certifications, MFA/SSO enforcement) with IT Engineering.




  • Conduct security risk assessments for new vendors, tools, and third-party integrations.




  • Maintain information security policies, standards, and employee security awareness training (including phishing simulations), in line with direction from the Global IT Director.




  • Track and report on security posture, risk, and compliance status to the Global IT Director.




  • Help evaluate and prepare for future compliance initiatives (e.g., SOC 2 Type II) as prioritized by leadership.




WHAT WE WANT TO SEE


  • 5+ years of experience in security engineering, IT security, application security, or a closely related role.




  • Experience maintaining an existing ISO 27001 ISMS: evidence collection, internal audits, and support for surveillance/recertification audits. (Building an ISMS from scratch isn't required; we already hold certification.)




  • Working knowledge of application security fundamentals (OWASP Top 10, secure SDLC practices) with hands-on experience using SAST/DAST/SCA tooling (e.g., Snyk, Semgrep, Checkmarx, Burp Suite).




  • Proficiency in a scripting language (e.g., Python) for security automation, with a strong inclination toward infrastructure-as-code (e.g., Terraform, Ansible) for codifying and enforcing