Security Engineer (Ingeniero/a de Seguridad)

clara

Bogotá ciudad

Presencial

COP 248.316.000 - 372.474.000

Jornada completa

Hace 6 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Consigue una respuesta de este empleador — un currículum y una carta de presentación adaptados exactamente a lo que busca para contratar.

Supera los filtros ATS

Descripción de la vacante

Clara is the fastest-growing company in Latin America, delivering a leading payments platform for large businesses. We’re building the financial infrastructure that powers high-performing organizations across the region, with a fast-paced environment and teams distributed across the Americas.

We’re hiring a Security Engineer to own outcomes, lead security workstreams, and mentor junior engineers. You’ll shape AI safety controls, cloud security on AWS/GCP, and guardrails to enable safe product

Formación

  • 2-4 years in security engineering or related role
  • Strong hands-on AWS and/or GCP security knowledge
  • Solid programming ability (Python/Go/TypeScript) to build tooling
  • Experience with SIEM and EDR platforms
  • Familiarity with LLM-based systems and agents

Responsabilidades

  • Own outcomes across the security function and mentor engineers
  • Define and operate controls for AI usage, data handling and logging
  • Threat-model AI systems and secure-by-default patterns
  • Secure cloud environments (AWS/GCP) and IAM, logging, and detections
  • Lead incident response and forensic investigations with SIEM and EDR tools
  • Coordinate preventive controls and audits aligned to PCI DSS and ISO 27001

Conocimientos

Security engineering
AWS/GCP security
Programming: Python/Go/JS
SIEM/EDR experience
LLM-based systems

Herramientas

Splunk
Terraform

Descripción del empleo

Ready to accelerate your career?

Clara is the fastest-growing company in Latin America. We've built the leading solution for companies to make and manage all their payments. We already help over 20,000 large and growing businesses operate with agility and financial clarity through locally issued corporate cards, bill pay, financing, and a powerful B2B platform built for scale.

Clara is backed by some of the most successful investors in the world, including top regional VCs like monashees, Kaszek, and Canary, and leading global funds like Notable Capital, Coatue, DST Global Partners, ICONIQ Growth, General Catalyst, Citi Ventures, SV Angel, Citius, Endeavor Catalyst, and Goldman Sachs - in addition to dozens of angel investors and local family offices.

We're building the financial infrastructure that powers high-performing organizations across the region. We invite you to join us if you want to be part of a fast-paced environment that will accelerate your career and support you to do some of the best work of your life alongside a passionate and committed team distributed across the Americas.

Security Engineer
What you'll do
  • You will own outcomes, not a queue. You'll lead workstreams across the security function, pair with and mentor early-career engineers, and be trusted to make calls without waiting for sign-off.
  • Own the AI security posture, enabling rather than blocking
  • Define and operate the controls for how Clara uses LLMs, coding agents, agentic browsers, MCP integrations and internal inference gateways: data handling, identity, permissions, logging
  • Own the LLM-based investigation agent on the SIEM: design its instructions and rules, evaluate its accuracy, catch hallucinated attributions and unsupported conclusions, and decide what it is allowed to close autonomously
  • Threat-model AI systems as first-class attack surface: prompt injection, data exfiltration through AI tools, over-privileged agents, model and tool supply chain
  • Build the guidance and paved paths that let product and engineering adopt AI safely by default, and be a credible voice in those decisions
  • Cloud security on AWS and GCP
  • Own detection and posture across AWS (GuardDuty, IAM, VPC, CloudTrail) and GCP (Security Command Center, IAM, service accounts, org policies), and drive remediation with the owning teams
  • Design and implement guardrails as code: organization policies, SCPs, IAM boundaries, infrastructure-as-code policy checks
  • Lead parts of our large-scale GCP project inventory and cleanup program, and turn one-off findings into automated controls
  • Secure identity and edge: Auth0, Cloudflare, Google Workspace, SSO and service-to-service authentication
  • Secure code, CI/CD and application security
  • Run and evolve the application security program: SAST (SonarQube, Semgrep or similar), dependency and secrets scanning, PR review for security-sensitive changes, and CI/CD pipeline hardening
  • Review architecture and code for new products and integrations (card issuing, payments, banking partners) and produce actionable, prioritized findings
  • Define secure-by-default patterns and libraries for engineers, including for AI-generated code, and measure whether they're being used
  • Coordinate pentests and vulnerability disclosure, and drive findings to closure
  • Detection, response and incident leadership
  • Build and tune detections in Splunk across identity/SSO, cloud, endpoint, email and network sources, with a bias toward high-signal alerts
  • Lead incident investigation and response through incident.io: scoping, containment (EDR isolation, credential revocation, cloud access), root cause and post-incident review
  • Own email and web protection policy and the phishing program
  • Mentor early-career engineers on investigation technique and evidence-based reporting, and review their work
  • Compliance as a byproduct of good engineering
  • Map your controls to PCI DSS and ISO 27001 requirements, and produce the evidence auditors need without slowing the team down
  • Support customer security reviews and enterprise sales when a technical voice is needed
What we look for
  • 2-4 years in security engineering, cloud security, application security or a closely related engineering role, including hands‑on production experience
  • Strong, practical knowledge of AWS and/or GCP security: IAM design, network controls, logging and detection, and the ability to read and write infrastructure as code (Terraform or similar)
  • Solid programming ability in at least one language (Python, Go, JavaScript/TypeScript): you build tooling and automation, not just review other people's code
  • Real secure-code experience: you can find and explain injection, auth/authz, secrets handling and supply-chain issues in code and in CI/CD pipelines, and you know how to get developers to fix them
  • Hands‑on experience with a SIEM (Splunk preferred) and an EDR platform, including detection engineering and investigation
  • Working understanding of LLM-based systems and agents, including their f
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

engineering Security Engineer (Ingeniero/a de Seguridad) Clara LATAM Base ATS verificado Acepta LATAM Publicado hoy +118 puestos en esta empresa Engineering/ Builders about 5 hours ago · Bogota D.C. / DC / Colombia; Mexico City / CDMX / Mexico
engineering Security Engineer (Ingeniero/a de Seguridad) Clara LATAM Base ATS verificado Acepta LATAM Publicado hoy +118 puestos en esta empresa Engineering/ Builders about 5 hours ago · Bogota D.C. / DC / Colombia; Mexico City / CDMX / Mexico

WhateverAI • Bogotá ciudad

Híbrido
COP 90.000.000 - 120.000.000
ESOP
Annual learning budget
Hybrid work model
Security Engineer (Ingeniero/a de Seguridad) New Bogota D.C. / DC / Colombia; Mexico City / CDMX / Mexico
Security Engineer (Ingeniero/a de Seguridad) New Bogota D.C. / DC / Colombia; Mexico City / CDMX / Mexico

Clara Lending Co. • Bogotá ciudad

Híbrido
COP 277.675.000 - 401.086.000
Security Engineer: AI & Cloud Security for Fintech
Security Engineer: AI & Cloud Security for Fintech

WhateverAI • Bogotá ciudad

Híbrido
COP 90.000.000 - 120.000.000
ESOP
Annual learning budget
Hybrid work model
Security Engineer: AI & Cloud Defense
Security Engineer: AI & Cloud Defense

clara • Bogotá ciudad

Presencial
COP 248.316.000 - 372.474.000
Security Engineer: AI & Cloud Security Leader
Security Engineer: AI & Cloud Security Leader

Clara Lending Co. • Bogotá ciudad

Híbrido
COP 277.675.000 - 401.086.000
Senior Security Engineer
Senior Security Engineer

Arionkoder • Colombia

Presencial
COP 183.002.000 - 256.204.000
Competitive USD salary
20 business days of vacation
Family Leave
+1
Security Engineer - SR
Security Engineer - SR

Arionkoder • Bogotá, Distrito Capital

Presencial
COP 218.762.000 - 328.144.000
20 business days of vacation
Family Leave
Dynamic remote work culture
engineering Fullstack Software Engineer - [Ingeniero de Software Fullstack ] - Hybrid Clara LATAM Base ATS verificado Acepta LATAM Publicado hoy +94 puestos en esta empresa Engineering/ Builders about 3 hours ago · Bogotá / CUN / Colômbia
engineering Fullstack Software Engineer - [Ingeniero de Software Fullstack ] - Hybrid Clara LATAM Base ATS verificado Acepta LATAM Publicado hoy +94 puestos en esta empresa Engineering/ Builders about 3 hours ago · Bogotá / CUN / Colômbia

WhateverAI • Bogotá

Presencial
COP 90.000.000 - 140.000.000
data AI Business Operations Analyst - Bogotá (Hybrid) Clara LATAM Base ATS verificado Acepta LATAM Publicado hoy +102 puestos en esta empresa Operations about 3 hours ago · Bogota D.C. / DC / Colombia
data AI Business Operations Analyst - Bogotá (Hybrid) Clara LATAM Base ATS verificado Acepta LATAM Publicado hoy +102 puestos en esta empresa Operations about 3 hours ago · Bogota D.C. / DC / Colombia

WhateverAI • Bogotá

Híbrido
COP 120.000.000 - 180.000.000
Sr. AI Security Engineer
Sr. AI Security Engineer

Backblaze • Colombia

Presencial
COP 285.938.000 - 393.167.000