Head Of Security

Tonder

Xico

Presencial

MXN 1.000.000 - 1.500.000

Jornada completa

Hace 7 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Destaca para este puesto: genera un currículum y una carta de presentación adaptados en cuestión de un minuto.

Supera los filtros ATS

Descripción de la vacante

Tonder is building payments infrastructure for Latin America, and security is a core part of the product. We’re looking for a Head of Security to own and strengthen Tonder’s security program across infrastructure, engineering, compliance, and operations.

This hands-on leadership role defines the security roadmap and ensures controls are implemented, automated, monitored, and improved over time, working closely with Engineering and leadership.

Formación

  • Strong experience leading security in fintech, payments, or regulated environments.
  • Deep understanding of AWS security, IAM, networking, secrets, cloud architecture, and production systems.
  • Experience with DevSecOps, application security, infrastructure security, and vulnerability management.
  • Experience with PCI DSS and security compliance programs.
  • Strong incident response, threat modeling, security architecture, and risk management.
  • Ability to go deep technically while also setting strategy and priorities.
  • Experience working with engineering teams and senior leadership.
  • Strong automation mindset and ability to turn security requirements into code, tooling, and workflows.
  • Advanced use of AI for security analysis, automation, monitoring, and engineering productivity.
  • High ownership and urgency to drive security projects from risk identification through remediation.

Responsabilidades

  • Own security strategy, roadmap, priorities, and posture.
  • Lead cloud, application, infrastructure security, IAM, secrets management, and production access controls.
  • Build security into the engineering lifecycle through DevSecOps, CI/CD controls, automated testing, scanning, and remediation.
  • Own vulnerability management from detection through remediation and validation.
  • Lead security incident response, investigation, containment, root‑cause analysis, and post‑incident improvements.
  • Own PCI DSS and other security/compliance programs.
  • Review architecture with Engineering to identify risks and define secure‑by‑design controls.
  • Build automated and AI‑assisted security workflows for monitoring, evidence collection, remediation, analysis, and operational security tasks.
  • Own third‑party security reviews, vendor security assessments, penetration testing, and remediation programs.
  • Define security metrics, dashboards, alerts, and reporting for leadership.
  • Continuously identify systemic risks and turn them into durable technical controls.
  • Help build security team, processes, and operating model as Tonder scales.

Conocimientos

AWS security
IAM
DevSecOps
Application security
Infrastructure security
Vulnerability management
PCI DSS
Security incident response
Threat modeling
Security architecture
Risk management
Automation mindset
AI for security
Leadership

Descripción del empleo

Tonder is building payments infrastructure for Latin America, and security is a core part of the product.

We’re looking for a Head of Security to own and continuously strengthen Tonder’s security program across infrastructure, engineering, compliance, and operations.

This is a hands‑on leadership role. You’ll define the security roadmap, work directly with Engineering and leadership, and make sure security controls are not only documented, but actually implemented, automated, monitored, and improved over time.

We want someone who can combine strong technical judgment with execution — from cloud security and DevSecOps to PCI, incident response, risk management, and security architecture.

What you’ll own
  • Own Tonder’s security strategy, roadmap, priorities, and overall security posture.
  • Lead cloud security, application security, infrastructure security, IAM, secrets management, and production access controls.
  • Build security directly into the engineering lifecycle through DevSecOps, CI/CD controls, automated testing, scanning, and remediation.
  • Own vulnerability management from detection through remediation and validation.
  • Lead security incident response, investigation, containment, root‑cause analysis, and post‑incident improvements.
  • Own and continuously improve PCI DSS and other relevant security and compliance programs.
  • Work closely with Engineering to review architecture, identify risks, and define secure‑by‑design controls.
  • Build automated and AI‑assisted security workflows for monitoring, evidence collection, remediation, analysis, and operational security tasks.
  • Own third‑party security reviews, vendor security assessments, penetration testing, and remediation programs.
  • Define security metrics, dashboards, alerts, and reporting for leadership.
  • Continuously identify systemic risks and turn them into durable technical controls instead of recurring manual processes.
  • Help build the security team, processes, and operating model as Tonder scales.
What we’re looking for
  • Strong experience leading security in fintech, payments, financial services, or another highly regulated environment.
  • Deep understanding of AWS security, IAM, networking, secrets, cloud architecture, and production systems.
  • Strong experience with DevSecOps, application security, infrastructure security, and vulnerability management.
  • Experience with PCI DSS and security compliance programs.
  • Strong understanding of incident response, threat modeling, security architecture, and risk management.
  • Ability to go deep technically while also setting strategy and priorities.
  • Experience working directly with engineering teams and senior leadership.
  • Strong automation mindset and ability to turn security requirements into code, tooling, and workflows.
  • Advanced use of AI for security analysis, automation, monitoring, and engineering productivity.
  • High ownership, urgency, and the ability to drive security projects from risk identification through actual remediation.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Head of Security & DevSecOps (Fintech)
Head of Security & DevSecOps (Fintech)

Nodi • Ciudad de México

Presencial
MXN 1.800.000 - 3.200.000
FinTech Security & Cloud Architecture Lead
FinTech Security & Cloud Architecture Lead

Tonder • Xico

Presencial
MXN 1.000.000 - 1.500.000
Chief Security Architect for FinTech & PCI
Chief Security Architect for FinTech & PCI

tonder • Ciudad de México

Presencial
MXN 1.800.000 - 2.400.000
Head of Security Engineering
Head of Security Engineering

Base Labs • Ciudad de México

Presencial
MXN 1.200.000 - 1.800.000
Medical insurance
DevSecOps Engineer
DevSecOps Engineer

Athenaworks • Estado de México

Presencial
MXN 1.019.000 - 1.529.000
Payment in USD
Flexible schedule
Learning budget
+1
Ic5 - Staff Engineer - Devsecops
Ic5 - Staff Engineer - Devsecops

Spin • Hermosillo

Presencial
MXN 1.200.000 - 1.900.000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

A2MAC1 • Santiago de Querétaro

Presencial
MXN 1.200.000 - 1.800.000
Biweekly Payment
IMSS
Christmas Bonus
+5
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

A2MAC1 - Decode the future • Santiago de Querétaro

Presencial
MXN 700.000 - 1.100.000
Biweekly pay
IMSS
Christmas bonus
+6
Senior Security Application Engineer - Automation & Detection
Senior Security Application Engineer - Automation & Detection

PVH (Tommy Hilfiger/Calvin Klein) • Región Centro

Presencial
MXN 2.099.000 - 3.150.000
Solution Architect
Solution Architect

EPAM Systems, Inc. • México

Presencial
MXN 900.000 - 1.400.000