Ic5 - Staff Engineer - Devsecops

Spin

Hermosillo

Presencial

MXN 1.200.000 - 1.900.000

Jornada completa

Hace 8 días
Generador de candidaturas

No envíes un currículum genérico: crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Descripción de la vacante

Spin is seeking a Staff SecDevOps Engineer to drive security across fintech platforms. You will embed automated security testing in CI/CD, harden cloud and container environments, and partner with teams to shift security left while preserving availability and data integrity.

You will mentor junior engineers, influence cross-functional security practices, and shape the security roadmap with strategic tool evaluations.

Formación

  • 8+ years in Information Security, DevOps, or Platform Engineering, preferably fintech or tech.
  • Hands-on CI/CD with security testing integrated into pipelines.
  • Expert in Terraform/CloudFormation and CSPM practices.

Responsabilidades

  • Embed automated security testing into build and deployment pipelines.
  • Define and enforce security guardrails for IaC and cloud workloads.
  • Design tooling for vulnerability detection and remediation workflows.
  • Develop and enforce security policies across cloud, CI/CD, and on-prem environments.
  • Oversee security monitoring (SIEM) and lead incident response and root-cause analysis.
  • Lead audits for compliance with NIST, ISO 27001, OWASP, etc.
  • Mentor engineers in secure coding and DevSecOps practices.
  • Contribute to the security roadmap and evaluate new tools.

Conocimientos

CI/CD & DevSecOps
Automation scripting
Cloud security
IaC & policy-as-code
Secrets management
Incident response
Communication
Problem solving
Execution under pressure
English proficiency

Educación

Bachelor's degree in Systems Engineering/CS/IT

Herramientas

Terraform
CloudFormation
Kubernetes
Checkov
tfsec
Jenkins
GitHub Actions
GitLab CI

Descripción del empleo

Objective of the Role

As a Staff SecDevOps Engineer, you will drive the integration of security into our software development lifecycle and cloud infrastructure across our fintech B2C and B2B platforms. You will build automated security guardrails into CI/CD pipelines, harden cloud and container environments, and partner closely with engineering teams to shift security left, while ensuring the availability, integrity, and confidentiality of systems and data. Additionally, you will provide strategic guidance, mentorship, and leadership to junior engineers and cross-functional teams.

Main Responsibilities
  • CI/CD Security Integration: Embed automated security testing (SAST, DAST, SCA) into build and deployment pipelines across engineering teams.
  • Infrastructure-as-Code & Cloud Security: Define and enforce security guardrails for Terraform/CloudFormation, container images, and Kubernetes workloads.
  • Security Automation: Design and build tooling to automate vulnerability detection, remediation workflows, and continuous compliance checks.
  • Policy Development and Enforcement: Develop, implement, and enforce security policies and access controls across cloud, CI/CD, and on-premise environments.
  • Security Monitoring and Incident Response: Oversee security monitoring (SIEM/SOC), and lead investigation, response, and root cause analysis of security incidents.
  • Security Audits and Compliance: Lead internal and external security audits, ensuring alignment with NIST, ISO 27001, OWASP, and other relevant frameworks.
  • Mentorship and Enablement: Train and mentor engineering teams on secure coding, DevSecOps practices, tools, and technologies.
  • Strategic Planning and Technology Evaluation: Contribute to the security roadmap, and evaluate and recommend new security tools and technologies to enhance the platform.
Required Knowledge & Experience
  • Bachelor’s degree in Systems Engineering, Computer Science, Information Technology, or a related field.
  • 8+ years in Information Security, DevOps, or Platform Engineering (preferably in fintech or tech companies).
  • CI/CD & DevSecOps: Hands-on experience with CI/CD platforms (Jenkins, GitHub Actions, GitLab CI) and embedding security testing (SAST, DAST, SCA) into pipelines.
  • Automation & Scripting: Proficiency in Python, Go, or Bash for security automation and custom tooling.
  • Cloud & Container Security: Experience securing cloud environments (AWS, GCP, Azure), containers, and Kubernetes, including Cloud Security Posture Management (CSPM).
  • IaC & Policy-as-Code: Expertise in Infrastructure-as-Code (Terraform, Ansible, CloudFormation) and IaC security scanners (e.g., Checkov, tfsec).
  • Secrets & Network Security: Familiarity with secrets management (HashiCorp Vault, AWS KMS), policy-as-code, and network security (firewalls, IDS/IPS, VPN, encryption, SIEM/SOC).
  • Frameworks & Incident Response: Strong knowledge of security frameworks (NIST, ISO 27001, OWASP) and experience in security incident management and root-cause analysis.
  • Relevant certifications such as CISSP, CEH, CompTIA Security+, AWS Certified Security – Specialty, or Certified Kubernetes Security Specialist (CKS).
  • Communication & Influence: Excellent collaboration skills to drive security best practices across engineering teams.
  • Problem-Solving & Adaptability: Strong analytical capabilities, a focus on continuous process improvement, and the agility to adapt quickly to evolving technologies.
  • Execution Under Pressure: Proven ability to manage multiple priorities simultaneously in high-pressure environments.
  • Language: Intermediate English proficiency.

En Spin estamos comprometidos con construir un lugar de trabajo diverso e inclusivo.

Creemos en la igualdad de oportunidades y promovemos un entorno libre de discriminación por motivos de raza, origen nacional, género, identidad de género, orientación sexual, discapacidad, edad o cualquier otra condición legalmente protegida.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

DevSecOps / Application Security
DevSecOps / Application Security

D4 Consultores • Chihuahua

Presencial
MXN 391.000 - 446.000
Prestaciones superiores
Esquema 100% nomina
DevSecOps Engineer
DevSecOps Engineer

Athenaworks • Estado de México

Presencial
MXN 1.019.000 - 1.529.000
Payment in USD
Flexible schedule
Learning budget
+1
Staff SecDevOps Engineer: Secure CI/CD & Cloud Architect
Staff SecDevOps Engineer: Secure CI/CD & Cloud Architect

Spin Careers • Ciudad de México

Presencial
MXN 900.000 - 1.500.000
DevSecOps Engineer
DevSecOps Engineer

Quo Digital • Huimilpan

Presencial
MXN 279.000 - 446.400
Gerente DevSecOps & Cloud Security
Gerente DevSecOps & Cloud Security

Paynau (formerly Red Efectiva) • Monterrey

Presencial
MXN 900.000 - 1.500.000
Gerente DevSecOps & Cloud Security
Gerente DevSecOps & Cloud Security

Red Efectiva • Monterrey

Presencial
MXN 900.000 - 1.300.000
DevSecOps
DevSecOps

Latbcconsulting • Ciudad de México

Híbrido
Prestaciones y beneficios adicionales
Oportunidades de crecimiento y desarrollo profesional
Capacitaciones y programas de formación continua
DevSecOps Engineer — Cloud Security & CI/CD Automation
DevSecOps Engineer — Cloud Security & CI/CD Automation

Orion Innovation México • Ciudad de México

Presencial
MXN 800.000 - 1.200.000
Head of Security Engineering
Head of Security Engineering

Base Labs • Ciudad de México

Presencial
MXN 1.200.000 - 1.800.000
Medical insurance
Technology Compliance Engineer
Technology Compliance Engineer

Turtle Trax S.A. • Estado de México

Híbrido
MXN 70.000 - 90.000