Security Engineer

Bright Machines, Inc.

Región Centro

Presencial

MXN 850.000 - 1.350.000

Jornada completa

Hace 8 días

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Bright Machines is seeking an IT security leader to run day-to-day information security across corporate IT, platform, and product environments. You will partner with the Global IT Director to enforce policy, and collaborate with Infrastructure, Platform Engineering, and Delivery teams.

You will maintain the ISO 27001:2022 certification, manage audits, and support customer security questionnaires. Strong written and verbal English is essential to engage with Legal, Sales, and technical partners

Formación

  • Experience maintaining an existing ISO 27001 ISMS with audits and surveillance support.
  • Hands-on with application security fundamentals and SAST/DAST/SCA tooling.
  • Proficiency in Python for security automation and IaC tooling (Terraform/Ansible).
  • Familiarity with cloud security (IAM, network security, encryption).
  • Able to complete customer security questionnaires and discuss security with stakeholders.

Responsabilidades

  • Execute day-to-day information security operations across corporate IT, platform, and product environments.
  • Maintain ISO 27001:2022 certification, manage evidence, audits, and remediation.
  • Handle customer security due diligence, questionnaires, and audits with Legal and Sales.
  • Collaborate with Platform Engineering to embed security into the SDLC and run SAST/DAST/SCA tooling.
  • Lead vulnerability management, triage, and remediation with engineering teams.
  • Coordinate third-party penetration tests and security assessments; track findings to closure.
  • Support security posture of network and compute infrastructure with EDR/SOC controls.
  • Contribute to incident response planning, investigations, and tabletop exercises.
  • Oversee identity and access governance with IT Engineering (MFA/SSO).
  • Perform security risk assessments for vendors and integrations.
  • Maintain security policies, standards, and awareness training.
  • Track and report security posture, risk, and compliance to leadership.
  • Assist with future compliance initiatives (e.g., SOC 2 Type II).

Conocimientos

ISO 27001
Security engineering
Audits & compliance
English proficiency
Python scripting
IaC tooling
SAST/DAST/SCA
Cloud security
EDR/ SOC
Customer security demos

Herramientas

Snyk
Semgrep
Checkmarx
Burp Suite
Terraform
Ansible

Descripción del empleo

RETHINK MANUFACTURING

Theonly way toignite changeis to build the best team. At Bright Machines®,we’reinnovators and experts in our craft who have joined together tomanufacturetheAI and data center infrastructureat the edge. We believeunifyingsoftware, intelligent automation, anddataisthe answerto delivering qualityand flexibilityatscale. We deliver products to meet the demands of today whilecontinuously investing in our Bright Factory modelto take advantage of what comes next.

Working with us meansyou’llhave the opportunity to make lasting, impactful changes for our company and our customers. Ifyou’reready to apply your exceptional skills toa brighter way of manufacturing AI infrastructure,we’dlove to speak with you.

ABOUT THE ROLE

As part of the IT organization, you will execute and enforce Bright Machines' day-to-day information security program—spanning platform security, application security, and information security compliance—across our corporate, product, and manufacturing environments. The Global IT Director, to whom this role reports, sets security policy and strategy; you'll partner with the Director on that strategy while owning hands-on execution, and you'll work closely with our Infrastructure Engineer, who owns network security execution, and with Platform Engineering, our closest partner on application security. You will own day-to-day maintenance of our existing ISO 27001:2022 certification and execution of the customer security requirements our commercial relationships depend on. Because you'll work daily with IT, Platform Engineering, Software Development, and Delivery, strong written and verbal English communication is essential.

WHAT YOU WILL BE DOING
  • Execute day-to-day information security operations across corporate IT, platform, and product environments, in partnership with the Global IT Director, who sets security policy and strategy.

  • Maintain our existing ISO 27001:2022 certification: manage evidence collection, internal audits, and corrective actions, and support annual surveillance and recertification audits.

  • Execute customer security due diligence, completing security questionnaires (SIG, CAIQ), supporting customer audits, and tracking contractual security requirements, partnering with Legal and Sales as needed.

  • Partner with Platform Engineering to build application security into the SDLC: threat modeling support, secure code review guidance, and operation of SAST/DAST/SCA tooling.

  • Run vulnerability management across applications and platform infrastructure: scanning, triage, and driving remediation with engineering teams to SLA.

  • Coordinate third-party penetration tests and security assessments; track findings to closure.

  • Partner with the Infrastructure Engineer on the security posture of network and compute infrastructure, including our EDR/managed SOC and network IDS/IPS controls, keeping application and platform controls aligned with network security architecture.

  • Support security incident response: help maintain the IR plan, participate in investigations, and run periodic tabletop exercises.

  • Support identity and access governance for corporate and platform systems (access reviews, certifications, MFA/SSO enforcement) with IT Engineering.

  • Conduct security risk assessments for new vendors, tools, and third-party integrations.

  • Maintain information security policies, standards, and employee security awareness training (including phishing simulations), in line with direction from the Global IT Director.

  • Track and report on security posture, risk, and compliance status to the Global IT Director.

  • Help evaluate and prepare for future compliance initiatives (e.g., SOC 2 Type II) as prioritized by leadership.

WHAT WE WANT TO SEE
  • 5+ years of experience in security engineering, IT security, application security, or a closely related role.

  • Experience maintaining an existing ISO 27001 ISMS: evidence collection, internal audits, and support for surveillance/recertification audits. (Building an ISMS from scratch isn't required; we already hold certification.)

  • Working knowledge of application security fundamentals (OWASP Top 10, secure SDLC practices) with hands-on experience using SAST/DAST/SCA tooling (e.g., Snyk, Semgrep, Checkmarx, Burp Suite).

  • Proficiency in a scripting language (e.g., Python) for security automation, with a strong inclination toward infrastructure-as-code (e.g., Terraform, Ansible) for codifying and enforcing security controls.

  • Familiarity with GRC platforms for compliance evidence and monitoring.

  • Basic cloud security literacy (AWS, Azure, and/or GCP): IAM, network security groups, encryption, logging and monitoring.

  • Comfortable completing customer security questionnaires and supporting customer-facing security conversations under direction.

  • Familiarity with EDR/managed SOC platforms and comfort participating in security operations and detection/response workflows.

  • Excellent written and verbal English communication skills, with the ability to communicate clearly with IT, Platform Engineering, Software Development, and Delivery stakeholders.

  • Comfortable as an execution-focused security practitioner in a lean IT organization, partnering closely with the Global IT Director, Infrastructure Engineer, Platform Engineering, and staff IT Engineers rather than working in isolation.

IT WOULD BE GREAT IF YOU HAD
  • Security certifications such as Security+, GSEC, or CCSP.

  • Experience in manufacturing, industrial, IoT, or OT/ICS security environments.

  • Exposure to penetration testing engagements, hands-on or coordinating with external testers.

  • Familiarity with Zero Trust architecture principles.

  • English language proficiency.

BE EMPOWERED TO CHANGE AN INDUSTRY

Bright Machines is a next-generation, AI-enabled manufacturer focused on data center infrastructureproduction. Bright Machines uses its proprietary AI-based robotics and software to assemble AI infrastructure hardware products (i.e., data center servers) for hyperscalers, neoclouds, and leading Original Equipment Manufacturers (OEMs) to reduce their time to revenue. With its Bright Factory model, Bright Machines builds higher quality data center infrastructure at scale, addresses increasing market demands for computing power due to the surge of AI, and answers the call to the U.S. national mandate to reshore manufacturing. Bright Machines is headquartered in San Francisco, California, with an integration center in Guadalajara, Mexico. The company has been recognized as one of Forbes’ AI 50, awarded “Best AI-based Solution for Manufacturing” by AI Breakthrough, named a “Technology Pioneer” by the World Economic Forum, and highlighted by several other leading technology and innovation organizations.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Security Engineer
Security Engineer

Bright Machines • Región Centro

Presencial
MXN 1.200.000 - 1.800.000
Mechanical Engineer
Mechanical Engineer

Bright Machines, Inc. • Región Centro

Presencial
MXN 450.000 - 650.000
InfoSec Engineer: ISO 27001 & App Security Lead
InfoSec Engineer: ISO 27001 & App Security Lead

Bright Machines • Región Centro

Presencial
MXN 1.200.000 - 1.800.000
Security Engineer – ISO 27001 & AppSec
Security Engineer – ISO 27001 & AppSec

Bright Machines, Inc. • Región Centro

Presencial
MXN 850.000 - 1.350.000
Global Solutions Engineer, LATAM
Global Solutions Engineer, LATAM

United States Digital Space LLC • México

Presencial
MXN 900.000 - 1.300.000
Healthcare programs
Parental leave
Paid holidays
+2
AI Security Researcher
AI Security Researcher

Nearshore Cyber • México

Híbrido
MXN 1.339.000 - 2.511.000
Competitive compensation with equity
Remote-first
International collaboration
+3
Senior Architect, AI & Cloud Security
Senior Architect, AI & Cloud Security

Edwards Lifesciences • Torreón

Presencial
MXN 900.000 - 1.200.000
Manager, Security Engineering & Operations
Manager, Security Engineering & Operations

United States Digital Space LLC • Región Centro

Híbrido
MXN 2.042.000 - 3.063.000
Manufacturing Engineer - Plant A
Manufacturing Engineer - Plant A

Vertiv • Reynosa

Presencial
MXN 1.532.000 - 2.043.000
Manufacturing Engineer
Manufacturing Engineer

Cisco Systems, Inc. • Región Centro

Presencial
MXN 360.000 - 600.000