We are looking for a Software Engineer, with solid experience in Java and AWS, based in Latin America to work on a long-term project for one of our clients, a hyper-growth fintech company based in Los Angeles, California.Our client´s mission is to make financial advice better and more accessible for everyone. They are building a revolutionary platform for financial advisors and their clients to remove the friction from investing and reduce the barrier to entry into wealth creation and management.
Responsibilities
- Independently take defined security and reliability problems through design, implementation, and production rollout.
- Integrate platform security capabilities into existing Java and Spring Boot services, such as encrypting PII fields with AWS KMS, applying Postgres row-level security, and adopting centralized authorization, including safe, zero-downtime backfill of existing data.
- Harden APIs and services with consistent authorization at every boundary, input validation, rate limiting, idempotency, audit logging, and least-privilege IAM.
- Diagnose and fix database performance issues, including query and index optimization, connection management, and key rotation for encrypted data.
- Improve observability (metrics, tracing, structured logging) and remediate production incidents, shipping durable fixes rather than workarounds.
- Work closely with Security, Platform, and product engineers to deliver remediation work to a high standard of quality.
Requirements
- Advanced Level of English.
- 5+ years of full-stack engineering experience with a strong backend focus, building and maintaining production systems in Java and Spring Boot.
- Hands-on experience implementing authentication and authorization (OAuth 2.0/OIDC, Spring Security, RBAC).
- Solid AWS experience, including IAM, KMS or Secrets Manager, and RDS/Aurora; exposure to infrastructure as code (Terraform or CDK).
- Advanced SQL and Postgres skills, including query optimization and safe schema and data migrations.
- Strong API design and service-integration skills across distributed systems.
- Experience owning production services: monitoring, debugging, and incident remediation.
- A track record of building and hardening systems, rather than primarily performing security reviews, audits, or compliance work.
- Familiarity with TypeScript, React, or GraphQL, as parts of the product require coordinated cross- stack changes.
Bonus Points
- Bachelor’s Degree in Computer Science, Systems Engineering or related fields.
- Experience in fintech, payments, brokerage, or other regulated, security-sensitive environments (e.g., SOC 2, PCI DSS).
- Application-level encryption experience: envelope encryption, tokenization, key rotation, and libraries such as the AWS Encryption SDK or Google Tink.
- Experience with event-driven architectures (Kafka or similar), including protecting sensitive data in asynchronous pipelines.
- Experience with Snowflake, including data access controls such as masking and row access policies.