Sezzle

Senior Security Infrastructure Engineer

Sezzle
Apply
4 hours ago
Remote, MexicoSenior

Responsibilities

  • Lead vulnerability management across infrastructure, platforms, and applications, including scanning, dependency analysis, finding validation, and remediation coordination.
  • Build and operate SIEM/XDR capabilities, including log ingestion, detection rules, alert tuning, investigations, and response workflows.
  • Investigate security incidents across cloud infrastructure and applications, perform root cause analysis, and drive long-term fixes.
  • Design detection strategies for suspicious activity and data exfiltration using application and database telemetry.
  • Lead threat modeling and security design reviews to identify and mitigate architectural risks.
  • Secure and improve AWS and Kubernetes infrastructure, including cloud-native controls, hardening, and operational practices.
  • Drive CI/CD, container, dependency, and software supply chain security initiatives.
  • Partner with engineering teams to remediate vulnerabilities and improve secure development and deployment practices.
  • Implement security controls aligned with PCI DSS, SOC 2, and other compliance requirements.
  • Develop automation, including appropriate AI use, to improve security operations, detection, and response efficiency.
  • Triage and validate external security findings from vulnerability scanners and bug bounty programs.

Requirements

  • 6+ years of experience in security, software, or infrastructure engineering, including hands-on experience securing cloud-based production systems.
  • Experience with threat modeling, security design reviews, vulnerability management, SIEM platforms, detection engineering, monitoring, and incident response.
  • Experience triaging findings from vulnerability scanners and bug bounty programs and coordinating remediation.
  • Strong knowledge of AWS, Linux, and Kubernetes infrastructure, including security architecture, hardening, and operational best practices.
  • Experience with CI/CD hardening, software supply chain risk mitigation, and container and dependency security tools such as Snyk, Trivy, and Grype.
  • Ability to investigate issues using logs, cloud tooling, and system-level data.
  • Knowledge of common security vulnerabilities and mitigation strategies, including OWASP and SANS guidance.
  • Working knowledge of PCI DSS, SOC 2, and other compliance expectations.
  • Demonstrated experience using Claude or equivalent large language model tools to improve productivity, research, and communication.
  • Preferred qualifications include experience tuning detection rules, reducing alert noise, improving investigation workflows, designing secure CI/CD workflows, and using automation and AI at scale.

Benefits

  • Remote, full-time role.
  • Opportunity to work with modern security tooling and AI-enabled automation on real-world security problems at scale.
  • Company culture emphasizes high standards, ownership, action, trust, candid collaboration, and delivering results.

Tech Stack

AWSElasticsearchGitGoKubernetesLinuxMySQLPostgreSQLPythonReactReact NativeSplunkTypeScript

Categories

Sezzle

About Sezzle

201-500 employees

Sezzle builds a buy now, pay later platform that lets consumers split purchases into interest-free installments online and in stores, integrated with e-commerce and retail merchants. The company earns revenue from merchant fees and related consumer charges and provides underwriting and payment processing services. Founded in 2016 and headquartered in Minneapolis, Sezzle is a public company dual-listed on Nasdaq and the ASX.

Contact me