1 day ago
Bogotá, ColombiaSenior
Responsibilities
- Analyze and remediate code-level vulnerabilities, dependency issues, insecure configurations, and IaC misconfigurations.
- Triage and remediate Upwind CSPM findings across AWS accounts, workloads, and services, including root-cause fixes and remediation runbooks.
- Partner with engineering teams to fix issues in Terraform, CloudFormation, container images, and application code.
- Operate and improve AWS security detection and remediation workflows using Security Hub, GuardDuty, Config, IAM Access Analyzer, Inspector, and related tools.
- Automate security workflows where feasible using Lambda, EventBridge, and SSM Automation.
- Track security posture metrics, remediation velocity, aging findings, and risk trends.
- Support cloud security incident investigations, log analysis, impact assessment, containment, remediation, and post-incident reviews.
- Participate in cloud security architecture reviews covering IAM, network segmentation, encryption, and data protection.
- Provide practical risk-based security recommendations to engineering and non-technical stakeholders.
Requirements
- At least 3 years of hands-on cloud security experience with deep practical AWS experience.
- Direct experience remediating CSPM or CNAPP findings using platforms such as Upwind, Wiz, Prisma Cloud, or Orca.
- Experience analyzing and remediating application and code-level vulnerabilities through SAST, SCA, and container image scanning.
- Working knowledge of Terraform and/or CloudFormation, with the ability to remediate misconfigurations directly in code.
- Scripting ability in Python and/or Bash for automation and investigations.
- Familiarity with incident response processes and cloud-native log sources.
- Strong written and verbal communication skills.
- Fluent English, as interviews will be conducted in English.
- Preferred experience securing EKS, ECR, and Kubernetes security policies.
- Preferred exposure to CI/CD security integration, scanning gates, policy-as-code, and pipeline hardening.
- Preferred familiarity with SOC 2, ISO 27001, PCI-DSS, GDPR, and NIST 800-53 Baseline Controls.
- AWS Security Specialty or Solutions Architect certification, vendor CSPM certification, or prior dedicated cloud security or DevSecOps team experience is preferred.
- Experience with ethical hacking and certifications such as CEH, OSCP, GCIH, or CISSP are nice to have.
Benefits
- Hybrid work arrangement in Bogotá, Colombia, with 2 days per week in the office.
