2 hours ago
Bogotá, Colombia or Mexico City, MexicoMid Level / Senior
Responsibilities
- Define and operate security controls for LLMs, coding agents, agentic browsers, MCP integrations, and internal inference gateways.
- Own and evaluate Clara’s LLM-based SIEM investigation agent, including its instructions, rules, accuracy, hallucinations, and autonomous actions.
- Threat-model AI systems and create secure-by-default guidance and adoption paths.
- Own cloud security detection and posture across AWS and GCP, including IAM, network controls, logging, guardrails, and infrastructure-as-code policy checks.
- Lead GCP project inventory and cleanup initiatives and automate recurring security controls.
- Secure identity and edge systems including Auth0, Cloudflare, Google Workspace, SSO, and service-to-service authentication.
- Run the application security program, including SAST, dependency and secrets scanning, secure code review, and CI/CD hardening.
- Review product and integration architecture and code, prioritize findings, and drive remediation.
- Build and tune Splunk detections across identity, cloud, endpoint, email, and network sources.
- Lead incident investigations and response through incident.io, including containment, root-cause analysis, and post-incident reviews.
- Own email and web protection policies, phishing initiatives, pentests, and vulnerability disclosure coordination.
- Map controls to PCI DSS and ISO 27001, produce audit evidence, and support technical customer security reviews and enterprise sales.
- Mentor early-career security engineers and review their investigative work.
Requirements
- 2–4 years of security engineering, cloud security, application security, or closely related engineering experience with hands-on production work.
- Strong practical AWS and/or GCP security knowledge covering IAM design, network controls, logging, detection, and infrastructure as code such as Terraform.
- Programming ability in at least one of Python, Go, JavaScript, or TypeScript for building tooling and automation.
- Hands-on secure-code experience identifying injection, authentication and authorization, secrets-handling, and supply-chain issues in code and CI/CD pipelines.
- Experience with a SIEM, preferably Splunk, and an EDR platform, including detection engineering and investigation.
- Working knowledge of LLM-based systems and agents, their failure modes, and technical experience using or building with them.
- Strong risk judgment, written and spoken Spanish and English communication, and comfort working in a fast-changing environment.
- Preferred: fintech, payments, or regulated-environment experience involving PCI DSS, ISO 27001, or SOC 2.
- Preferred: experience securing or red-teaming LLM applications, agents, or MCP tooling; Kubernetes and container security; detection-as-code, SOAR, or security automation.
- Preferred certifications include AWS Security Specialty, Google Professional Cloud Security Engineer, OSCP, GIAC, or CISSP.
- Portuguese, open-source contributions, conference talks, and CTF or bug-bounty experience are additional preferred qualifications.
Benefits
- Ownership and direct exposure to leadership at a fast-growing fintech.
- Opportunity to secure agentic AI systems deployed in production.
- Budget and time for certifications, conferences, and participation in the hacker community.
- Competitive salary and stock options through ESOP from day one.
- Annual learning budget and accelerated internal development paths.
- Multicultural environment with daily exposure to Portuguese, Spanish, and English.
- Flexible vacation and a hybrid work model with no enforced minimum office days for most roles, while office presence is expected during ramp-up or when required by the leader.
- Fast, transparent hiring process including application review, technical deep-dive, practical exercise, and team and leadership conversations.
Tech Stack
AWSCloudflareGoGoogle Cloud PlatformJavaScriptKubernetesPythonSAP Cloud PlatformSonarQubeSplunkTerraformTypeScript
Categories
About Clara
CLARA Analytics builds AI-driven software to help property and casualty insurers and self-insured organizations manage claims, reduce litigation risk, and improve provider selection and outcomes. Its products are sold on a subscription basis and integrate with existing claims systems to deliver triage, severity prediction, and workflow insights. The company was founded in 2016 and is headquartered in Santa Clara, California.
