4 hours ago
Remote, ColombiaSenior
Responsibilities
- Lead vulnerability management across infrastructure, platforms, and applications, including scanning, dependency analysis, validation, remediation coordination, and verification.
- Build, operate, and mature SIEM/XDR capabilities through log ingestion, detection rule development, alert tuning, and investigation workflows.
- Investigate security incidents across cloud infrastructure and applications, perform root cause analysis, and drive lasting fixes.
- Design detection strategies for suspicious activity and data exfiltration using application and database telemetry.
- Lead threat modeling and security design reviews to identify and mitigate risks early.
- Secure and improve AWS and Kubernetes infrastructure, including infrastructure, CI/CD, container, and software supply chain hardening.
- Implement dependency and container supply chain risk detection systems and controls.
- Partner with engineering teams to remediate vulnerabilities and improve secure development and deployment practices.
- Implement security controls aligned with PCI DSS, SOC 2, and other compliance requirements.
- Develop automation, including appropriate use of AI, to improve security operations, detection, and response.
Requirements
- 6+ years of experience in security, software, or infrastructure engineering, including hands-on experience securing cloud-based production systems.
- Experience with threat modeling, security design reviews, vulnerability management, security scanning, triage, validation, remediation, and verification.
- Experience using SIEM platforms such as Wazuh, Splunk, or ELK for detection engineering, monitoring, and incident response.
- Experience triaging vulnerability scanner and bug bounty findings.
- Strong knowledge of AWS, Linux, and Kubernetes infrastructure, including security architecture, hardening, and operational practices.
- Experience with CI/CD hardening, software supply chain risk mitigation, container security, and dependency security tools such as Snyk, Trivy, or Grype.
- Ability to investigate issues using logs, cloud tooling, and system-level data.
- Knowledge of common security vulnerabilities and mitigation strategies, including OWASP and SANS guidance.
- Working knowledge of PCI DSS, SOC 2, and related compliance expectations.
- Experience designing detection rules, reducing alert noise, improving investigation workflows, and using telemetry pipelines for security analytics.
- Demonstrated experience working with Claude or equivalent large language model tools is required.
Benefits
- Remote, full-time role.
- Monthly gross salary range of $5,000-$9,500 USD based on experience level.
Tech Stack
Categories
About Sezzle
Sezzle builds a buy now, pay later platform that lets consumers split purchases into interest-free installments online and in stores, integrated with e-commerce and retail merchants. The company earns revenue from merchant fees and related consumer charges and provides underwriting and payment processing services. Founded in 2016 and headquartered in Minneapolis, Sezzle is a public company dual-listed on Nasdaq and the ASX.
