Skip to content

Open nowPosted 45 days ago

Security Engineer

Bright Machines16 open roles

Where
Guadalajara Area, Mexico
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity EngineerBright Machines · Guadalajara Area, Mexico
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Bright Machines's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.4% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.5%1 day
  2. 3.5%3 days
  3. 7.4%7 days
  4. 13.2%14 days
  5. 34.6%30 days
This job: posted 45 days ago

The posting

RETHINK MANUFACTURING

The only way to ignite change is to build the best team. At Bright Machines®, we’re innovators and experts in our craft who have joined together to manufacture the AI and data center infrastructure at the edge. We believe unifying software, intelligent automation, and data is the answer to delivering quality and flexibility at scale. We deliver products to meet the demands of today while continuously investing in our Bright Factory model to take advantage of what comes next.

Working with us means you’ll have the opportunity to make lasting, impactful changes for our company and our customers. If you’re ready to apply your exceptional skills to a brighter way of manufacturing AI infrastructure, we’d love to speak with you.

ABOUT THE ROLE

As part of the IT organization, you will execute and enforce Bright Machines' day-to-day information security program—spanning platform security, application security, and information security compliance—across our corporate, product, and manufacturing environments. The Global IT Director, to whom this role reports, sets security policy and strategy; you'll partner with the Director on that strategy while owning hands-on execution, and you'll work closely with our Infrastructure Engineer, who owns network security execution, and with Platform Engineering, our closest partner on application security. You will own day-to-day maintenance of our existing ISO 27001:2022 certification and execution of the customer security requirements our commercial relationships depend on. Because you'll work daily with IT, Platform Engineering, Software Development, and Delivery, strong written and verbal English communication is essential.

WHAT YOU WILL BE DOING

  • Execute day-to-day information security operations across corporate IT, platform, and product environments, in partnership with the Global IT Director, who sets security policy and strategy.
  • Maintain our existing ISO 27001:2022 certification: manage evidence collection, internal audits, and corrective actions, and support annual surveillance and recertification audits.
  • Execute customer security due diligence, completing security questionnaires (SIG, CAIQ), supporting customer audits, and tracking contractual security requirements, partnering with Legal and Sales as needed.
  • Partner with Platform Engineering to build application security into the SDLC: threat modeling support, secure code review guidance, and operation of SAST/DAST/SCA tooling.
  • Run vulnerability management across applications and platform infrastructure: scanning, triage, and driving remediation with engineering teams to SLA.
  • Coordinate third-party penetration tests and security assessments; track findings to closure.
  • Partner with the Infrastructure Engineer on the security posture of network and compute infrastructure, including our EDR/managed SOC and network IDS/IPS controls, keeping application and platform controls aligned with network security architecture.
  • Support security incident response: help maintain the IR plan, participate in investigations, and run periodic tabletop exercises.
  • Support identity and access governance for corporate and platform systems (access reviews, certifications, MFA/SSO enforcement) with IT Engineering.
  • Conduct security risk assessments for new vendors, tools, and third-party integrations.
  • Maintain information security policies, standards, and employee security awareness training (including phishing simulations), in line with direction from the Global IT Director.
  • Track and report on security posture, risk, and compliance status to the Global IT Director.
  • Help evaluate and prepare for future compliance initiatives (e.g., SOC 2 Type II) as prioritized by leadership.

WHAT WE WANT TO SEE

  • 5+ years of experience in security engineering, IT security, application security, or a closely related role.
  • Experience maintaining an existing ISO 27001 ISMS: evidence collection, internal audits, and support for surveillance/recertification audits. (Building an ISMS from scratch isn't required; we already hold certification.)
  • Working knowledge of application security fundamentals (OWASP Top 10, secure SDLC practices) with hands-on experience using SAST/DAST/SCA tooling (e.g., Snyk, Semgrep, Checkmarx, Burp Suite).
  • Proficiency in a scripting language (e.g., Python) for security automation, with a strong inclination toward infrastructure-as-code (e.g., Terraform, Ansible) for codifying and enforcing security controls.
  • Familiarity with GRC platforms for compliance evidence and monitoring.
  • Basic cloud security literacy (AWS, Azure, and/or GCP): IAM, network security groups, encryption, logging and monitoring.
  • Comfortable completing customer security questionnaires and supporting customer-facing security conversations under direction.
  • Familiarity with EDR/managed SOC platforms and comfort participating in security operations and detection/response workflows.
  • Excellent written and verbal English communication skills, with the ability to communicate clearly with IT, Platform Engineering, Software Development, and Delivery stakeholders.
  • Comfortable as an execution-focused security practitioner in a lean IT organization, partnering closely with the Global IT Director, Infrastructure Engineer, Platform Engineering, and staff IT Engineers rather than working in isolation.

IT WOULD BE GREAT IF YOU HAD

  • Security certifications such as Security+, GSEC, or CCSP.
  • Experience in manufacturing, industrial, IoT, or OT/ICS security environments.
  • Exposure to penetration testing engagements, hands-on or coordinating with external testers.
  • Familiarity with Zero Trust architecture principles.
  • English language proficiency.

BE EMPOWERED TO CHANGE AN INDUSTRY

Bright Machines is a next-generation, AI-enabled manufacturer focused on data center infrastructure production. Bright Machines uses its proprietary AI-based robotics and software to assemble AI infrastructure hardware products (i.e., data center servers) for hyperscalers, neoclouds, and leading Original Equipment Manufacturers (OEMs) to reduce their time to revenue. With its Bright Factory model, Bright Machines builds higher quality data center infrastructure at scale, addresses increasing market demands for computing power due to the surge of AI, and answers the call to the U.S. national mandate to reshore manufacturing.

Bright Machines is headquartered in San Francisco, California, with an integration center in Guadalajara, Mexico. The company has been recognized as one of Forbes’ AI 50, awarded “Best AI-based Solution for Manufacturing” by AI Breakthrough, named a “Technology Pioneer” by the World Economic Forum, and highlighted by several other leading technology and innovation organizations.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Bright Machines's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Bright Machines's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Bright Machines's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.