Skip to content

Open nowPosted 6 days ago

Senior Security Engineer

Workable (global search)108,016 open roles

Where
Argentina
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security EngineerWorkable (global search) · Argentina
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 6 days ago

Workable (global search) median: 7 days open

The posting

Azumo builds and operates production AI systems for companies ranging from seed-stage startups to Meta. We are hiring a Senior Security Engineer to own the technical security posture of those systems once they are live: the infrastructure they run on, the pipelines that feed them, and the agents that act on their output. The role is fully remote across Latin America, aligned to your client's working day.

This is not an audit seat. Azumo has shipped production AI since 2016, and the work here is in the systems themselves — hardening infrastructure, closing vulnerabilities, and building the guardrails that keep AI-driven workflows safe in front of real users.

Where this role sits

At Azumo, ownership is split by what gets built: the pipelines, the method behind a decision, the product, and what an AI system does once it's live. Security doesn't work that way. It has to be right across all of them, and that's what this role owns.

Gap or breach, it's yours. If there's a gap, you find it and close it before anyone outside the team does. If there's a breach, you run it: containment, root cause, and the fix that keeps it from happening twice.

Whoever builds the system answers for whether it works. You answer for whether it's safe to run. That split is agreed before the work starts, not reported after.

What you will build

Platform and infrastructure hardening: Cloud infrastructure, APIs, internal tooling, and CI/CD pipelines: encryption, secrets management, logging, and access controls that are built in, not bolted on, and stay correct as the systems around them change.

Vulnerability management and offensive security: Scanning, penetration testing, adversarial testing, threat modeling, and manual review across everything Azumo ships into a client's environment — with remediation you drive to closed, not to ticket.

AI and agent security: Prompt-injection defense, adversarial-input testing, and guardrails for the tool-calling and agentic systems the AI Engineer lane builds. Untrusted input arrives from IVR and voice channels, web systems, APIs and people, and what handles it stays bounded, observable and safe to fail.

Watching what the agents do: Monitoring AI systems in production for anomalies, abuse attempts and unsafe decisions — the same production behavior the AI Engineer lane measures for accuracy, watched here for misuse.

The standing audit: Azumo runs an automated security, cost, and architecture audit across every client codebase, graded by severity down to the file and line, on day one and every day after. You own it — what it checks, how it's graded, how often it's wrong.

Monitoring, detection, and incident response: Alerting and detection for what you harden, investigation when something looks wrong, and root cause when it turns out to be something. You lead the response itself: containment, the remediation plan, and the preventative change that follows, with operational visibility into access patterns and security events maintained rather than reconstructed after the fact.

Customer and partner security engagement: Security questionnaires, vendor risk assessments, and enterprise RFPs, plus the technical questions that come directly from a client's bank, auditor or enterprise prospect. You explain the architecture, the controls and what is monitored, and you defend the answer without a translation layer in between.

Secure development practices: Working with the engineering teams on how they build, not only on what they ship: architecture reviews, secure patterns, and the trade-off between security, reliability and delivery speed argued in the room with Product, Compliance and Operations rather than raised afterwards.

Work inside the client's environment: Their repositories, their tooling, sometimes their compliance review. Azumo is SOC 2 certified, client code stays in client repositories, and some engagements carry additional requirements such as HIPAA.

How we work

Our engineers build with AI every day. Claude Code, Codex, and similar tools are part of the standard toolchain here, not an experiment. The audit you'll own runs across the whole codebase on day one and every day after, grading security, cost, and architecture findings by severity with the exact file and line, so a small team can move quickly without quality drifting. We stay vendor-neutral across OpenAI, Anthropic, and open-weight models, and we run Valkyrie, our own production layer, when a single interface to any model is the right call.

About Azumo

Azumo is a San Francisco based software development company that has been building intelligent applications since 2016. We provide nearshore AI engineering teams to organizations that need production AI faster than they can hire for it: as an embedded engineering team, as AI staff augmentation alongside an existing team, or as a full project build.

Our engineers work from Latin America, aligned to United States time zones, and have delivered for Twitter, Meta, Discovery Channel, Omnicom, UnitedHealth, and CENTEGIX.

We hire for seniority and test for it before anyone joins a client team. We support engineers in going deep on the modern AI stack, and we give time back to open-source work, community teaching, and philanthropy.

Requirements

Basic qualifications

  • 5+ years of hands-on experience in security engineering, infrastructure security, application security, DevSecOps, or offensive security, with the engineering fundamentals to match: testing, code review, CI/CD, Git, containers, and API design.
  • Deep, current knowledge of the AWS ecosystem, and the judgment to secure it under production pressure, not just in a lab.
  • Demonstrated experience identifying and remediating vulnerabilities in live production systems.
  • Experience securing AI or LLM-powered systems or automated agents: prompt injection, adversarial inputs, unauthorized actions, unsafe outputs, and data leakage. This is the requirement we screen hardest on.
  • Working knowledge of compliance frameworks as operating practice rather than documentation: SOC 2, PCI DSS, and the expectations that come with handling financial and consumer data, kept continuously rather than assembled for an audit.
  • Self-directed prioritization. You decide what gets fixed first in a fast-moving environment, and you can explain why.
  • Active use of AI-assisted coding tools such as Claude Code, Cursor, or GitHub Copilot in real delivery work.
  • Strong communication skills: the ability to explain a finding to engineers and defend it to a client directly, without a translation layer in between.
  • Clear written and spoken English, C1 or above.
  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent professional experience.

Preferred qualifications

  • Familiarity with prompt-injection attacks, adversarial AI techniques, AI guardrails, and behavioral anomaly detection.
  • Cloud security tooling, SIEM and observability platforms, penetration testing tools, endpoint security platforms, and infrastructure-as-code security (Terraform, Bicep, or similar).
  • Prior experience in high-growth startup, fintech, banking, or payments environments.
  • Certifications such as CISSP, CISM, AWS Security Specialty, or similar.
  • Contributions to open-source security tooling, published technical writing, or active participation in the security community.

Benefits

  • 100% remote-firste culture (work anywhere in Latin America)
  • Paid time off (PTO)
  • U.S Holidays
  • Solid AI Training and certification
  • Mentored career development
  • Profit Sharing
  • $US remuneration
  • Maternity coverage
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.