SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer

Bright Machines - Guadalajara, Jalisco, Mexico - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Bright Machines is an AI-enabled manufacturer specializing in data center infrastructure production, using proprietary AI-based robotics and software to assemble servers for hyperscalers and cloud providers. As Security Engineer reporting to the Global IT Director, you will execute and enforce Bright Machines' information security program across corporate, product, and manufacturing environments. This is a hands-on execution role partnering closely with IT leadership, Infrastructure Engineering, and Platform Engineering teams. Key responsibilities include: • Execute day-to-day information security operations across corporate IT, platform, and product environments in partnership with the Global IT Director who sets policy and strategy. • Maintain ISO 27001:2022 certification: manage evidence collection, internal audits, corrective actions, and support annual surveillance and recertification audits. • Execute customer security due diligence by completing security questionnaires (SIG, CAIQ), supporting customer audits, and tracking contractual security requirements in partnership with Legal and Sales. • Partner with Platform Engineering to build application security into the SDLC: threat modeling support, secure code review guidance, and operation of SAST/DAST/SCA tooling. • Run vulnerability management across applications and platform infrastructure: scanning, triage, and driving remediation with engineering teams to SLA. • Coordinate third-party penetration tests and security assessments; track findings to closure. • Partner with Infrastructure Engineer on network and compute infrastructure security posture, including EDR/managed SOC and network IDS/IPS controls. • Support security incident response: maintain IR plan, participate in investigations, and run periodic tabletop exercises. • Support identity and access governance for corporate and platform systems (access reviews, certifications, MFA/SSO enforcement). • Conduct security risk assessments for new vendors, tools, and third-party integrations. • Maintain information security policies, standards, and employee security awareness training. • Track and report on security posture, risk, and compliance status to leadership. • Help evaluate and prepare for future compliance initiatives (e.g., SOC 2 Type II). Required qualifications: 5+ years in security engineering, IT security, application security, or related role. Experience maintaining an existing ISO 27001 ISMS. Working knowledge of application security fundamentals (OWASP Top 10, secure SDLC practices) with hands-on experience using SAST/DAST/SCA tooling (Snyk, Semgrep, Checkmarx, Burp Suite). Proficiency in a scripting language (Python) for security automation and infrastructure-as-code (Terraform, Ansible). Familiarity with GRC platforms. Basic cloud security literacy (AWS, Azure, GCP). Comfortable completing customer security questionnaires. Familiarity with EDR/managed SOC platforms. Excellent written and verbal English communication skills. Nice-to-have: Security certifications (Security+, GSEC, CCSP), experience in manufacturing/industrial/IoT/OT/ICS security, exposure to penetration testing, familiarity with Zero Trust architecture.

Similar roles