SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Clara is a leading B2B fintech for spend management in Latin America, offering corporate cards, bill pay, financing, and a B2B platform serving over 20,000 businesses. The company is backed by top-tier investors including Kaszek, Coatue, DST Global, and General Catalyst.
As a Security Engineer, you will own outcomes across multiple security domains, leading workstreams and mentoring early-career engineers. You'll operate with autonomy and make decisions without requiring sign-off.
**AI Security & Governance**: Define and operate controls for Clara's use of LLMs, coding agents, agentic browsers, and MCP integrations. Own the LLM-based investigation agent on the SIEM, including instruction design, accuracy evaluation, and autonomous closure decisions. Threat-model AI systems as first-class attack surfaces (prompt injection, data exfiltration, over-privileged agents, supply chain). Build guidance and paved paths for safe AI adoption across product and engineering teams.
**Cloud Security (AWS & GCP)**: Own detection and posture across AWS (GuardDuty, IAM, VPC, CloudTrail) and GCP (Security Command Center, IAM, service accounts, org policies). Design and implement guardrails as code (organization policies, SCPs, IAM boundaries, infrastructure-as-code policy checks). Lead large-scale GCP project inventory and cleanup initiatives, converting one-off findings into automated controls. Secure identity and edge systems including Auth0, Cloudflare, Google Workspace, and service-to-service authentication.
**Application Security & CI/CD**: Run and evolve the application security program including SAST (SonarQube, Semgrep), dependency and secrets scanning, PR review for security-sensitive changes, and CI/CD pipeline hardening. Review architecture and code for new products and integrations (card issuing, payments, banking partners). Define secure-by-default patterns and libraries for engineers, including for AI-generated code. Coordinate pentests and vulnerability disclosure programs.
**Detection, Response & Incident Leadership**: Build and tune detections in Splunk across identity/SSO, cloud, endpoint, email, and network sources. Lead incident investigation and response through incident.io, including scoping, containment (EDR isolation, credential revocation, cloud access), root cause analysis, and post-incident review. Own email and web protection policy and phishing programs. Mentor early-career engineers on investigation techniques and evidence-based reporting.
**Compliance**: Map controls to PCI DSS and ISO 27001 requirements, producing evidence for auditors without slowing the team. Support customer security reviews and enterprise sales with technical expertise.
**Requirements**:
- 2–4 years in security engineering, cloud security, application security, or closely related engineering role with hands-on production experience
- Strong, practical knowledge of AWS and/or GCP security: IAM design, network controls, logging, detection, and ability to read/write infrastructure as code (Terraform or similar)
- Solid programming ability in at least one language (Python, Go, JavaScript/TypeScript); you build tooling and automation
- Real secure-code experience: finding and explaining injection, auth/authz, secrets handling, and supply-chain issues in code and CI/CD pipelines; ability to drive developer remediation
- Hands-on experience with a SIEM (Splunk preferred) and EDR platform, including detection engineering and investigation
- Working understanding of LLM-based systems and agents, including failure modes, with experience using or building with them in a technical setting
- Sound judgment on risk: distinguishing between findings that block launches and those that ship with follow-up; ability to defend those calls
- Strong written and spoken communication in Spanish and English; ability to explain risk to engineers, product managers, and auditors
- Comfort with pace and ambiguity; preference for building processes rather than waiting for them
**Nice to have**:
- Experience in fintech, payments, or other regulated environments (PCI DSS, ISO 27001, SOC 2)
- Experience securing or red-teaming LLM applications, agents, or MCP tooling
- Kubernetes and container security
- Detection-as-code, SOAR, or security automation experience
- Certifications: AWS Security Specialty, Google Professional Cloud Security Engineer, OSCP, GIAC, or CISSP
- Portuguese language skills
- Open source contributions, conference talks, or CTF/bug bounty track record