About this role
- This position is open to candidates located in Colombia or Costa Rica only -
The client builds AI-powered intelligence and document-analysis products for commercial and U.S. government customers. Engineering runs a lean, AWS-first platform (Kubernetes/EKS, Terraform, GitHub Actions) with a smaller Azure footprint.
The security function works hand-in-hand with a small DevOps team and is supported by strong internal automation — we care more about sound judgment and self-direction than any one certification.
What you'll do
• A hands-on cloud security engineer to own day-to-day security operations and support our compliance programs. This is a sole-coverage role: the engineer is the security point of contact for the company, backed by DevOps for execution.
Required Qualifications
• Hands-on AWS security: IAM and least-privilege design, GuardDuty, Security Hub, CloudTrail
• Security alert triage and incident response in cloud environments
• Comfortable working in Terraform and shipping changes through pull requests
• Kubernetes security fundamentals (RBAC, workload hardening)
• Vulnerability management: scanning, prioritization, and coordinating remediation with engineers
• Experience supporting SOC 2 audits (control evidence, working with auditors)
• CI/CD and supply-chain security awareness (GitHub Actions, dependency/image scanning)
Preferred Qualifications
• CrowdStrike Falcon administration (endpoint + cloud/container sensors)
• CMMC / NIST 800-171 / GCC High or FedRAMP exposure — we run a federal compliance program, and portions of this work may require a U.S. person
• Azure security (Microsoft Defender, ACR, Azure DevOps)
• Cloudflare Zero Trust (WARP) and WAF
• Golden image / AMI build pipelines (Packer)
• Scripting for security automation (Python preferred); comfort working alongside AI coding agents — our engineering workflow is heavily agent-assisted