Senior Security Engineer
Job description
About the role
Nelo is seeking a hands-on security professional to establish and lead our security function from the ground up. You will partner with engineering leadership to embed security into our core infrastructure and development lifecycle while balancing risk with rapid product velocity. This role requires a practitioner who thrives on writing code and building systems instead of only advising. You will own the design, implementation, and scaling of security controls across our entire stack. The position demands comfort with ambiguity and the ability to drive initiatives from an empty document to a mature operational process. You will act as the central authority on security topics for product, infrastructure, and operations teams. Success in this role will be measured by the robustness of the security posture and the enablement of the engineering team.
Key facts
What you'll do
- Architect and deploy security guardrails across our cloud environment and developer workflows to prevent misconfigurations before they reach production.
- Implement least-privilege IAM models and manage secrets and endpoint access controls to harden production systems against unauthorized access.
- Codify security policies using Terraform and policy-as-code frameworks to enforce secure AWS infrastructure as code.
- Build and automate security observability pipelines to detect anomalies, investigate events, and reduce mean time to respond.
- Author code and infrastructure configurations to enforce security controls, eliminating reliance on manual checklists and tribal knowledge.
- Spearhead external security initiatives, including the strategic expansion of bug bounty programs and oversight of third-party penetration tests.
- Own the end-to-end process for SOC 2 Type 1 and Type 2 certifications, designing workflows for automated evidence collection and reporting.
- Conduct rigorous reviews of engineering designs and pull requests to ensure security standards are met without blocking delivery.
- Define and maintain standards for secure cloud architecture, network segmentation, and data protection across services.
- Collaborate with product and operations teams to integrate security requirements into roadmaps and incident response plans.
- Develop runbooks and operational procedures to ensure security processes are repeatable and scalable as the team grows.
- Measure the effectiveness of security controls and iterate based on data from detections, audits, and incident post-mortems.
- Mentor engineers on secure coding practices and threat modeling to elevate the entire organization's security literacy.
- Act as the technical liaison with compliance auditors and external assessors to streamline certification and audit cycles.
Requirements
- Hold a Bachelor's degree in Computer Science, Information Security, or a closely related technical field.
- Possess proven engineering background with significant hands-on experience securing production environments at scale.
- Demonstrate practical expertise in cloud security, specifically within AWS, including identity, network, and data protection.
- Show proficiency in infrastructure-as-code tools such as Terraform, CloudFormation, or similar provisioning frameworks.
- Exhibit the ability to ship code and own technical outcomes, prioritizing tangible results over theoretical recommendations.
- Bring experience with scripting and automation using Python and/or Go to solve security problems programmatically.
- Have a deep understanding of compliance frameworks, including experience guiding a company through SOC 2 or ISO 27001 certifications.
- Maintain a strong commitment to confidentiality and integrity, given the sensitive nature of financial data and infrastructure security.
- Thrive in a fast-paced, startup-like environment where priorities shift quickly and adaptability is essential.
- Communicate clearly and professionally with both technical and non-technical stakeholders, including executives and legal teams.
Nice to have
- Prior experience guiding a company through SOC 2 or ISO 27001 certifications end-to-end.
- Hands-on experience managing bug bounty programs or external penetration testing engagements.
- Deep knowledge of AWS primitives including GuardDuty, CloudTrail, IAM, VPC, KMS, and security groups.
- Active use of agentic coding tools like Claude Code in daily development workflows to accelerate secure delivery.
Skills & tools
- AWS (GuardDuty, CloudTrail, IAM, VPC, KMS)
- Terraform
- Python
- Go
- SOC 2 / ISO 27001 compliance
- Agentic AI coding tools
Practical notes
- This is an individual contributor role; you will be responsible for building the security function yourself.
- We operate with a lean, fast-paced culture where AI tools are integrated into daily engineering workflows.
- The interview process consists of a hiring manager conversation, a case study, and an on-site panel.
- The work location is on-site in Condesa, Mexico City, requiring consistent presence during standard business hours.
- Travel may be required occasionally for security assessments, audits, or stakeholder meetings.
- No visa sponsorship is provided for this position; candidates must ensure they have the right to work in Mexico.
- The role is full-time with a standard weekly schedule as defined by company policy.
- Compensation includes a competitive salary and equity with a 10-year option expiration.
- Benefits include medical, dental, and vision coverage, unlimited PTO, and parental leave.
- The successful candidate will start as soon as possible, given the critical need to build security operations.
- Candidates must be located in or be willing to relocate to Mexico City to meet on-site requirements.