06 sep
|
Empresa líder
|
México
06 sep
Empresa líder
México
CLOUDSUFI is a Silicon Valley-based specialist Data Engineering & Cloud Technologies player with top-tier clients, favourable revenue mix, strong financial performance, and robust management.
We help organizations with Data Discovery, Insights, and Monetization, offering our engineers the opportunity to work on new platforms and technologies—including Cloud Hyper Scalers and AI/ML/NLP—that put them ahead of peers in the IT Services industry.
Started in ****, CLOUDSUFI is a family of 250+ members working towards a common goal of making enterprise data dance.Our ValuesWe are a passionate and empathetic team that prioritizes human values.
Our purpose is to elevate the quality of lives for our family, customers, partners and the community.Equal Opportunity StatementCLOUDSUFI is an equal opportunity employer.
We celebrate diversity and are committed to creating an inclusive environment for all employees.
All qualified candidates receive consideration for employment without regard to race, colour, religion, gender, gender identity or expression, sexual orientation and national origin status.
We provide equal opportunities in employment, advancement, and all other areas of our workplace.
Please explore more atShiftUS ShiftRole SummaryThis role sits within CLOUDSUFI's live engagement where AI is already embedded operationally across reliability and security—not a future aspiration.
The team runs an AI co-pilot spanning multiple platforms, a set of purpose-built AI security sub-agents, and a formal AI governance program that assesses CLOUDSUFI's own internal AI agents for risk.
As a Junior Security Engineer, you will work under the guidance of senior engineers and architects to support, operate, and learn from this AI-driven program.Responsibilities — AI-Driven Initiatives1.
AI-Augmented Security Operations & Incident ResponseSupport incident response activities by usingAI-driven detection, correlation, and root-cause analysis toolsunder the guidance of senior engineers to speed up triage.Help operate and monitor existing AI security sub-agents (covering areas such as vulnerability scanning, threat intel, and vendor risk), flagging anomalies or failures for senior review.Assist in documenting and following up on AI-assisted incident findings, including tracking remediation actions through to closure.2.
AI-Driven Threat & Vulnerability PrioritizationAssist in triaging vulnerability scan results usingrisk-based prioritization supported by intelligent vulnerability analysistooling (SAST/SCA, EASM,
container scanning)Support cloud security posture reviews by usingpredictive analytics and intelligent monitoring dashboards, escalating notable trends to senior team members.3.
AI-Augmented Perimeter, WAF & Anomaly DetectionHelp monitor and tune WAF policies usingbehavioral analytics and anomaly detection dashboards, under supervision, and learn to interpret traffic pattern alerts.Participate in architecture and design reviews that useautomated threat modeling tools, learning how AI-agent risk (e.g., prompt injection, authorization gaps, secrets exposure) is assessed and documented.Assist in tracking action items from the AI-risk remediation roadmap and help prepare status updates for stakeholders.5.
AI-Enabled DevSecOps & CI/CDSupport the implementation of security controls within CI/CD pipelines, learningautomation-first and AI-augmented approachesand shift-left practices from senior engineers.Help integrate basic AI-assisted checks (e.g., secret-scanning, dependency checks) into the development lifecycle.6.
AI-Enabled Program & Workflow SupportSupport multiple concurrent security initiatives usingAI-enabled workflow and tracking toolsshared across SRE and Security teams.Help promote a security-first culture by learning and sharingdata-driven, AI-backed security practiceswith the wider team.Security CapabilitiesFoundational knowledge of container, application, and cloud security concepts, with interest in automated risk detection tooling.Exposure to static and dynamic application security testing tools, including basic code analysis.Basic understanding of API and web/mobile application security testing concepts.Interest in penetration testing and threat assessment fundamentals; willingness to learn AI-assisted reconnaissance techniques.Familiarity with threat detection and response concepts, including behavioral analytics and anomaly-based detection.Some hands‐on exposure to security automation or scripting (Python, Bash, or similar).
Basic exposure to cloud security posture management (CSPM) and continuous monitoring concepts.Interest in observability and monitoring, and a willingness to learn predictive analytics and anomaly detection.About You1–3 years of experience in cloud security, IT security,
or a related engineering role, with an eagerness to build deeper expertise in infrastructure as code.Some exposure to cloud-native logging and monitoring tools; interest in AI-driven alerting and noise reduction.Basic familiarity with WAF concepts and a willingness to learn adaptive rule tuning.Coursework or hands‐on exposure to security monitoring and observability platforms.Exposure to CI/CD pipelines and interest in integrating security controls and shift-left practices.Basic understanding of vulnerability management concepts and risk-based prioritization.Awareness of common compliance frameworks (PCI-DSS, SOC2, SOX, HIPAA).
Beginner‐to‐intermediate familiarity with Infrastructure as Code tools (Terraform, Ansible, or CloudFormation).
Willingness to learn incident management processes, including AI-assisted triaging.Strong analytical and problem‐solving skills, with curiosity to assess simple architectures for vulnerabilities under senior guidance.Interest in learning how security policies, standards, and governance frameworks are developed and maintained, including for AI-agent usage.Core CompetenciesSecurity Automation and AI IntegrationThreat Detection and Response (EDR/XDR/NDR)SIEM, Logging, and Observability basicsUEBA and Predictive Threat Analytics (exposure)SOAR and automated incident response (exposure)Vulnerability Management fundamentalsIdentity Security basicsApplication Security and WAF fundamentalsDevSecOps and Secure SDLCCloud Security (IaaS/SaaS) fundamentalsZero Trust Architecture conceptsNetwork Security basics (IDS/IPS, segmentation, access controls)Incident Response fundamentalsAI Agent Risk & Governance basics (authorization models, prompt-injection risk, secrets exposure in AI tool configs)Preferred CertificationsAWS Cloud Practitioner / Associate-level cloud security certification (preferred, not required)CompTIA Security+ or equivalent entry‐level security certificationExposure to AI/ML applications in cybersecurity is a plusWhat Sets You ApartStrong curiosity and eagerness toward AI-first and automation-first security practices.Willingness to learn intelligent assistants and AI-driven decision systems used in security workflows, and to develop an understanding of the risks those systems introduce.A proactive, self‐driven learning attitude and ability to grow through data‐driven security insights.Genuine interest in next‐generation cybersecurity capabilities using AI and automation.Required SkillsAI Engineering Agentic AI DEVSECOPS INFOSEC#J-*****-Ljbffr
📌 Software Engineer (México)
🏢 Empresa líder
📍 México