We fully embrace working remotely and we are eager to act, improve and accelerate progress inside and outside of our organization.
The Senior Security
Engineer is a versatile member of the Security Operations team who brings deep expertise in vulnerability management while actively contributing across the full scope of security operations. You are expected to operate as a well-rounded security professional who supports the team across multiple disciplines, including: Security Assessments and Tool Evaluations This is a hands-on, execution-focused role within the Security Operations team. The idóneo candidate owns the vulnerability management function with discipline and rigor, while consistently contributing to incident response, threat analysis, compliance support, and other operational priorities as they arise.
This role requires a senior security professional who operates with a generalist mindset, brings expertise in vulnerability management, and is capable of mentoring junior team members and driving strategic improvements to the security program.
Security Operations Lead Experience : 5+ years of technical experience in security operations, with strong hands-on experience in vulnerability management. You've worked in a SOC, CSIRT, or similar operational security environment where you wore multiple hats and operated with a high degree of autonomy. You are willing to participate in a scheduled on-call rotation to effectively address and mitigate critical security incidents outside of business hours.
Experience investigating security alerts using EDRs and SIEM platforms. Familiarity with endpoint security policies, secure email gateways, and DLP concepts. Ability to produce clear, data-driven reporting for technical and executive audiences.
Experience working with Infrastructure as Code (IaC) tools such as Terraform, CloudFormation, or Ansible,
including the ability to review and secure infrastructure configurations.
Cloud Native : Experience working within cloud environments, preferably AWS, with an understanding of cloud-native vulnerability considerations including containers and serverless.
Experience with Python, Bash, or similar scripting languages to automate workflows, reporting, and integration with ticketing systems. Ability to interface with auditors, prepare evidence, and ensure security controls meet local compliance requirements. When the team needs support on an incident, a compliance audit, a threat intel deep-dive, or a security assessment, you lean in without hesitation.
Bilingual Communication : Required full professional fluency in English and Spanish. You must be able to translate technical findings into actionable guidance for engineering teams, auditors, and non-technical business partners.
Certifications : Defensive security certifications (GCIH, GEVA) are a plus. Offensive security certifications (OSCP, GPEN, GXPN) are a strong plus. Produce recurring vulnerability posture reports and trend analysis for stakeholders.
Serve as a technical investigator for complex security alerts and support the investigation, containment, and remediation of security incidents. Develop and integrate detection use cases for business applications, ensuring we are logging the right data, not just more data. Mentor and support junior team members, contributing to knowledge sharing and the overall growth of the security team.
LI-Remote We believe crypto is the future of finance, and we're committed to making it useful by providing equal access to safe and intuitive financial products. When we hire people for our team, we specifically test for the following traits in addition to our cultural values: Self-Management : We look for individuals who can independently manage their work, career, and professional development. Remote-first Premium health, dental and life insurances
📌 Remote Senior Security Operations Engineer (Zapopan)
🏢 Bitso
📍 Zapopan