Ready to accelerate your career?
Clara is the fastest-growing company in Latin America.
We've built the leading solution for companies to make and manage all their payments.
We already help over 20,000 large and growing businesses operate with agility and financial clarity through locally issued corporate cards, bill pay, financing, and a powerful B2B platform built for scale.Clara is backed by some of the most successful investors in the world, including top regional VCs like monashees, Kaszek, and Canary, and leading global funds like Notable Capital, Coatue, DST General Partners, ICONIQ Growth, General Catalyst, Citi Ventures, SV Angel, Citius, Endeavor Catalyst, and Goldman Sachs - in addition to dozens of angel investors and local family offices.
We're building the financial infrastructure that powers high-performing organizations across the region.
We invite you to join us if you want to be part of a fast-paced environment that will accelerate your career and support you to do some of the best work of your life alongside a passionate and committed team distributed across the Americas.Security EngineerWhat you'll doYou will own outcomes, not a queue.
You'll lead workstreams across the security function, pair with and mentor early-career engineers, and be trusted to make calls without waiting for sign-off.Own the AI security posture, enabling rather than blockingDefine and operate the controls for how Clara uses LLMs, coding agents, agentic browsers, MCP integrations and internal inference gateways: data handling, identity, permissions, loggingOwn the LLM-based investigation agent on the SIEM: design its instructions and rules, evaluate its accuracy, catch hallucinated attributions and unsupported conclusions, and decide what it is allowed to close autonomouslyThreat-model AI systems as first-class attack surface: prompt injection, data exfiltration through AI tools, over-privileged agents, model and tool supply chainBuild the guidance and paved paths that let product and engineering adopt AI safely by default, and be a credible voice in those decisionsCloud security on AWS and GCPOwn detection and posture across AWS (GuardDuty, IAM, VPC, CloudTrail) and GCP (Security Command Center, IAM, service accounts, org policies), and drive remediation with the owning teamsDesign and implement guardrails as code: organization policies, SCPs, IAM boundaries, infrastructure-as-code policy checksLead parts of our large-scale GCP project inventory and cleanup program, and turn one-off findings into automated controlsSecure identity and edge: Auth0, Cloudflare, Google Workspace, SSO and service-to-service authenticationSecure code, CI/CD and application securityRun and evolve the application security program: SAST (SonarQube, Semgrep or similar), dependency and secrets scanning, PR review for security-sensitive changes, and CI/CD pipeline hardeningReview architecture and code for new products and integrations (card issuing, payments, banking partners) and produce actionable, prioritized findingsDefine secure-by-default patterns and libraries for engineers, including for AI-generated code,
and measure whether they're being usedCoordinate pentests and vulnerability disclosure, and drive findings to closureDetection, response and incident leadershipBuild and tune detections in Splunk across identity/SSO, cloud, endpoint, email and network sources, with a bias toward high-signal alertsLead incident investigation and response through incident.io: scoping, containment (EDR isolation, credential revocation, cloud access), root cause and post-incident reviewOwn email and web protection policy and the phishing programMentor early-career engineers on investigation technique and evidence-based reporting, and review their workCompliance as a byproduct of good engineeringMap your controls to PCI DSS and ISO ***** requirements, and produce the evidence auditors need without slowing the team downSupport customer security reviews and enterprise sales when a technical voice is neededWhat we look for2–4 years in security engineering, cloud security, application security or a closely related engineering role, including hands-on production experienceStrong, practical knowledge of AWS and/or GCP security: IAM design, network controls, logging and detection, and the ability to read and write infrastructure as code (Terraform or similar)Solid programming ability in at least one language (Python, Go, JavaScript/TypeScript): you build tooling and automation, not just review other people's codeReal secure-code experience: you can find and explain injection, auth/authz, secrets handling and supply-chain issues in code and in CI/CD pipelines, and you know how to get developers to fix themHands-on experience with a SIEM (Splunk preferred) and an EDR platform, including detection engineering and investigationWorking understanding of LLM-based systems and agents, including their failure modes, and experience using or building with them in a technical settingSound judgment on risk: you know the difference between a finding that blocks a launch and one that ships with a follow-up, and you can defend that callStrong written and spoken communication in Spanish and English; you can explain a risk to an engineer, a product manager and an auditor in the same weekComfort with pace and ambiguity: priorities move, the stack evolves, and you'd rather build the process than wait for itNice to haveExperience in fintech, payments or another regulated environment (PCI DSS, ISO *****, SOC 2)Experience securing or red-teaming LLM applications, agents or MCP toolingKubernetes and container securityDetection-as-code, SOAR or security automation experienceCertifications such as AWS Security Specialty, Google Professional Cloud Security Engineer, OSCP, GIAC or CISSPPortugueseContributions to open source, conference talks or CTF/bug bounty track recordWhat you'll getOwnership of problems that matter at a unicorn fintech,
with direct exposure to leadership and to the decisions that shape how Clara adopts AIFrontier work: securing agentic AI in production, in a company that is actually deploying itA modern stack and the mandate to improve it: AWS, GCP, Splunk, Auth0, Cloudflare, SonarQube, incident.io, Claude and internal AI toolingA team that values evidence over hierarchy, and expects you to push back when the data doesn't holdBudget and time for certifications, conferences and the hacker communityFast, transparent hiring: application review, a technical deep-dive on real scenarios you've handled, a practical exercise, and conversations with the team and leadershipHow to stand outTell us about a control you designed that made engineers faster, not slower.
Or an incident you led, a detection you built, a vulnerability you found, or something you've published.
We care about how you think about risk and how you get things fixed, not about the length of your tool list.Why join ClaraAt Clara, you'll have the autonomy, speed, and support to make meaningful impact — not just on your team, but on how organizations are run across Latin America.Who we areWe're the leading B2B fintech for spend management in Latin America.Certified as one of the world's fastest-growing companies, a Great Place to Work, and a LinkedIn Top Startup.Passionate about making Latin America more prosperous and competitive.Constantly innovating to build financial infrastructure that enables each of our customers to thrive.Product-led, high-talent-density culture — designed for builders who raise the bar.Proud of our open, inclusive, and values-driven environment.What we believe in#Clarity.
We say things clearly, directly, and proactively.
#Simplicity.
We reduce noise to focus on what really matters.
#Ownership.
We take responsibility and never wait to be told.
#Pride.
We build products and experiences we're proud of.
#Always Be Changing (ABC).
We grow through feedback, risk-taking, and action.
#Inclusivity.
Every voice counts.
Everyone contributes to our mission.What we offerCompetitive salary and stock options (ESOP) from day oneMulticultural team with daily exposure to Portuguese, Spanish, and English (our corporate language)Annual learning budget and internal accelerated development pathsHigh-ownership environment: we move fast, learn fast, and raise the bar — togetherSmart, ambitious teammates — low ego, high impactFlexible vacation and hybrid work model focused on resultsIf you're ready for growth, ownership, and impact — apply now and help us redefine B2B finance in Latin America.
Clara's Hybrid PolicyClaridians in a hybrid mode split their time between working from the office, talking to or visiting customers, or working from home.
This hits a balance between bringing people together for in-person collaboration and learning from each other, while supporting flexibility about how to do this in a way that makes sense for each individual and team.We don't enforce a minimum number of days for most roles, but you're expected to spend time at the office organically, and be at the office most days during your ramp-up or when required by your leader.
📌 Security Engineer (Ingeniero/A De Seguridad) (Xico)
🏢 Clara
📍 Xico