Mid Security Engineer
Summary of the Role
We are looking for a Midlevel Security Engineer to own the operational core of our security program across Microsoft and AWS environments. Working closely with the Senior Security Engineer, you will actively execute vulnerability scanning, CVSS-based triage, patch management, and remediation to drive findings through verified closure. Additionally, you will support everyday security operations, network/application security, and serve as an internal first responder for managed detection and response (MDR) escalations.
Desired Skills
- Upper Intermediate English proficiency (strong verbal and written communication).
- 3+ years of hands-on security engineering experience in vulnerability management and security operations.
- Demonstrated experience running vulnerability scanning and CVSS-based triage, actively driving findings through remediation to closure.
- Practical experience across the Microsoft security stack, specifically Microsoft Defender (Endpoint/Office 365), Intune, and Entra ID.
- Working knowledge of securing cloud environments and native services within AWS.
- Applied experience responding to operational security incidents and triage escalations.
Responsibilities
- Vulnerability & Patch Management: Execute routine vulnerability scanning, perform CVSS triage, deploy patches, and coordinate remediation across enterprise endpoints and cloud systems.
- Microsoft & AWS Operations: Maintain, monitor, and enforce security controls across Microsoft Defender, Intune, Entra ID, and AWS infrastructure.
- Incident Response & MDR Support: Act as the internal first responder for MDR escalations, assisting with investigation, containment, and mitigation.
- Security Hardening Execution: Collaborate with system and engineering owners to execute security standards established by the Senior Security Engineer.
Nice-to-Haves
- Security certifications such as Security+, SC-200, AZ-500, or AWS Certified Security - Specialty.
- Experience in financial services, fintech, or highly regulated environments (SOC 2, PCI DSS, GLBA, ISO 27001).
- Basic automation and scripting experience using PowerShell or Python.
- Prior experience working alongside an MDR/MSSP or supporting security audit evidence collection.
Who You Are
- Strong Ownership & Follow-Through: You are operationally disciplined and take pride in independently driving security findings through to verified closure.
- Collaborative Communicator: You maintain strong documentation, communicate clearly with system owners, and escalate issues when necessary without hesitation.
- Execution-Minded Partner: You thrive working alongside senior engineers, translating strategic hardening standards into daily operational success.
Some benefits:
- 🏢 Offices in some cities
- 🖥️ 100% remote work
- ⌚ Full-time schedule, flexible according to objectives
- 🏖️PTO & holidays
- ⚕️Medical insurance
About Howdy
Howdy.com, founded in 2018 and headquartered in Austin, Texas, helps US companies who want to hire, manage, and retain their teams in Latin America (LatAm) directly but need help with multinational logistics, contracts, compliance, and culture. Companies that use Howdy.com get the best talent available in LatAm and gain access to an entire network and a thriving community of professionals who are changing the world. By partnering with Howdy.com, companies can expand their physical presence into some of the fastest-growing economies in LatAm.
Howdy.com is a member of Y Combinator and has garnered significant support from prominent investors, including Greycroft and Obvious Ventures. The company raised over $20 million in a series A venture capital round.
Our core values
#1 Sports Team: At Howdy, we win together. From players to support, everyone is vital to our success. We hire for excellence, prioritize teamwork, and strive for continuous improvement. We collaborate, seek advice, and actively contribute to Howdy's victories.
Altruism: Demonstrating altruism involves prioritizing the team and assuming the best in others. We communicate openly, provide honest feedback, and extend grace. Altruism is selfless service, focusing on supporting our players and team growth.
Curiosity: Being curious at Howdy means having the willingness to learn, adapt, and explore new ideas. We question existing beliefs, embrace humility, and see curiosity as our superpower. Demonstrating curiosity involves researching unfamiliar tasks, asking questions to understand the full picture, and seeking better ways to complete routine tasks.
Have Spirit: Having spirit at Howdy is about celebrating wins, building a sense of community, and bringing positivity. Demonstrating spirit involves attending events, getting to know teammates, participating in challenges, and proudly wearing the Howdy swag. Simply put, it's about bringing a super-fan spirit to work every day.