Security Engineer
Summary of the Role
We are looking for a Cybersecurity Engineer to support and strengthen our cloud and enterprise security posture across Microsoft and AWS environments. In this hands-on role, you will be responsible for vulnerability scanning, CVSS-based triage, patch management, and serving as an internal first responder for security operations and MDR escalations. You will focus on operational execution alongside senior engineers, with room to grow into driving preventive hardening, DevSecOps pipelines, and security architecture.
Desired Skills
- Full-time availability
- Upper Intermediate English proficiency (B2 or above) with strong written and verbal communication skills.
- 3+ years of hands-on professional experience in cybersecurity and security operations roles.
- Demonstrated experience with the Microsoft security stack, specifically Defender for Endpoint, Defender for Office 365, Intune, and Entra ID (Azure AD).
- Practical experience securing multi-account AWS environments and cloud-native services.
- Proven track record running vulnerability scanning, triaging findings via CVSS, and driving issues through remediation to verified closure.
- Execution-focused background in running patch management workflows, system hardening, and responding to security alerts.
Responsibilities
- Execute vulnerability scanning, triage findings based on risk, and coordinate remediation across cloud and on-premise systems.
- Manage enterprise patch management workflows, software updates, and system configuration checks.
- Serve as the internal first responder for MDR escalations, security incidents, and endpoint alerts.
- Partner closely with internal IT, DevOps, and system owners to enforce established security standards and fix identified risks.
- Document security controls, remediation workflows, and operational procedures to maintain clear traceability.
Nice-to-Haves
- Deep experience designing and implementing preventive controls, Entra ID Conditional Access, and hybrid Active Directory hardening.
- Experience implementing AWS security controls using Infrastructure as Code (Terraform or CloudFormation) and CSPM tooling.
- Hands-on experience integrating SAST/DAST security testing into CI/CD pipelines, secure SDLC, and threat modeling.
- Proven track record owning enterprise patch governance, emergency patch protocols, and exception management.
- Experience supporting or leading compliance audits for frameworks like SOC 2, PCI DSS, GLBA, or ISO 27001.
- Practical scripting skills in PowerShell or Python to automate security tasks and triage workflows.
- Relevant industry certifications such as Security+, SC-200, AWS Certified Security - Specialty, or CISSP.
Who You Are
- Methodical, operationally disciplined, and persistent when driving security findings all the way to verified closure.
- Communicates complex security risks and technical requirements clearly to IT, DevOps, and business stakeholders.
- Takes strong personal ownership of assigned systems, documentation, and incident workflows.
- Collaborates effectively with senior technical leaders and engineering teams to solve underlying vulnerabilities rather than just clearing alerts.
Some benefits:
- 🏢 Offices in some cities
- 🖥️ 100% remote work
- ⌚ Full-time schedule, flexible according to objectives
- 🏖️PTO & holidays
- ⚕️Medical insurance
About Howdy
Howdy.com, founded in 2018 and headquartered in Austin, Texas, helps US companies who want to hire, manage, and retain their teams in Latin America (LatAm) directly but need help with multinational logistics, contracts, compliance, and culture. Companies that use Howdy.com get the best talent available in LatAm and gain access to an entire network and a thriving community of professionals who are changing the world. By partnering with Howdy.com, companies can expand their physical presence into some of the fastest-growing economies in LatAm.
Howdy.com is a member of Y Combinator and has garnered significant support from prominent investors, including Greycroft and Obvious Ventures. The company raised over $20 million in a series A venture capital round.
Our core values
#1 Sports Team: At Howdy, we win together. From players to support, everyone is vital to our success. We hire for excellence, prioritize teamwork, and strive for continuous improvement. We collaborate, seek advice, and actively contribute to Howdy's victories.
Altruism: Demonstrating altruism involves prioritizing the team and assuming the best in others. We communicate openly, provide honest feedback, and extend grace. Altruism is selfless service, focusing on supporting our players and team growth.
Curiosity: Being curious at Howdy means having the willingness to learn, adapt, and explore new ideas. We question existing beliefs, embrace humility, and see curiosity as our superpower. Demonstrating curiosity involves researching unfamiliar tasks, asking questions to understand the full picture, and seeking better ways to complete routine tasks.
Have Spirit: Having spirit at Howdy is about celebrating wins, building a sense of community, and bringing positivity. Demonstrating spirit involves attending events, getting to know teammates, participating in challenges, and proudly wearing the Howdy swag. Simply put, it's about bringing a super-fan spirit to work every day.