SR Security Engineer

Full-Time
Fully_Remote
Argentina, Chile, Colombia, Mexico, Peru, Uruguay, Brazil

Summary of the Role

We are looking for a Senior Security Engineer to own the end-to-end design, implementation, and hardening of our enterprise cloud and systems infrastructure. Sitting within the Technology team, you will establish preventive controls, design structural security improvements, and lead patch management programs across multi-account AWS environments and Microsoft enterprise ecosystems. You will integrate security into CI/CD pipelines, lead threat modeling efforts, and set the security standard across Engineering, DevOps, and IT to ensure proactive defense and risk mitigation.

Desired Skills

  • Upper Intermediate English proficiency (strong verbal and written communication).
  • 5+ years of hands-on security engineering experience in vulnerability management and security operations.
  • Hands-on Microsoft Hardening: Deep expertise securing Microsoft environments, including Defender for Endpoint, Defender for Office 365, Intune, Entra ID Conditional Access, and hybrid Active Directory.
  • AWS Cloud Security & IaC: Strong experience securing multi-account AWS environments and cloud-native services using Infrastructure as Code (IaC) to implement preventive security controls.
  • Enterprise Patch Governance: Proven ownership of enterprise-wide patch management programs, including emergency patching strategies and exception governance.
  • DevSecOps & Secure SDLC: Hands-on experience integrating security testing (SAST/AppSec) into CI/CD pipelines, conducting threat modeling, and implementing cloud/network security controls.
  • Program & Technical Leadership: Demonstrated ownership of preventive security initiatives with the ability to mentor engineers, influence cross-functional teams, and translate complex risk/compliance requirements into practical engineering controls.

Responsibilities

  • Infrastructure & Cloud Hardening: Design, deploy, and enforce preventive security controls across multi-account AWS infrastructure and Microsoft modern workplace ecosystems (Intune, Defender, Entra ID).
  • Enterprise Patch & Vulnerability Management: Own and operate the end-to-end enterprise patch management program, overseeing regular updates, emergency patch deployments, and exception workflows.
  • DevSecOps & Application Security: Integrate automated security testing (SAST) into CI/CD pipelines, partner with engineering teams on secure SDLC practices, and conduct threat modeling.
  • Security Architecture & Standards: Set structural security benchmarks, author clear security documentation, and drive proactive controls that mitigate risk before incident creation.
  • Mentorship & Cross-Functional Collaboration: Mentor junior security engineers and influence Engineering, DevOps, and IT teams to embed security best practices into daily workflows.

Nice-to-Haves

  • Industry & Audit Experience: Background in Financial Services or FinTech (or other highly regulated industries), with exposure to SOC 2, PCI DSS, or ISO 27001 audit leadership.
  • Vendor & Tooling Ownership: Experience selecting, onboarding, or managing MDR/MSSP vendors, as well as hands-on exposure to CSPM tools (e.g., Orca Security).
  • Advanced Security Operations: Experience in detection engineering, threat hunting, or managed SOC oversight.
  • Relevant Certifications: CISSP, CCSP, AWS Certified Security – Specialty, Microsoft SC-200 / SC-300, or GIAC certifications.

Who You Are

  • Preventive & Proactive Security Mindset: You focus on prevention, architectural improvements, and building durable controls rather than strictly executing an operational alert triage queue.
  • Strong Ownership & Technical Leader: You comfortably take full ownership of security programs end-to-end, set high technical standards, and enjoy mentoring other engineers to elevate the team.
  • Architectural Thinker & Influencer: You possess strong risk-assessment judgment and excel at translating compliance or security needs into clear, practical engineering controls while influencing Engineering, DevOps, and IT partners.

Some benefits: 

  • 🏢 Offices in some cities 
  • 🖥️ 100% remote work
  • ⌚ Full-time schedule, flexible according to objectives
  • 🏖️PTO & holidays
  • ⚕️Medical insurance

About Howdy

Howdy.com, founded in 2018 and headquartered in Austin, Texas, helps US companies who want to hire, manage, and retain their teams in Latin America (LatAm) directly but need help with multinational logistics, contracts, compliance, and culture. Companies that use Howdy.com get the best talent available in LatAm and gain access to an entire network and a thriving community of professionals who are changing the world. By partnering with Howdy.com, companies can expand their physical presence into some of the fastest-growing economies in LatAm.

Howdy.com is a member of Y Combinator and has garnered significant support from prominent investors, including Greycroft and Obvious Ventures. The company raised over $20 million in a series A venture capital round.

Our core values

#1 Sports Team: At Howdy, we win together. From players to support, everyone is vital to our success. We hire for excellence, prioritize teamwork, and strive for continuous improvement. We collaborate, seek advice, and actively contribute to Howdy's victories.

Altruism: Demonstrating altruism involves prioritizing the team and assuming the best in others. We communicate openly, provide honest feedback, and extend grace. Altruism is selfless service, focusing on supporting our players and team growth.

Curiosity: Being curious at Howdy means having the willingness to learn, adapt, and explore new ideas. We question existing beliefs, embrace humility, and see curiosity as our superpower. Demonstrating curiosity involves researching unfamiliar tasks, asking questions to understand the full picture, and seeking better ways to complete routine tasks.

Have Spirit: Having spirit at Howdy is about celebrating wins, building a sense of community, and bringing positivity. Demonstrating spirit involves attending events, getting to know teammates, participating in challenges, and proudly wearing the Howdy swag. Simply put, it's about bringing a super-fan spirit to work every day.