Senior Cloud Security Engineer - AA, Remote: Colombia - Costa Rica, Fulltime
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 2h ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 5d ago
The date the source published, not the day we noticed it (2026-09-28). Last seen at its source just now.
Is it remote?
Marked remote on the employer's board
Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.
Who may apply?
Colombia, Costa Rica
No source stated where this role may be worked. This is read from the ad's own words.
What the ad says
…position is open to candidates located in Colombia or Costa Rica only - The client builds AI-powered intelligence and document-analysis products for commercial and U.S. government customers…
Pay not stated
Similar roles pay $90k–102k/yr
Middle 50% of 9 listings that do state pay — Engineering · all levels · Colombia · USD/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
bamboohr employer's own board first seen 2h ago · last seen just now
- location not stated
The listing
- This position is open to candidates located in Colombia or Costa Rica only -
The client builds AI-powered intelligence and document-analysis products for commercial and U.S. government customers. Engineering runs a lean, AWS-first platform (Kubernetes/EKS, Terraform, GitHub Actions) with a smaller Azure footprint.
The security function works hand-in-hand with a small DevOps team and is supported by strong internal automation — we care more about sound judgment and self-direction than any one certification.
What you'll do
- A hands-on cloud security engineer to own day-to-day security operations and support our compliance programs. This is a sole-coverage role: the engineer is the security point of contact for the company, backed by DevOps for execution.
Required Qualifications
- Hands-on AWS security: IAM and least-privilege design, GuardDuty, Security Hub, CloudTrail
- Security alert triage and incident response in cloud environments
- Comfortable working in Terraform and shipping changes through pull requests
- Kubernetes security fundamentals (RBAC, workload hardening)
- Vulnerability management: scanning, prioritization, and coordinating remediation with engineers
- Experience supporting SOC 2 audits (control evidence, working with auditors)
- CI/CD and supply-chain security awareness (GitHub Actions, dependency/image
scanning)
Preferred Qualifications
- CrowdStrike Falcon administration (endpoint + cloud/container sensors)
- CMMC / NIST 800-171 / GCC High or FedRAMP exposure — we run a federal
compliance program, and portions of this work may require a U.S. person - Azure security (Microsoft Defender, ACR, Azure DevOps)
- Cloudflare Zero Trust (WARP) and WAF
- Golden image / AMI build pipelines (Packer)
- Scripting for security automation (Python preferred); comfort working alongside AI coding agents — our engineering workflow is heavily agent-assisted