Stop applying to remote jobs that are already dead.
Every listing shows the evidence: when we last checked it, how, and when it was posted and closed.

All listings

R2 via BambooHR

Cloud Security Engineer (LatAm Only)

LATAM Level not stated
still open verified 2d ago posted 3d ago seen 2h ago
Apply at r2.bamboohr.com

This is the employer's own posting, not a copy on a job board.

What we know

Is it still open?

Confirmed still open

Last checked 2d ago — checked against the employer's own applicant tracking system, which is the company answering directly.

We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.

Check this listing's status as JSON

How old is it?

Posted 3d ago

The date the source published, not the day we noticed it (2026-10-08). Last seen at its source 2h ago.

We have tracked this listing since 8 Oct 2026 (2 days). The employer's own board has carried it every time we have read it, most recently 2 hours ago.

Is it remote?

Marked remote on the employer's board

Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.

Who may apply?

LATAM

No source stated where this role may be worked. This is read from the ad's own words.

Pay not stated

Similar roles pay $3,750–7,250/mo

Middle 50% of 52 listings that do state pay — Engineering · all levels · LATAM · USD/month. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.

Skills named in the ad

AWSBashCI/CDCross-functional CollaborationGitHub ActionsGitLab CIISO 27001Incident ManagementInfrastructure as CodeKnowledge BasePythonRAGSIEMSOC 2TerraformTroubleshooting

Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.

Carried by 1 source

The listing

At R2, we believe that small and medium businesses are the productive engine of society. Small and medium businesses (SMBs) make up over 90% of companies in Latin America, yet they face a trillion-dollar credit gap. Our mission is to unlock SMBs’ potential by providing financial solutions tailored to their needs. We are reimagining the financial infrastructure of Latin America, where SMBs’ financial needs are met without ever having to go to a bank.


R2 enables platforms across Latin America to embed financial services that SMBs can leverage, starting with revenue-based financing. We are a high-performing, close-knit team with talent from organizations such as Google, Amazon, Nubank, Uber, Capital One, Mercado Libre, Globant, and J.P. Morgan. 


We are entering a new phase of growth following a strategic investment from Ant International, focused on rapidly expanding our partner footprint, strengthening our credit and underwriting capabilities, and scaling operations across multiple markets. As part of this growth journey, eligible team members have the opportunity to participate in R2’s Phantom Share Program, a performance-based incentive designed to align our team with the company’s long-term success and value creation. We believe in building a culture of ownership, where those who help create value share meaningfully in it.


R2 is scaling quickly, and we're looking for a Cloud Security Engineer (IC3). You will secure R2’s cloud infrastructure and drive the adoption of DevSecOps practices across engineering. You’ll report to the Director of Infrastructure and work closely with our Security, Infrastructure and Platform Engineering teams. We’re looking for someone proactive, detail-oriented, and passionate about technology.


What You'll Do


  • Cloud Security Posture
    • Operate and improve CSPM, CNAPP and DSPM tooling across R2’s AWS footprint
    • Identify, prioritize, triage and track remediation of cloud security findings end-to-end
    • Ensure zero open high-severity findings older than 30 days
  • IAM, Secrets & Data Protection
    • Implement and harden IAM controls, encryption, secrets management and data protection across AWS accounts
    • Own secrets rotation and access review processes for production systems
  • DevSecOps & Automation
    • Integrate security controls into CI/CD pipelines (GitHub Actions, GitLab CI) — SAST/SCA/IaC scanning with blocking criteria for high-severity findings
    • Automate security processes via scripting (Python/Bash/Go), APIs and Terraform/IaC
  • Network & Perimeter Security
    • Manage and harden network security controls — WAF rule sets, security groups, NACLs, and network segmentation across VPCs
    • Tune and maintain AWS WAF rate-limiting thresholds and manage rule groups against scanning and malicious traffic
    • Enforce least-privilege network access across accounts and environments
  • GenAI & Agent Security
  • Contribute to securing R2’s GenAI applications, RAG architectures, agents, APIs, connectors and MCP servers
  • Design and build internal AI/LLM-based security agents to automate threat detection, finding triage, and incident response.
  • Define controls against data leakage, improper access, prompt injection and unsafe tool use by autonomous agents
  • SOC & Detection
    • Collaborate with the SOC on alert integration and use-case development in SIEM
  • Cross-functional
  • Build and maintain security documentation, runbooks and standards
  • Support incident response, root cause analysis and remediation across production environments


Who You Are


  • 3–5 years of experience in cloud security, DevSecOps or a similar role
  • Hands-on experience with CSPM/CNAPP/DSPM platforms (Wiz, Prisma Cloud, Orca or equivalent)
  • Strong AWS security knowledge (IAM, KMS, Secrets Manager, Security Hub, GuardDuty, Inspector)
  • Experience embedding security into CI/CD pipelines and Infrastructure as Code (Terraform)
  • Scripting ability (Python, Bash; Go a plus) for security automation via APIs
  • Familiarity with Kubernetes/EKS and container security
  • Experience hardening network security controls (WAF, security groups, NACLs, VPC segmentation)
  • Understanding of GenAI/LLM security risks (prompt injection, agentic tool misuse, data leakage)
  • English proficiency — written and spoken (required)

Nice to Have

  • AWS Certified Security – Specialty
  • Experience with SIEM/SOAR platforms
  • Familiarity with ISO 27001, SOC 2, or similar compliance frameworks
  • Fintech or regulated-industry experience



What We Offer

  • The chance to join a high-impact, mission-driven fintech.
  • Ownership and impact in a fast-paced, growth-oriented startup.
  • Cross-functional collaboration with exceptional teams.
  • Exposure to complex regulatory challenges and innovation in embedded finance.


Locations: Buenos Aires, São Paulo, Bogotá, Santiago

Apply at r2.bamboohr.com