Cloud Security Engineer (LatAm Only)
- Hiring from
- Latin America
- Work type
- Remote
- Posted
511,014 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
At R2, we believe that small and medium businesses are the productive engine of society. Small and medium businesses (SMBs) make up over 90% of companies in Latin America, yet they face a trillion-dollar credit gap. Our mission is to unlock SMBs’ potential by providing financial solutions tailored to their needs. We are reimagining the financial infrastructure of Latin America, where SMBs’ financial needs are met without ever having to go to a bank.
R2 enables platforms across Latin America to embed financial services that SMBs can leverage, starting with revenue-based financing. We are a high-performing, close-knit team with talent from organizations such as Google, Amazon, Nubank, Uber, Capital One, Mercado Libre, Globant, and J.P. Morgan.
We are entering a new phase of growth following a strategic investment from Ant International, focused on rapidly expanding our partner footprint, strengthening our credit and underwriting capabilities, and scaling operations across multiple markets. As part of this growth journey, eligible team members have the opportunity to participate in R2’s Phantom Share Program, a performance-based incentive designed to align our team with the company’s long-term success and value creation. We believe in building a culture of ownership, where those who help create value share meaningfully in it.
R2 is scaling quickly, and we're looking for a Cloud Security Engineer (IC3). You will secure R2’s cloud infrastructure and drive the adoption of DevSecOps practices across engineering. You’ll report to the Director of Infrastructure and work closely with our Security, Infrastructure and Platform Engineering teams. We’re looking for someone proactive, detail-oriented, and passionate about technology.
What You'll Do
- Cloud Security Posture
- Operate and improve CSPM, CNAPP and DSPM tooling across R2’s AWS footprint
- Identify, prioritize, triage and track remediation of cloud security findings end-to-end
- Ensure zero open high-severity findings older than 30 days
- IAM, Secrets & Data Protection
- Implement and harden IAM controls, encryption, secrets management and data protection across AWS accounts
- Own secrets rotation and access review processes for production systems
- DevSecOps & Automation
- Integrate security controls into CI/CD pipelines (GitHub Actions, GitLab CI) — SAST/SCA/IaC scanning with blocking criteria for high-severity findings
- Automate security processes via scripting (Python/Bash/Go), APIs and Terraform/IaC
- Network & Perimeter Security
- Manage and harden network security controls — WAF rule sets, security groups, NACLs, and network segmentation across VPCs
- Tune and maintain AWS WAF rate-limiting thresholds and manage rule groups against scanning and malicious traffic
- Enforce least-privilege network access across accounts and environments
- GenAI & Agent Security
- Contribute to securing R2’s GenAI applications, RAG architectures, agents, APIs, connectors and MCP servers
- Design and build internal AI/LLM-based security agents to automate threat detection, finding triage, and incident response.
- Define controls against data leakage, improper access, prompt injection and unsafe tool use by autonomous agents
- SOC & Detection
- Collaborate with the SOC on alert integration and use-case development in SIEM
- Cross-functional
- Build and maintain security documentation, runbooks and standards
- Support incident response, root cause analysis and remediation across production environments
Who You Are
- 3–5 years of experience in cloud security, DevSecOps or a similar role
- Hands-on experience with CSPM/CNAPP/DSPM platforms (Wiz, Prisma Cloud, Orca or equivalent)
- Strong AWS security knowledge (IAM, KMS, Secrets Manager, Security Hub, GuardDuty, Inspector)
- Experience embedding security into CI/CD pipelines and Infrastructure as Code (Terraform)
- Scripting ability (Python, Bash; Go a plus) for security automation via APIs
- Familiarity with Kubernetes/EKS and container security
- Experience hardening network security controls (WAF, security groups, NACLs, VPC segmentation)
- Understanding of GenAI/LLM security risks (prompt injection, agentic tool misuse, data leakage)
- English proficiency — written and spoken (required)
Nice to Have
- AWS Certified Security – Specialty
- Experience with SIEM/SOAR platforms
- Familiarity with ISO 27001, SOC 2, or similar compliance frameworks
- Fintech or regulated-industry experience
What We Offer
- The chance to join a high-impact, mission-driven fintech.
- Ownership and impact in a fast-paced, growth-oriented startup.
- Cross-functional collaboration with exceptional teams.
- Exposure to complex regulatory challenges and innovation in embedded finance.
Locations: Buenos Aires, São Paulo, Bogotá, Santiago