Ciklum

Senior Cyber Security Engineer

Ciklum Mexico, Chihuahua, Mexico

IT Services and IT Consulting · 1,001-5,000 employees

4 h ago
Remote security Mid (2-5 yrs) Full-time Mexico
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Senior Cyber Security Engineer will support the production engineering team by embedding security into the SDLC and managing vulnerabilities across applications and microservices. They will also monitor security platforms, triage alerts, and collaborate with cross-functional teams to implement security controls aligned with industry frameworks.

What they look for

Application security Cloud security Python Go Kubernetes CI/CD Vulnerability management Penetration testing NIST CIS HiTrust Authentication Authorization Supply chain security Detection engineering Automation

Requirements

Candidates must have at least 2 years of experience in application security and expertise in cloud environments. Proficiency in modern programming languages like Python or Go and familiarity with CI/CD and container security are essential.

Benefits

Comprehensive company-paid medical insurance Mental health programs 5 undocumented sick-leave days per year Internal events Udemy license Language courses Company-paid certifications 20 working-days paid vacation Local bank holidays Internal mobility program

Full description

Ciklum is looking for a Senior Cyber Security Engineer to join our team in Mexico.

We are a custom product engineering company that supports both multinational organizations and scaling startups to solve their most complex business challenges. With a global team of over 4,000 highly skilled developers, consultants, analysts and product owners, we engineer technology that redefines industries and shapes the way people live.

About the role:

As a Senior Cyber Security Engineer, you'll become a part of a cross-functional development team engineering experience of tomorrow. You will support our client's security Team (Production Engineering). This team focuses on securing all product applications and services. This role works closely with engineering teams to embed security within the SLDC and ensures our services are crafted with the highest security standards and quality. You will help review and analyze detection and remediation of vulnerabilities from a variety of systems and services as well as support and respond to various operational activities related to our risk profile from third party monitoring services.

This role is ideal for someone with strong technical skills, a developer’s mindset, and a passion for securing modern applications and cloud services.

Responsibilities:

  • Support vulnerability management for applications and microservices
  • Provide guidance on secure authentication, authorization, secrets management, and data security
  • Evaluate, enhance, and recommend the implementation of application security automation within CI/CD pipelines to detect and remediate security issues early
  • Monitor, analyze, and triage alerts and logs from various security platforms such as Security Scorecard and other third party monitoring services
  • Triage, remediate, and escalate security alerts / events / reports
  • Stay current on emerging threats, vulnerabilities, and threat actor behaviors, and apply this knowledge to improve detection and response
  • Provide support for the response and remediation from vulnerabilities from our penetration testing program
  • Collaborate with Engineering, IT, Infrastructure, and Compliance teams to implement security controls aligned with frameworks like NIST, HiTrust, and CIS.
  • Maintain production security procedures and metrics
  • Develop and research enhanced security training
  • Ability to work independently to ensure goals set by leadership are reached, and a team player
  • Drive continuous improvement by identifying automation opportunities, integrating emerging best practices, and enhancing detection and response capabilities
  • Evaluate and apply AI/LLM based tooling to accelerate triage, deduplicating and correlating findings across scanners, prioritizing by exploitability and business context, and drafting remediation guidance while maintaining human review of results

Requirements:

  • Minimum 2 years experience in application security, or similar security roles
  • Expertise in cloud environments
  • Development experience in any modern programming language (Python, Go, etc.)
  • Familiarity with software development lifecycle (SDLC) processes and source control technologies
  • Experience with supply chain security (dependency management, SBOMs)
  • Exposure to container and CI/CD security (Kubernetes, GitHub Actions, etc.)
  • Exposure to offensive security expertise and penetration testing certifications, such as (OSWE, OSCP+, etc.) are highly desirable
  • Comfortable writing detection queries and scripts
  • Familiarity with regulatory frameworks such as SOC 2, CIS, or HiTrust
  • Knowledge of common attack vectors and MITRE ATT&CK framework
  • Problem-solving skills and the ability to thrive in a fast-paced, collaborative environment
  • Experience with SSO platforms, such as Okta and SAML are a plus
  • Experience with AWS, GCP, CDN/edge security tools and services are a plus
  • Experience with automation frameworks or scripting in Python, PowerShell, or Bash
  • Security certifications such as Security +, or CEH or similar

What`s in it for you?

  • Care: your mental and physical health is our priority. We ensure comprehensive company-paid medical insurance and mental health programs, 5 undocumented sick-leave days per year
  • Tailored education path: boost your skills and knowledge with our regular internal events (meetups, conferences, workshops), Udemy license, language courses and company-paid certifications
  • Growth environment: share your experience and level up your expertise with a community of skilled professionals, locally and globally
  • Long-term employment with 20 working-days paid vacation and local bank holidays
  • Flexibility: 100% remote work mode
  • Opportunities: we value our specialists and always find the best options for them. Our Internal Mobility Program helps change a project if needed to help you grow, excel professionally and fulfill your potential
  • Global impact: work on large-scale projects that redefine industries with international and fast-growing clients
  • Welcoming environment: feel empowered with a friendly team, open-door policy, informal atmosphere within the company and regular team-building events

About us:

At Ciklum, we are always exploring innovations, empowering each other to achieve more, and engineering solutions that matter. With us, you’ll work with cutting-edge technologies, contribute to impactful projects, and be part of a One Team culture that values collaboration and progress. As we expand into Latin America, every Ciklumer is helping to shape our story. Collaborate with seasoned experts and make a global impact backed by two decades of industry leadership.

Explore, empower, engineer with Ciklum!

Interested already? We would love to get to know you! Submit your application. We can’t wait to see you at Ciklum.

#LI-AV3

Similar roles