Nelo Logo

Nelo

Senior Security Engineer

Posted 3 Days Ago
Be an Early Applicant
In-Office
New York, NY
185K-220K Annually
Senior level
In-Office
New York, NY
185K-220K Annually
Senior level
Seek a Senior Security Engineer with strong cloud security and Terraform skills to build secure systems, manage certifications like SOC2, and lead external security programs for a fintech in NYC.
The summary above was generated by AI
About Nelo

Nelo is a leading consumer fintech and e-commerce platform in Mexico, with >$500MM in annualized GMV and >$70MM in annualized revenue. Our mission is to increase the buying power of consumers in Latin America by building a modern alternative to credit cards.

We’ve raised over $40M in venture capital from Homebrew, Two Sigma Ventures, and Susa Ventures, and secured a $100M asset credit facility from Victory Park Capital. Our lean team includes leaders from Uber, Amazon, Rappi, and DiDi, with offices in Mexico City and New York City.

About the Role

Security has been built into how we build software from day one, but as we scale we are creating a dedicated security engineering role with broad ownership across application security, infrastructure, and internal controls.

This role is built for someone who wants real ownership:

  • You will prioritize where to invest time and resources

  • You will implement controls yourself, not delegate them

  • You will be trusted to balance risk, velocity, and pragmatism

  • You will work closely with leaders including the CEO and CTO

This role is in-person in our NYC office (Tribeca).

What You’ll DoBuild Secure-by-Default Systems
  • Design and implement security guardrails across cloud infrastructure and developer workflows

  • Improve IAM, secrets management, endpoint management and access controls across production systems

  • Harden AWS infrastructure using Terraform and policy-as-code

  • Increase observability for security-relevant events and anomalies

Own Security as an Engineering Problem
  • Write code, configs, and tooling to enforce security controls

  • Reduce reliance on manual reviews through automation

  • Make the secure path the easiest path

Lead External Security Programs
  • Own and run penetration tests and bug bounty program

  • Triage findings and partner with engineers to fix issues

  • Turn findings into systemic improvements

Manage Certifications and Compliance
  • Take Nelo through SOC2 (Type 1 and Type 2)

  • Implement automated evidence collection

Raise the Bar Across the Team
  • Set standards by example through high-quality implementations

  • Review designs and PRs with a security-first mindset

Who You AreRequired
  • 5+ years of engineering experience, with a meaningful focus on security

  • Strong hands-on experience with cloud security fundamentals

  • Comfortable working with Terraform or similar infrastructure-as-code tooling

Strong Signals
  • You’ve taken a company through SOC2, ISO 27001, or similar certification

  • You’ve run bug bounty programs or managed pentests directly

  • You have strong experience with AWS (eg. GuardDuty, CloudTrail, IAM, security groups)

  • You use Claude Code or other agentic coding tools

Not a Fit If
  • You need a separate team to implement your ideas

  • You prefer static environments over fast-moving systems

Compensation and Benefits
  • Competitive compensation and meaningful equity

  • 100% medical, dental, and vision coverage (50% for dependents)

  • Unlimited PTO and generous parental leave

  • 401(k)

About the Process
  • Conversation with the hiring manager

  • Case study

  • On-site Interview

  • Fast decision

Top Skills

AWS
Bug Bounty Programs
Cloud Security
Iam
Security Groups
Security Guardrails
Terraform

Nelo New York, New York, USA Office

New York, New York, United States, 10013

Similar Jobs

Yesterday
In-Office
New York City, NY, USA
210K-270K Annually
Senior level
210K-270K Annually
Senior level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Real Estate
Responsible for designing, implementing, and maintaining security measures to protect systems and data. Automates security processes and collaborates with engineering teams to identify vulnerabilities and ensure compliance with standards.
Top Skills: AWSGoJavaScriptPythonRuby
4 Days Ago
Remote or Hybrid
US
82K-115K Annually
Senior level
82K-115K Annually
Senior level
Information Technology
The Sr. Security Engineer I leads incident response, threat detection, and engineering, managing investigations, enhancing detection capabilities, and mentoring analysts.
Top Skills: Crowdstrike XdrDnsEdrFirewallsIdentity LogsMicrosoft Azure Active DirectoryMicrosoft DefenderMicrosoft SentinelPalo Alto XsiamPowershellPythonSIEMSplunk
8 Days Ago
Remote or Hybrid
United States
90K-140K Annually
Senior level
90K-140K Annually
Senior level
Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
The Senior Security Engineer will identify and mitigate security issues, implement protective measures, and contribute to security platforms and documentation for Applied's infrastructure.
Top Skills: Amazon Web ServicesAnsibleAttack Surface ManagementBashCasbCspmCwppDlpGoogle Cloud PlatformKubernetesPamPowershellPythonSaseSwgTerraformWafZero Trust Network Access

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account