
Senior Security Operations Engineer at Bitso
MéxicoFull-timeSecurity EngineeringPosted about 2 months ago
About the Role
<div class="content-intro"><h3 class="p1"><span class="s1">Working At Bitso</span></h3>
<p class="p1"><span class="s1" style="font-size: 12pt;">We are a diverse team that takes pride in understanding the perspectives of others. We fully embrace working remotely and we are eager to act, improve and accelerate progress inside and outside of our organization.</span></p>
<p class="p1"><span class="s1" style="font-size: 12pt;">To drive revolutionary changes in society and make crypto useful, we delight our customers with world-class products, deep care, and intentional empathy.</span></p></div><p><strong><span style="font-size: 12pt;">Your Purpose</span></strong></p>
<p><span style="font-size: 12pt;">The Senior Security Engineer is a versatile member of the Security Operations team who brings deep expertise in vulnerability management while actively contributing across the full scope of security operations. You will own the vulnerability management function, but your involvement doesn’t stop there. You are expected to operate as a well-rounded security professional who supports the team across multiple disciplines, including:</span></p>
<ul>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Vulnerability Management</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Cyber Incident Management</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Threat Intelligence and Threat Hunting</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Security Assessments and Tool Evaluations</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Regulatory Compliance and Audit Support</span></li>
</ul>
<p><span style="font-size: 12pt;">This is a hands-on, execution-focused role within the Security Operations team. The ideal candidate owns the vulnerability management function with discipline and rigor, while consistently contributing to incident response, threat analysis, compliance support, and other operational priorities as they arise. This role requires a senior security professional who operates with a generalist mindset, brings expertise in vulnerability management, and is capable of mentoring junior team members and driving strategic improvements to the security program.</span></p>
<p><strong><span style="font-size: 12pt;">Reports To</span></strong></p>
<p><span style="font-size: 12pt;">Security Operations Lead</span></p>
<p><strong><span style="font-size: 12pt;">Who You Are</span></strong></p>
<ul>
<li style="font-size: 12pt;"><span style="font-size: 12pt;"><strong>Experience</strong>: 5+ years of technical experience in security operations, with strong hands-on experience in vulnerability management. You’ve worked in a SOC, CSIRT, or similar operational security environment where you wore multiple hats and operated with a high degree of autonomy.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;"><strong>Ops Mindset</strong>: You possess a strong sense of urgency and ownership. You don’t wait to be told what to do, you see gaps and fill them. You are willing to participate in a scheduled on-call rotation to effectively address and mitigate critical security incidents outside of business hours.</span></li>
</ul>
<p><span style="font-weight: 400; font-size: 12pt;"><strong>Technical Proficiency:</strong></span></p>
<ol>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Hands-on experience with enterprise vulnerability scanning platforms (Qualys, Tenable, Rapid7, or equivalent).</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Strong understanding of risk-based vulnerability prioritization beyond CVSS factoring in exploit availability, threat intelligence, asset exposure, and business context.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Experience investigating security alerts using EDRs and SIEM platforms.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Familiarity with endpoint security policies, secure email gateways, and DLP concepts.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Ability to produce clear, data-driven reporting for technical and executive audiences.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Experience working with Infrastructure as Code (IaC) tools such as Terraform, CloudFormation, or Ansible, including the ability to review and secure infrastructure configurations.</span></li>
</ol>
<ul>
<li style="font-size: 12pt;"><span style="font-size: 12pt;"><strong>Cloud Native</strong>: Experience working within cloud environments, preferably AWS, with an understanding of cloud-native vulnerability considerations including containers and serverless.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;"><strong>Automation & Scripting</strong>: Experience with Python, Bash, or similar scripting languages to automate workflows, reporting, and integration with ticketing systems. Experience leveraging AI/ML tools to improve operational efficiency is a plus.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;"><strong>Regulatory & Compliance</strong>: Experience supporting regulatory compliance audits and working within frameworks relevant to the Mexican financial regulatory landscape (CNBV, Ley Fintech). Ability to interface with auditors, prepare evidence, and ensure security controls meet local compliance requirements.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;"><strong>Adaptability</strong>: You are comfortable operating outside your primary domain. When the team needs support on an incident, a compliance audit, a threat intel deep-dive, or a security assessment, you lean in without hesitation.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;"><strong>Bilingual Communication</strong>: Required full professional fluency in English and Spanish. You must be able to translate technical findings into actionable guidance for engineering teams, auditors, and non-technical business partners.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;"><strong>Certifications</strong>: Defensive security certifications (GCIH, GEVA) are a plus. Offensive security certifications (OSCP, GPEN, GXPN) are a strong plus.</span></li>
</ul>
<p><strong><span style="font-size: 12pt;">What You Will Do</span></strong></p>
<ul>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Own and operate the end-to-end vulnerability management lifecycle: discovery, scanning, prioritization, remediation tracking, and verification.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Prioritize vulnerabilities using a risk-based approach that accounts for exploitability, threat intelligence, asset criticality, and business impact.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Produce recurring vulnerability posture reports and trend analysis for stakeholders.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Serve as a technical investigator for complex security alerts and support the investigation, containment, and remediation of security incidents.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Participate in the on-call rotation to ensure coverage for critical alerts.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Consume threat intelligence feeds and proactively hunt for Indicators of Compromise (IOCs) in our environment.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Develop and integrate detection use cases for business applications, ensuring we are logging the right data, not just more data.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Support regulatory compliance audits, including preparation of evidence and documentation aligned with Mexican financial regulatory requirements.</span></li>
<li style="font-size: 12pt;"><span style="font-size: 12pt;">Mentor and support junior team members, contributing to knowledge sharing and the overall growth of the security team.</span></li>
</ul>
<p> </p>
<p><em><span style="font-weight: 400; font-size: 12pt;"><a href="https://hbr.org/2022/07/apply-to-a-job-even-if-you-dont-meet-all-criteria">Research</a> in Diversity, Equity, and Inclusion suggests that individuals may hesitate to apply for jobs if they do not meet all the listed criteria. At Bitso, we value diversity and your unique strengths could be just what we're looking for. If this role excites you but you don't match every point in the description, we still want to hear from you.</span></em></p>
<p class="hashtag"><span style="font-weight: 400; font-size: 12pt;">#LI-Remote </span><span style="font-weight: 400; font-size: 12pt;"><br><br></span></p><div class="content-conclusion"><h3 class="p1" style="line-height: 1.4;"><span class="s1" style="font-size: 12pt;">Who We Are</span></h3>
<p class="p1" style="line-height: 1.4;"><span class="s1" style="font-size: 12pt;">With over 9 million users, Bitso is the leading cryptocurrency platform in Latin America. We are developing the cryptocurrency ecosystem in the region and enabling financial inclusion. We believe crypto is the future of finance, and we’re committed to making it useful by providing equal access to safe and intuitive financial products.</span></p>
<p style="line-height: 1.4;"><span style="font-size: 12pt;">When we hire people for our team, we specifically test for the following traits in addition to our cultural values:</span></p>
<ul class="ak-ul" data-indent-level="1">
<li style="font-size: 12pt;">
<p data-renderer-start-pos="5354"><span style="font-size: 12pt;"><strong data-renderer-mark="true">Mission-Driven</strong>: We seek individuals who are passionate about crypto and Bitso’s mission and resilient in facing industry challenges</span></p>
</li>
<li style="font-size: 12pt;">
<p data-renderer-start-pos="5354"><span style="font-size: 12pt;"><strong data-renderer-mark="true">High Sense of Urgency</strong>: We prioritize candidates who demonstrate a high sense of urgency and responsibility.</span></p>
</li>
</ul>
<ul class="ak-ul" data-indent-level="1">
<li style="font-size: 12pt;">
<p data-renderer-start-pos="5603"><span style="font-size: 12pt;"><strong data-renderer-mark="true">Exceptional Hard Skills</strong>: We seek individuals who possess exceptional skills in their respective fields, with no room for mediocrity.</span></p>
</li>
<li style="font-size: 12pt;">
<p data-renderer-start-pos="5739"><span style="font-size: 12pt;"><strong data-renderer-mark="true">Self-Management</strong>: We look for individuals who can independently manage their work, career, and professional development.</span></p>
</li>
</ul>
<h3 class="p1" style="line-height: 1.4;"><span class="s1" style="font-size: 12pt;">Compensation & Benefits</span></h3>
<p class="p1" style="line-height: 1.4;"><span class="s1" style="font-size: 12pt;">At Bitso, you are taking the front seat on the edge of crypto innovation, creating the next generation of crypto-powered products.</span></p>
<p class="p1" style="line-height: 1.4;"><span class="s1" style="font-size: 12pt;">So for those willing to commit, adapt and pioneer the most important change of the century we offer:</span></p>
<ul class="ul1">
<li class="li1" style="font-size: 12pt;"><span class="s1" style="font-size: 12pt;"><strong>Me Time</strong> program, including unlimited paid time off.</span></li>
<li class="li1" style="font-size: 12pt;"><span class="s1" style="font-size: 12pt;"><strong>Remote-first</strong> work environment.</span></li>
<li class="li1" style="font-size: 12pt;"><span class="s1" style="font-size: 12pt;"><strong>Employee Stock Option</strong> program.</span></li>
<li class="li1" style="font-size: 12pt;"><span class="s1" style="font-size: 12pt;"><strong>Zero trading fees</strong> through our Bitso Alpha app.</span></li>
<li class="li1" style="font-size: 12pt;"><span class="s1" style="font-size: 12pt;"><strong>Extended Family Leave</strong> <strong>Policy:</strong> all birthing parents, non-birthing parents and adopting parents are eligible for a 4-months leave.</span></li>
<li class="li1" style="font-size: 12pt;"><span class="s1" style="font-size: 12pt;"><strong>Premium health, dental and life insurances</strong> in Mexico, Gibraltar, Colombia, USA, Brazil and Argentina.</span></li>
</ul>
<p class="p1" style="line-height: 1.4;"><span class="s1" style="font-size: 12pt;">Want to leave an undoubtedly legacy with us? Fasten your seatbelt and join this spaceship, where you will find exponential growth and the opportunity to thrive!</span></p>
<ul class="ul1">
<li class="li1" style="font-size: 12pt; line-height: 1.4;"><span class="s1" style="font-size: 12pt;">These are the applicable requisites, although equivalent competencies in any of the above will also be considered.</span></li>
<li class="li1" style="font-size: 12pt; line-height: 1.4;"><span class="s1" style="font-size: 12pt;">To see our Privacy Policy please click <a href="https://bitso.com/terms" target="_blank">here</a>.</span></li>
</ul></div>