Jobs Companies Nelo Senior Security Engineer

Sobre esta vaga de Senior Security Engineer na Nelo

Nelo · Presencial · CDMX

Security Engineer

About Nelo

Nelo is a leading fintech in Mexico reimagining credit to expand consumer buying power. Founded in 2019 by former Uber international growth team leads Kyle Miller and Stephen Hebson, Nelo offers credit cards, BNPL loans, bill payments, and its own marketplace — all under one app — designed from first principles for a mobile-first, real-time payments world.

With $100M in annual revenue, $1B in annualized GMV, and $140M+ raised in equity and debt, Nelo is one of the most capital-efficient consumer fintech companies in Latin America. The company is profitable — positive operating profit in both 2024 and 2025. It runs lean and technical: 60 employees, 8 engineers, with AI driving underwriting, collections, and operations.

  • HQ: Mexico City, Mexico; commercial and people operations in New York City

  • Founded: 2019

  • Team size: 60 FTEs

  • Open roles: 10+

  • Website: nelo.mx

  • Stage: Post-Series A; $100M credit facility (Victory Park Capital, 2022); profitable

  • Benefits: 401k, open PTO, medical, dental, vision, STD, LTD, fertility

Company values:

  • Be your best selves: ambition, hard work, intellectual curiosity

  • Everyone is an owner: all employees receive equity including customer support; 10-year option expiration; equity refreshers

  • Customer first: product decisions grounded in customer benefit

  • Open and honest communication: quarterly financials and board presentations shared company-wide; low tolerance for bureaucracy or gossip

  • Move fast, learn fast: hundreds of experiments run monthly; rigorous experimentation cultureAbout the role

Security has been part of how Nelo builds software from day one. As we scale, we are creating a dedicated Security Engineer role with broad ownership across application security, cloud infrastructure, and internal controls.

This is a hands-on role for someone who wants to define the security function rather than inherit it. You will decide where to invest, implement controls yourself, and balance risk against velocity in a fast-moving lending business. You will work directly with the CTO, the CEO, and engineering leadership.

This role is in-person at our Mexico City office in Condesa.

What you'll do

Build secure-by-default systems

  • Design and implement security guardrails across cloud infrastructure and developer workflows

  • Improve IAM, secrets management, endpoint management, and access controls across production systems

  • Harden AWS infrastructure using Terraform and policy-as-code

  • Increase observability for security-relevant events and anomalies

Treat security as an engineering problem

  • Write code, configs, and tooling to enforce controls

  • Replace manual reviews with automation wherever it makes sense

  • Make the secure path the default path for engineers

Run external security programs

  • Own penetration tests and the bug bounty program end-to-end

  • Triage findings, partner with engineers on fixes, and turn one-off issues into systemic improvements

Drive certifications and compliance

  • Take Nelo through SOC 2 Type 1 and Type 2

  • Build automated evidence collection so compliance does not become a recurring tax on the team

Raise the bar across engineering

  • Set the standard through your own implementations

  • Review designs and PRs with a security-first lens

Why you should apply

  • You have built security programs at a startup before and know the difference between security theater and controls that actually reduce risk. You can tell which one a given investment is.

  • You write code and ship infrastructure yourself. Terraform, Python, Go, whatever the job calls for. You do not hand off implementation to someone else and call it done.

  • You have deep AWS instincts. You know where the sharp edges are in IAM, how to read CloudTrail, when GuardDuty findings matter and when they are noise.

  • You have taken a company through SOC 2 or a comparable certification and you know how to run it without grinding engineering to a halt. Automated evidence collection is the baseline you build toward, not a stretch goal.

  • You are comfortable with AI tools as part of your daily workflow. You use Claude Code or similar to move faster, and you have opinions about where they belong in a security review and where they do not.

  • You can hold a strong security position and still ship product on time. You see velocity and security as the same problem, not opposing ones.

Why you should NOT apply

  • You want to manage a team of security engineers. There is no team to manage. You are the team, at least for the foreseeable future. If your value is in delegating, this role will not fit.

  • You see security as a gatekeeping function. The job is to make the secure path the easiest path, not to block PRs and write policy documents that nobody reads. If your instinct is to slow things down rather than redesign them, the engineering team will route around you.

  • You need a mature environment with established tooling and processes. Some of this exists. Most of it does not. You are building the function, not stepping into one.

  • You treat compliance as a separate workstream from engineering. SOC 2 evidence at Nelo will be collected by code, not by a GRC tool with a person filling out questionnaires. If that distinction is not natural to you, this will feel like the wrong job.

  • You think AI tools are a gimmick. Every team at Nelo uses AI in daily workflows. If you are skeptical of agentic coding tools or refuse to use them, you will be working against the grain of how engineering moves here.

How we work

  • ~60 people across CDMX and New York. Lean, fast, opinionated about quality.

  • This role is based in Mexico City and is expected to be in-office given the proximity required with engineering and infrastructure work.

  • Every team at Nelo uses AI in daily workflows. Engineering is no exception.

Who you are

Required

  • Engineering background with substantial time spent on security in production environments

  • Strong hands-on experience with cloud security fundamentals, ideally on AWS

  • Comfortable building and modifying infrastructure with Terraform or equivalent IaC tooling

  • You ship code and own outcomes, not just recommendations

Strong signals

  • You have taken a company through SOC 2, ISO 27001, or a comparable certification

  • You have personally run a bug bounty program or managed external pentests

  • Depth in AWS security primitives such as GuardDuty, CloudTrail, IAM, VPC, KMS, and security groups

  • You use Claude Code or other agentic coding tools as part of your daily workflow

Interview process

  • Conversation with the hiring manager

  • Case study

  • On-site panel

  • Fast decision

Compensation and benefits

  • Competitive salary and meaningful equity

  • 100% medical, dental, and vision coverage

  • Unlimited PTO and extended parental leave

Pronto para se candidatar à Nelo?
Candidatar-se à Nelo

Vagas semelhantes

Cadastre-se para receber sugestões sob medida com base nas vagas que você abre e nas buscas que você salva.

Mais vagas na Nelo

Ver todas as vagas na Nelo →

Candidatar-se agora
🤖

Opa — calma aí

A JobsRadar foi feita para pessoas de verdade passando por um momento difícil na busca por emprego — não para requisições automatizadas. Você está clicando rápido demais e agora está temporariamente bloqueado.

Volte mais tarde. Se você está mesmo procurando emprego, estamos com você — apenas aja como um ser humano.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Ganhe vantagem na sua busca por emprego.

Entre no nosso canal do Telegram para o que ajuda você a conseguir a vaga — referências salariais, o pulso semanal do mercado e avisos de novos recursos. Sem spam, só sinal.

Entre no canal — é grátis