Confirmed on the employer's own hiring board on Sep 24, 2026. First seen by Alion on Sep 24, 2026. Azumo scores A on the Alion truth index.
Senior Security Engineer
Azumo builds and operates production AI systems for companies ranging from seed-stage startups to Meta. We are hiring a Senior Security Engineer to own the technical security posture of those systems once they are live: the infrastructure they run on, the pipelines that feed them, and the agents that act on their output. The role is fully remote across Latin America, aligned to your client's working day.
This is not an audit seat. Azumo has shipped production AI since 2016, and the work here is in the systems themselves - hardening infrastructure, closing vulnerabilities, and building the guardrails that keep AI-driven workflows safe in front of real users.
Where this role sits
At Azumo, ownership is split by what gets built: the pipelines, the method behind a decision, the product, and what an AI system does once it's live. Security doesn't work that way. It has to be right across all of them, and that's what this role owns.
Gap or breach, it's yours. If there's a gap, you find it and close it before anyone outside the team does. If there's a breach, you run it: containment, root cause, and the fix that keeps it from happening twice.
Whoever builds the system answers for whether it works. You answer for whether it's safe to run. That split is agreed before the work starts, not reported after.
What you will build
- Platform and infrastructure hardening: Cloud infrastructure, APIs, internal tooling, and CI/CD pipelines: encryption, secrets management, logging, and access controls that are built in, not bolted on, and stay correct as the systems around them change.
- Vulnerability management and offensive security: Scanning, penetration testing, adversarial testing, threat modeling, and manual review across everything Azumo ships into a client's environment - with remediation you drive to closed, not to ticket.
- AI and agent security: Prompt-injection defense, adversarial-input testing, and guardrails for the tool-calling and agentic systems the AI Engineer lane builds. Untrusted input arrives from IVR and voice channels, web systems, APIs and people, and what handles it stays bounded, observable and safe to fail.
- Watching what the agents do: Monitoring AI systems in production for anomalies, abuse attempts and unsafe decisions - the same production behavior the AI Engineer lane measures for accuracy, watched here for misuse.
- The standing audit: Azumo runs an automated security, cost, and architecture audit across every client codebase, graded by severity down to the file and line, on day one and every day after. You own it - what it checks, how it's graded, how often it's wrong.
- Monitoring, detection, and incident response: Alerting and detection for what you harden, investigation when something looks wrong, and root cause when it turns out to be something. You lead the response itself: containment, the remediation plan, and the preventative change that follows, with operational visibility into access patterns and security events maintained rather than reconstructed after the fact.
- Customer and partner security engagement: Security questionnaires, vendor risk assessments, and enterprise RFPs, plus the technical questions that come directly from a client's bank, auditor or enterprise prospect. You explain the architecture, the controls and what is monitored, and you defend the answer without a translation layer in between.
- Secure development practices: Working with the engineering teams on how they build, not only on what they ship: architecture reviews, secure patterns, and the trade-off between security, reliability and delivery speed argued in the room with Product, Compliance and Operations rather than raised afterwards.
- Work inside the client's environment: Their repositories, their tooling, sometimes their compliance review. Azumo is SOC 2 certified, client code stays in client repositories, and some engagements carry additional requirements such as HIPAA.
How we work
Our engineers build with AI every day. Claude Code, Codex, and similar tools are part of the standard toolchain here, not an experiment. The audit you'll own runs across the whole codebase on day one and every day after, grading security, cost, and architecture findings by severity with the exact file and line, so a small team can move quickly without quality drifting. We stay vendor-neutral across OpenAI, Anthropic, and open-weight models, and we run Valkyrie, our own production layer, when a single interface to any model is the right call.
About Azumo
Azumo is a San Francisco based software development company that has been building intelligent applications since 2016. We provide nearshore AI engineering teams to organizations that need production AI faster than they can hire for it: as an embedded engineering team, as AI staff augmentation alongside an existing team, or as a full project build.
Our engineers work from Latin America, aligned to United States time zones, and have delivered for Twitter, Meta, Discovery Channel, Omnicom, UnitedHealth, and CENTEGIX.
We hire for seniority and test for it before anyone joins a client team. We support engineers in going deep on the modern AI stack, and we give time back to open-source work, community teaching, and philanthropy.
Apply at https://azumo.com/join-our-team or write to us at [email protected].
Requirements
Basic qualifications
- 5+ years of hands-on experience in security engineering, infrastructure security, application security, DevSecOps, or offensive security, with the engineering fundamentals to match: testing, code review, CI/CD, Git, containers, and API design.
- Deep, current knowledge of the AWS ecosystem, and the judgment to secure it under production pressure, not just in a lab.
- Demonstrated experience identifying and remediating vulnerabilities in live production systems.
- Experience securing AI or LLM-powered systems or automated agents: prompt injection, adversarial inputs, unauthorized actions, unsafe outputs, and data leakage. This is the requirement we screen hardest on.
- Working knowledge of compliance frameworks as operating practice rather than documentation: SOC 2, PCI DSS, and the expectations that come with handling financial and consumer data, kept continuously rather than assembled for an audit.
- Self-directed prioritization. You decide what gets fixed first in a fast-moving environment, and you can explain why.
- Active use of AI-assisted coding tools such as Claude Code, Cursor, or GitHub Copilot in real delivery work.
- Strong communication skills: the ability to explain a finding to engineers and defend it to a client directly, without a translation layer in between.
- Clear written and spoken English, C1 or above.
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent professional experience.
Preferred qualifications
- Familiarity with prompt-injection attacks, adversarial AI techniques, AI guardrails, and behavioral anomaly detection.
- Cloud security tooling, SIEM and observability platforms, penetration testing tools, endpoint security platforms, and infrastructure-as-code security (Terraform, Bicep, or similar).
- Prior experience in high-growth startup, fintech, banking, or payments environments.
- Certifications such as CISSP, CISM, AWS Security Specialty, or similar.
- Contributions to open-source security tooling, published technical writing, or active participation in the security community.
Benefits
100% remote-firste culture (work anywhere in Latin America)
Paid time off (PTO)
U.S Holidays
Solid AI Training and certification
Mentored career development
Profit Sharing
$US remuneration
Maternity coverage

