Azumo builds and operates production AI systems for companies ranging from seed-stage startups to Meta. We are hiring a Senior Security Engineer to own the technical security posture of those systems once they are live: the infrastructure they run on, the pipelines that feed them, and the agents that act on their output. The role is fully remote across Latin America, aligned to your client's working day.
You will not be writing policy. Azumo has shipped production AI since 2016, and the work here is in the systems themselves - hardening infrastructure, closing vulnerabilities, and building the guardrails that keep AI-driven workflows safe in front of real users.
Where this role sits
Most engineering organizations split ownership by what's built: pipelines and data infrastructure, the model or the method behind a decision, the product itself, and - once AI systems are live - what they actually do in front of users. Security isn't one more slice next to those. It's the discipline that has to hold inside every one of them, and on any team large enough to carry a dedicated specialist, this is the role that owns it.
One question places the boundary: when a system is breached, was a control never built, or did someone get past one that existed? The first is an engineering gap, and wherever it sits - infrastructure, pipeline, agent, integration - it's this role's problem to close before someone outside the team finds it. The second is an incident, and this role runs it: containment, root cause, and the fix that keeps it from happening twice.
On engagements built around an embedded delivery model, this role's accountability is distinct from whoever owns delivery of the system itself: they answer for whether it works, this role answers for whether it's safe to run. Same principle either way - no handoff, one shared understanding of what "secure" means, agreed before the work starts rather than reported after.
What you will build
- Platform and infrastructure hardening. Cloud infrastructure, APIs, internal tooling, and CI/CD pipelines: encryption, secrets management, logging, and access controls that are built in, not bolted on, and stay correct as the systems around them change.
- Vulnerability management and offensive security. Scanning, penetration testing, adversarial testing, threat modeling, and manual review across everything Azumo ships into a client's environment - with remediation you drive to closed, not to ticket.
- AI and agent security. Prompt-injection defense, adversarial-input testing, and guardrails for the tool-calling and agentic systems the AI Engineer lane builds - the same production behavior, hardened against misuse rather than measured for accuracy. Bounded, observable, auditable, and safe to fail.
- The standing audit. Azumo runs an automated security, cost, and architecture audit across every client codebase, graded by severity down to the file and line, on day one and every day after. You own it - what it checks, how it's graded, how often it's wrong.
- Monitoring, detection, and incident response. Alerting and detection for what you harden, investigation when something looks wrong, and root cause when it turns out to be something.
- Work inside the client's environment. Their repositories, their tooling, sometimes their compliance review. Azumo is SOC 2 certified, client code stays in client repositories, and some engagements carry additional requirements such as HIPAA.
How we work
Our engineers build with AI every day. Claude Code, Codex, and similar tools are part of the standard toolchain here, not an experiment. The audit you'll own runs across the whole codebase on day one and every day after, grading security, cost, and architecture findings by severity with the exact file and line, so a small team can move quickly without quality drifting. We stay vendor-neutral across OpenAI, Anthropic, and open-weight models, and we run Valkyrie, our own production layer, when a single interface to any model is the right call.
About Azumo
Azumo is a San Francisco based software development company that has been building intelligent applications since 2016. We provide nearshore AI engineering teams to organizations that need production AI faster than they can hire for it: as an embedded engineering team, as AI staff augmentation alongside an existing team, or as a full project build. Our engineers work from Latin America, aligned to United States time zones, and have delivered for Twitter, Meta, Discovery Channel, Omnicom, UnitedHealth, and CENTEGIX.
We hire for seniority and test for it before anyone joins a client team. We support engineers in going deep on the modern AI stack, and we give time back to open-source work, community teaching, and philanthropy.
Apply at azumo.com/join-our-team or write to us at [email protected].
Requirements
Basic qualifications
- 7+ years of hands-on experience in security engineering, infrastructure security, application security, DevSecOps, or offensive security, with the engineering fundamentals to match: testing, code review, CI/CD, Git, containers, and API design.
- Deep, current knowledge of the AWS ecosystem, and the judgment to secure it under production pressure, not just in a lab.
- Demonstrated experience identifying and remediating vulnerabilities in live production systems.
- Experience securing AI or LLM-powered systems or automated agents: prompt injection, adversarial inputs, unauthorized actions, unsafe outputs, and data leakage. This is the requirement we screen hardest on.
- Active use of AI-assisted coding tools such as Claude Code, Cursor, or GitHub Copilot in real delivery work.
- Strong communication skills: the ability to explain a finding to engineers and defend it to a client directly, without a translation layer in between.
- Clear written and spoken English, B2/C1 or above.
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent professional experience.
Preferred qualifications
- Familiarity with prompt-injection attacks, adversarial AI techniques, AI guardrails, and behavioral anomaly detection.
- Cloud security tooling, SIEM and observability platforms, penetration testing tools, endpoint security platforms, and infrastructure-as-code security (Terraform, Bicep, or similar).
- Delivery under a compliance regime such as SOC 2 or HIPAA.
- Prior experience in high-growth startup, fintech, banking, or payments environments.
- Certifications such as CISSP, CISM, AWS Security Specialty, or similar.
- Contributions to open-source security tooling, published technical writing, or active participation in the security community.
Benefits
- 100% remote-first culture (work anywhere in the US or Canada)
- Paid time off (PTO)
- U.S. Holidays
- Solid AI Training and certification
- Mentored career development
- Profit sharing
- $US remuneration

