Colombia
Posted 11 hours ago
Job title: Senior Full Stack Engineer
Work Location: Colombia
Experience: 6–8 years
Education Qualification: High School
Roles and Responsibilities:
- Risk Identification: Identify and prioritize meaningful security risks across first-party code, services, infrastructure, build pipelines, and software supply chain components.
- Vulnerability Validation: Validate findings for exploitability, severity, affected products, business impact, and remediation priority.
- Cross-Functional Collaboration: Collaborate with Security Research and Product teams to translate novel findings, malicious component discoveries, and emerging attack patterns into research-ready outputs, product improvements, detection opportunities, and customer-facing intelligence.
- Remediation & Mitigation: Work closely with Application Security and Engineering to move validated findings through remediation and reduce repeat vulnerability patterns.
- AI-SDLC Evangelism: Champion modern AI-SDLC practices by translating recurring vulnerability classes, insecure coding patterns, and effective remediation approaches into reusable guidance, detection logic, secure coding standards, and remediation playbooks.
- Fix Implementation: Create clear remediation guidance, engineering-ready fix proposals, and pull requests where appropriate.
Required Skills & Desired Skills
- Experience: 8+ years of professional software engineering experience, including 2+ years in a Staff Engineer or equivalent technical leadership role.
- Security Expertise: Proven experience identifying, validating, and helping remediate vulnerabilities in production software, services, APIs, infrastructure, or software supply chain components.
- Code Proficiency: Strong ability to read, understand, and reason about complex codebases, preferably including Java, Kotlin, or other JVM-based backend systems.
- Tooling & Methods: Hands-on experience with application security testing methods and tools, such as SAST, DAST, SCA, secret scanning, threat modeling, secure code review, or vulnerability validation.
- AI & Automation: Practical experience using AI-assisted engineering, security analysis, or automation techniques to improve software quality outcomes.
- Communication: Ability to translate security findings into clear remediation guidance, engineering-ready recommendations, and practical risk-based priorities. Strong collaboration skills working across AppSec, Engineering, Product, or Security Research teams.
- Education: Bachelor’s degree in Computer Science, Engineering, or a related field—or equivalent practical experience.
- DevOps Culture: Solid understanding of cloud-native architecture, CI/CD workflows, build pipelines, containers, and modern DevOps practices.
- Leadership: Passion for raising the security bar through technical leadership, mentoring, secure engineering practices, and continuous improvement.
- Advanced English (B2+)
Desirable Certifications:
- SANS: GSEC, GCIH, GCLD, GCID, GMON
- (ISC)²: CISSP, CC, SSCP, CCSP, CAP, CSSLP
| Job Level | 6 – 10+ Years |

