B

Senior Security Engineer

Blossom • Colombia
Remote
Apply
AI Summary

Protect scalable digital products, design security policies, and maintain security compliance. Drive security outcomes through technical expertise and collaboration. Act as top technical security authority.

Key Highlights
Security Strategy & Architecture
Technical Authority & Mentorship
Risk & Incident Management
Key Responsibilities
Implement strategies and define plans around cybersecurity at the Product and Infrastructure layers.
Design and define long-term security architecture across systems, networks, and applications.
Drive secure-by-design principles and influence platform, infrastructure, and software design.
Identify immediate and potential risks, and develop mitigation strategies while continually monitoring and evaluating security measures.
Serve as the top technical security authority, providing deep expertise in areas such as cryptography, authentication, secure coding, and vulnerability management.
Lead security-focused design and code reviews for complex systems.
Provide training and guidance to Directors, Engineering Managers, Technical Leads, Senior Developers, and Mid-level Developers.
Mentor junior and senior security engineers, setting coding and security standards.
Conduct threat modeling for new projects and high-risk services.
Evaluate and prioritize security risks in both development and production environments.
Collaborate with product, infrastructure, and development teams to mitigate identified risks.
Lead investigations of complex security incidents, including root cause analysis and mitigation strategies.
Guide post-incident reviews and ensure systemic improvements are implemented.
Develop and implement automation tools for continuous security monitoring, vulnerability scanning, and compliance enforcement.
Ensure systems comply with regulatory requirements such as PCI-DSS, SOC 2, or ISO 27001.
Work closely with legal and compliance teams to maintain policies and audit-readiness.
Act as a security liaison across engineering, product, operations, and leadership.
Partner with DevOps/SRE teams to secure CI/CD pipelines and infrastructure-as-code.
Promote security culture by leading internal training and awareness campaigns.
Develop documentation and internal playbooks for the Secure Development Lifecycle (SDLC).
Oversee implementation of real-time intrusion detection, SIEM, and anomaly detection systems.
Continuously refine monitoring rules and alerts based on evolving threats.
Stay ahead of emerging threats, vulnerabilities, and mitigations.
Prototype new security techniques, contribute to open source, and represent the company at security conferences when applicable.
Technical Skills Required
Cryptography Authentication Secure Coding
Benefits & Perks
100% Remote work
Compensation in USD
Flexible working hours
Performance-based bonuses
Paid time off (PTO)
Learning & development budget (courses, certifications, events)

Job Description


Join Blossom!

We are a U.S.-based company with over 20 years of experience dedicated to enhancing the satisfaction of credit unions and their members. We are committed to developing simpler and more innovative financial services that assist credit unions in serving their current members and attracting new ones. We are building the next-generation technology layer for credit unions.

www.blossom.net

We're looking for a technically driven and detail-oriented Senior Security Engineer with a strong interest in protecting scalable digital products, who thrives in cross-functional environments and drives security outcomes through deep technical expertise, sound risk judgment, and effective collaboration across product, infrastructure, and engineering teams.

About The Role

We are looking for a senior security professional responsible for designing, implementing, and maintaining security policies and procedures to ensure Security Compliance and protect the company from data loss and cybersecurity risks. This person will act as the top technical security authority, defining cybersecurity strategy at both the Product and Infrastructure layers.

Key Responsibilities

Security Strategy & Architecture

  • Implement strategies and define plans around cybersecurity at the Product and Infrastructure layers.
  • Design and define long-term security architecture across systems, networks, and applications.
  • Align security practices with enterprise-wide IT strategies and business goals.
  • Drive secure-by-design principles and influence platform, infrastructure, and software design.
  • Identify immediate and potential risks, and develop mitigation strategies while continually monitoring and evaluating security measures.

Technical Authority & Mentorship

  • Serve as the top technical security authority, providing deep expertise in areas such as cryptography, authentication, secure coding, and vulnerability management.
  • Lead security-focused design and code reviews for complex systems.
  • Provide training and guidance to Directors, Engineering Managers, Technical Leads, Senior Developers, and Mid-level Developers.
  • Mentor junior and senior security engineers, setting coding and security standards.

Risk & Incident Management

  • Conduct threat modeling for new projects and high-risk services.
  • Evaluate and prioritize security risks in both development and production environments.
  • Collaborate with product, infrastructure, and development teams to mitigate identified risks.
  • Lead investigations of complex security incidents, including root cause analysis and mitigation strategies.
  • Guide post-incident reviews and ensure systemic improvements are implemented.

Automation, Tools & Compliance

  • Develop and implement automation tools for continuous security monitoring, vulnerability scanning, and compliance enforcement.
  • Evaluate and integrate third-party security solutions.
  • Ensure systems comply with regulatory requirements such as PCI-DSS, SOC 2, or ISO 27001.
  • Work closely with legal and compliance teams to maintain policies and audit-readiness.

Cross-functional Collaboration

  • Act as a security liaison across engineering, product, operations, and leadership.
  • Partner with DevOps/SRE teams to secure CI/CD pipelines and infrastructure-as-code.
  • Promote security culture by leading internal training and awareness campaigns.
  • Develop documentation and internal playbooks for the Secure Development Lifecycle (SDLC).

Monitoring & Threat Intelligence

  • Oversee implementation of real-time intrusion detection, SIEM, and anomaly detection systems.
  • Continuously refine monitoring rules and alerts based on evolving threats.
  • Stay ahead of emerging threats, vulnerabilities, and mitigations.
  • Prototype new security techniques, contribute to open source, and represent the company at security conferences when applicable.

Perks

  • 100% Remote work
  • Compensation in USD
  • Flexible working hours (results-oriented, not time-based)
  • Performance-based bonuses
  • Paid time off (PTO)
  • Learning & development budget (courses, certifications, events)
  • Work with international teams and global products
  • High ownership and autonomy in product decisions
  • Opportunity to grow into Lead / Head of Product roles
  • Access to AI tools and innovation-driven environment

Apply Now!

Similar Jobs

Explore other opportunities that match your interests

Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Not Applicable

cloud bridge tech recruitment

United Kingdom
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

cloud bridge

United Kingdom

Senior Manager - Penetration Testing

Cyber Security
•
13h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

lt harper recruitment group

United Kingdom

Subscribe our newsletter

New Things Will Always Update Regularly