Lead Security Engineer
Cloud SecurityIdentity and Access Management (IAM)application securityVulnerability ManagementSOC 2PCI DSSGDPRAWSRisk ManagementSecurity Architecture
About the Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead Security Engineer based in Mexico. As Lead Security Engineer, you will lead a small security team while owning the organization’s security and compliance program end to end. You will shape security strategy across a global SaaS platform handling sensitive guest and payment data at significant scale. The role combines people leadership with hands-on technical ownership across cloud security, identity and access management, application security, and vulnerability management. You will also oversee compliance frameworks, audits, policies, third-party risk, and security awareness initiatives. As the primary security point of contact, you will communicate with customers, partners, auditors, and executive stakeholders. This player-coach opportunity is ideal for a security leader who can balance technical depth, pragmatic risk management, and strong business communication. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead Security Engineer based in Mexico. As Lead Security Engineer, you will lead a small security team while owning the organization’s security and compliance program end to end. You will shape security strategy across a global SaaS platform handling sensitive guest and payment data at significant scale. The role combines people leadership with hands-on technical ownership across cloud security, identity and access management, application security, and vulnerability management. You will also oversee compliance frameworks, audits, policies, third-party risk, and security awareness initiatives. As the primary security point of contact, you will communicate with customers, partners, auditors, and executive stakeholders. This player-coach opportunity is ideal for a security leader who can balance technical depth, pragmatic risk management, and strong business communication. Accountabilities: Lead, coach, and develop a team of security engineers, including hiring, performance management, prioritization, and career development. Own the security and compliance program end to end, including SOC 2, PCI DSS, GDPR/CCPA, and other applicable security and privacy frameworks. Establish, maintain, and continuously improve the organization’s security control framework, policies, standards, and overall risk posture. Serve as the primary security point of contact for customers, partners, auditors, and internal stakeholders. Communicate the organization’s security posture effectively to audiences ranging from customer CISOs and security teams to executive leadership. Manage vendor and third-party security risk, including evaluating security practices and requirements. Review security terms and requirements within customer and vendor contracts. Develop, maintain, and communicate security policies and standards across the organization. Lead security awareness and training initiatives to strengthen security practices company-wide. Set the technical direction for security tooling and capabilities. Remain hands-on with security architecture assessments, threat modeling, and technical reviews alongside engineering teams. Help build and maintain a pragmatic, risk-based security program that supports a rapidly growing SaaS environment. Requirements: 8+ years of experience in security engineering or a closely related security discipline. 2+ years of experience leading a security team as a manager or technical lead. Demonstrated experience owning compliance programs end to end, with expertise in frameworks such as SOC 2 Type II, PCI DSS, ISO 27001, or similar. Strong hands-on technical foundation in cloud security, particularly AWS. Strong knowledge of identity and access management, application security, and vulnerability management. Experience with vendor and third-party risk management. Experience reviewing security requirements and contractual security terms with customers and vendors. Proven ability to build pragmatic, risk-based security programs within a growth-stage SaaS organization. Exceptional written and verbal communication skills, with the ability to translate technical security concepts for both technical and executive audiences. Strong leadership, coaching, prioritization, and stakeholder-management skills. Ability to balance strategic security leadership with hands-on technical execution. Strong judgment and ability to assess security risks in the context of business objectives. Experience in hospitality, fintech, or payments is a plus. CISSP, CISM, or CISA certification is a plus. Benefits: Unlimited paid time off to support rest and recharge. Standard holidays plus monthly company-wide Canary Days for additional long weekends. Dedicated birthday holiday. Travel stipend for visiting team members at hubs in San Francisco, New York, or Dallas. Credit toward stays at participating hotels through the hotel experience program. Minimum 30% discount on the best available rates at select partner hotels globally. Monthly Self Improvement Club budget to support personal goals. Dedicated professional development and learning stipend. Referral program with cash bonuses for successful hires. Opportunity to work in a fast-growing technology environment focused on AI, security, and global hospitality infrastructure. Equal opportunity employment environment. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
You'll be redirected to Jobgether's application page
Job Details
Salary
Not disclosed
Location
Mexico
Job type
Full-time
Category
Security Engineering
Experience
8+ years
Posted
Today
Job Highlights
- 8+ years level role
- 100% Remote — open to candidates in Brazil, Mexico, United States
- Full-time position
About Jobgether
This job is hosted by Jobgether. Clicking Apply opens their site.
Remote Work Style
Mixed
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.