Azumo
Senior Security Engineer
Remote role where the employee must remain based in a particular country.
Argentina only
Employer listed it yesterday · Added today
First listed yesterday.
Salary
Not stated
Location
Argentina only
Timezone
Not stated
Contract
Full-time
Experience
Senior
Category
Software
This employer didn't state pay. Jobs like this usually pay around $170k–$225k a year, a typical range taken from 597 senior-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Work from home
This is a remote role, but the employee must be based in Argentina. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Buenos Aires, Argentina, Buenos Aires, Argentina, Buenos Aires, Buenos Aires, Argentina, Remote"
What Nomaders makes of it
- Residency required in Argentina
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Senior Security Engineer
Azumo builds and operates production AI systems for companies ranging from seed-stage startups to Meta. We are hiring a Senior Security Engineer to own the technical security posture of those systems once they are live: the infrastructure they run on, the pipelines that feed them, and the agents that act on their output. The role is fully remote across Latin America, aligned to your client's working day.
This is not an audit seat. Azumo has shipped production AI since 2016, and the work here is in the systems themselves — hardening infrastructure, closing vulnerabilities, and building the guardrails that keep AI-driven workflows safe in front of real users.
Where this role sits
At Azumo, ownership is split by what gets built: the pipelines, the method behind a decision, the product, and what an AI system does once it's live. Security doesn't work that way. It has to be right across all of them, and that's what this role owns.
Gap or breach, it's yours. If there's a gap, you find it and close it before anyone outside the team does. If there's a breach, you run it: containment, root cause, and the fix that keeps it from happening twice.
Whoever builds the system answers for whether it works. You answer for whether it's safe to run. That split is agreed before the work starts, not reported after.
What you will build
Platform and infrastructure hardening: Cloud infrastructure, APIs, internal tooling, and CI/CD pipelines: encryption, secrets management, logging, and access controls that are built in, not bolted on, and stay correct as the systems around them change.
Vulnerability management and offensive security: Scanning, penetration testing, adversarial testing, threat modeling, and manual review across everything Azumo ships into a client's environment — with remediation you drive to closed, not to ticket.
AI and agent security: Prompt-injection defense, adversarial-input testing, and guardrails for the tool-calling and agentic systems the AI Engineer lane builds. Untrusted input arrives from IVR and voice channels, web systems, APIs and people, and what handles it stays bounded, observable and safe to fail.
Watching what the agents do: Monitoring AI systems in production for anomalies, abuse attempts and unsafe decisions — the same production behavior the AI Engineer lane measures for accuracy, watched here for misuse.
The standing audit: Azumo runs an automated security, cost, and architecture audit across every client codebase, graded by severity down to the file and line, on day one and every day after. You own it — what it checks, how it's graded, how often it's wrong.
Monitoring, detection, and incident response: Alerting and detection for what you harden, investigation when something looks wrong, and root cause when it turns out to be something. You lead the response itself: containment, the remediation plan, and the preventative change that follows, with operational visibility into access patterns and security events maintained rather than reconstructed after the fact.
Customer and partner security engagement: Security questionnaires, vendor risk assessments, and enterprise RFPs, plus the technical questions that come directly from a client's bank, auditor or enterprise prospect. You explain the architecture, the controls and what is monitored, and you defend the answer without a translation layer in between.
Secure development practices: Working with the engineering teams on how they build, not only on what they ship: architecture reviews, secure patterns, and the trade-off between security, reliability and delivery speed argued in the room with Product, Compliance and Operations rather than raised afterwards.
Work inside the client's environment: Their repositories, their tooling, sometimes their compliance review. Azumo is SOC 2 certified, client code stays in client repositories, and some engagements carry additional requirements such as HIPAA.
How we work
Our engineers build with AI every day. Claude Code, Codex, and similar tools are part of the standard toolchain here, not an experiment. The audit you'll own runs across the whole codebase on day one and every day after, grading security, cost, and architecture findings by severity with the exact file and line, so a small team can move quickly without quality drifting. We stay vendor-neutral across OpenAI, Anthropic, and open-weight models, and we run Valkyrie, our own production layer, when a single interface to any model is the right call.
About Azumo
Azumo is a San Francisco based software development company that has been building intelligent applications since 2016. We provide nearshore AI engineering teams to organizations that need production AI faster than they can hire for it: as an embedded engineering team, as AI staff augmentation alongside an existing team, or as a full project build.
Our engineers work from Latin America, aligned to United States time zones, and have delivered for Twitter, Meta, Discovery Channel, Omnicom, UnitedHealth, and CENTEGIX.
We hire for seniority and test for it before anyone joins a client team. We support engineers in going deep on the modern AI stack, and we give time back to open-source work, community teaching, and philanthropy.
Apply at https://azumo.com/join-our-team or write to us at people@azumo.com .
Requirements
- ·Basic qualifications
- ·Deep, current knowledge of the AWS ecosystem, and the judgment to secure it under production pressure, not just in a lab.
- ·Demonstrated experience identifying and remediating vulnerabilities in live production systems.
- ·Experience securing AI or LLM-powered systems or automated agents: prompt injection, adversarial inputs, unauthorized actions, unsafe outputs, and data leakage. This is the requirement we screen hardest on.
- ·Self-directed prioritization. You decide what gets fixed first in a fast-moving environment, and you can explain why.
Benefits
- ·100% remote-firste culture (work anywhere in Latin America)
- ·Paid time off (PTO)
- ·Solid AI Training and certification
- ·Mentored career development
- ·$US remuneration
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Azumo, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 15h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $170k to $225k per year · You'll be taken to the employer's careers page.