CSC Generation - Senior Security Engineer
Requirements
• 5+ years of experience in SecDevOps, Cybersecurity, or related roles • Hands-on, production-level experience with AWS and GCP security configurations • Practical AI experience with tools such as Claude, OpenAI, or similar in production or automation workflows • Demonstrated experience managing Kubernetes and containerized workloads • Demonstrated experience in at least 3 of the following: Identity and Access Management (Azure Entra ID, SSO); service mesh technologies (Istio or similar); GitOps tooling (ArgoCD or similar); Endpoint Detection and Response (EDR) / XDR solutions; OAuth, OIDC, SSO; IaC (Terraform preferred) and Git/GitHub workflows • Solid understanding of networking fundamentals (TCP/IP, DNS, firewalls, VPNs) • Scripting and automation skills (Python, PowerShell, or Bash) • Strong analytical, problem-solving, and communication skills • Security certifications such as CISSP, CISM, AWS Security Specialty, GCP Security Engineer, CKS, SC-200, OSCP, or CEH • Background in compliance frameworks (SOC 2, ISO 27001, PCI-DSS, GDPR) • Experience with workflow-automation platforms such as n8n • Hiring Manager Interview - Conversation with the Information Security Manager focused on your security engineering experience, multi-cloud background, and approach to DevSecOps. • Technical Challenge - A short AI or security-focused challenge so we can understand how you approach problems and execution. • Technical Deep-Dive Interview - Deep-dive interviews with Backcountry engineering and security leadership focused on your hands-on experience across Kubernetes, cloud security, and incident response. • In-Person Interview - We'd like to meet you at our Costa Rica office. Details and logistics will be arranged with your recruiter. • Reference Checks - Conducted in parallel with the final stages where possible. • Offer - We move quickly for the right candidate. • Interview process is subject to change. Any updates will be communicated promptly and clearly.
Responsibilities
• Protect and monitor infrastructure hosted in AWS and GCP; configure and maintain AWS WAF/CDN and GCP Cloud Armor rules; review Infrastructure as Code for security best practices • Secure containerized workloads across EKS and GKE clusters; implement Istio mesh policies (mTLS, authorization, traffic controls); manage GitOps delivery security through ArgoCD (RBAC, secrets, drift detection) • Integrate security into CI/CD pipelines using GitHub Actions; manage dependency and supply-chain risk via Dependabot; collaborate with engineering teams on secure development practices • Administer and secure Azure Entra ID and SSO configurations; enforce least-privilege access across cloud, Kubernetes, and SaaS platforms; conduct periodic access reviews • Manage Microsoft Defender XDR for endpoint and identity security; monitor alerts, investigate incidents, and lead incident response efforts across cloud, Kubernetes, and identity layers • Secure the Microsoft 365 environment (Exchange Online, SharePoint, OneDrive, Teams); implement Data Loss Prevention (DLP) policies and email security controls • Define and enforce secure baselines for Linux and Windows VMs, including patching, configuration management, and vulnerability remediation • Evaluate and govern the secure use of AI tools (Claude, OpenAI) and automation platforms (n8n) across the organization, including data handling, access controls, and leakage risks
Benefits
• The people who do best here are builders. They take ownership, move fast, and want to see the direct impact of their work. • Cross-Functional Impact: Your security decisions will touch every engineering team and cloud platform across the business — from infrastructure and CI/CD to AI adoption governance. • AI-First Skill Building: Get hands-on with advanced AI tools and automation platforms while building the security frameworks that govern their safe use across the organization. • End-to-End Ownership: Own security strategy across a multi-cloud, Kubernetes-native stack — from threat detection and incident response to identity management and policy enforcement. • Competitive Benefits: We offer an attractive benefits package including primarily remote work, private medical and life insurance, additional paid time off, monthly allowances and reimbursements, employee discounts, and opportunities for professional growth.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT