
Real job — pulled straight from Marathon Talent’s careers page · Verified August 9, 2026 · No reposts.
Job description
Marathon Talent is hiring a Applications Security Specialist — a full-time, based in Argentina role. Apply directly on Marathon Talent's careers page below.
Applications Security Specialist
Location: Argentina
Department: Financial Services
Workplace: remote
Description
Who we are
At R2, we believe that small and medium businesses are the productive engine of society. Small and medium businesses (SMBs) make up over 90% of companies in Latin America, yet they face a trillion-dollar credit gap. Our mission is to unlock SMBs’ potential by providing financial solutions that are tailored to their needs. We are reimagining the financial infrastructure of Latin America, where SMBs financial needs are satisfied without ever having to go to a bank.
R2 enables platforms in Latin America to embed financial services that SMBs can then leverage (starting with revenue-based financing). We are a tight-knit team coming from organizations such as Google, Amazon, Nubank, Uber, Capital One, Mercado Libre, Globant, and J.P. Morgan. We are entering a new phase of growth following a strategic investment from Ant International, with a focus on rapidly expanding our partner footprint, strengthening our credit and underwriting capabilities, and scaling our operations across multiple markets.
As an Application Security Engineer, you will ensure the operational efficiency of our IT systems and support the security posture of a growing fintech company. You’ll report to the Director of Infrastructure and work closely with our DevOps and Software Development teams. We’re looking for someone proactive, detail-oriented, and passionate about technology.
What you’ll work on
- Application Development & Code
- Conduct secure code reviews for Go-based microservices and identify vulnerabilities early in the development cycle.
- Perform security testing of APIs, web applications, and backend services before they reach production.
- Establish and evolve secure coding standards, guardrails, and reusable patterns for engineering teams.
- Lead threat modeling sessions with engineering and product teams at the design phase of new features and services.
- CI/CD & Pipeline Security
- Define and enforce security gates in CI/CD pipelines: SAST, DAST, SCA, and secrets scanning with blocking criteria for high-severity findings.
- Own the DAST process end-to-end: tool selection, scheduling, escalation workflows, and remediation tracking.
- Integrate container image scanning and infrastructure-as-code (IaC) security checks into deployment pipelines.
- Hardening & Observability
- Support hardening initiatives across Kubernetes, ingress, and workloads.
- Contribute to the security observability program by defining and tuning alerting rules for authentication anomalies and suspicious API usage.
- Drive the adoption of secure development across engineering teams by providing guidance, training, and hands-on support.
- Build and maintain security documentation, runbooks, and standards
- Vulnerability & Risk Management
- Triage, prioritize, and track remediation of security findings across the platform.
- Coordinate external penetration tests and work with vendors on scope, debriefs, and remediation plans.
- Sit with product and business teams to understand risk from a product perspective.
- Ensure there are no open high-severity findings older than 30 days.
Requirements
Who you are:
- 3–5 years of experience in application security, product security, or a similar role.
- Hands-on experience with SAST/DAST tools (Snyk, Checkmarx, OWASP ZAP, Burp Suite, or equivalent).
- Solid knowledge of OWASP Top 10 for web and APIs and real-world exploitability assessment
- Experience reviewing code in Go or similar compiled languages.
- Familiarity with Kubernetes, containers, and cloud-native architectures.
- Strong written and verbal communication, able to explain security risks clearly to both engineers and non-technical stakeholders.
- Self-driven and comfortable working with autonomy in a fast-paced environment.
- English proficiency — written and spoken (required).
Nice to have
- Certifications such as OSCP, OSWE, CEH or eWPT.
- Experience with Istio or service mesh security.
- Familiarity with compliance frameworks such as ISO 27001, GDPR, or SOC 2.
- Threat modeling experience (STRIDE, PASTA, or similar).
- Experience in fintech or regulated environments.
Benefits
What We Offer
- The chance to join a high-impact, mission-driven fintech with regional scale
- Cross-functional collaboration with exceptional teams across Latin America
- Equipment provided by R2
- Training budget for professional development
- Career growth within R2
Get Applications Security Specialist jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs
Frequently asked questions
What skills are required for Applications Security Specialist at Marathon Talent?
The required skills for Applications Security Specialist at Marathon Talent include: Go, Kubernetes, Docker, ISO 27001, GDPR, SOC 2.
What is the seniority level for Applications Security Specialist at Marathon Talent?
Applications Security Specialist at Marathon Talent is a Mid Level level position.
How do I apply for Applications Security Specialist at Marathon Talent?
You can view the full description and apply for Applications Security Specialist at Marathon Talent on EchoJobs: https://echojobs.io/job/marathon-talent-applications-security-specialist-rfsg8.



