Stori

Sr Cybersecurity Engineer

Mexico City, Mexico
R
Search for More Jobs Talk to a recruiter now 💪
Description

About Stori

Stori is a fast-growing, venture-backed financial technology company, on a mission to democratize credit access for 400 million underbanked LatAm consumers. Stori currently operates in Mexico and has a global team with offices in Arlington Virginia, Mexico City, and Asia. We have quickly made our mark as one of the top digital banks in Mexico with more than two million applicants for our credit card product since launching.

Stori is one of the top-funded startups in the region with US$250 million raised to date. We are backed by top global venture capital funds, such as GGV Capital, GIC, Lightspeed Venture Partners, General Catalyst, Goodwater Capital, Mexico’s Tresalia Capital, Vision Plus Capital, BAI Capital and Source Code Capital; who have successfully invested in startups such as Affirm, Airbnb, Alibaba, Stripe, and TikTok.

Stori has a standout founder team among fintechs, leveraging 100+ years of accumulated experience in consumer finance, banking and technology across Mastercard, Intel, Capital One, Morgan Stanley, GE Capital, and HSBC in the U.S., Mexico and Asia. The team has launched and managed many multi-million-customer credit card products globally, providing a wide breadth of experience and knowledge to our team.

We welcome diversity of background, experience and thinking. Storians are passionate about our mission and take pride in the products we build. Our culture thrives off of a flat structure and an inclusive environment where all of our employees can be their authentic selves, with boundless opportunities for professional growth.

The Role:

As a Sr Cyber Security Engineer, you will be responsible for safeguarding an organization's computer networks and systems. You will utilize your expertise in cybersecurity principles, practices, and tools to protect sensitive data, prevent unauthorized access, mitigate potential security threats, and monitoring. Your role will involve designing, implementing, and maintaining security measures to ensure the confidentiality, integrity, and availability of information assets.

Main responsibilities:

  1. Identify vulnerabilities and weaknesses that could be exploited by attackers.
  2. Help develop and implement security policies, protocols, and procedures.
  3. Conduct regular security assessments, vulnerability scans, and penetration testing.
  4. Prepare and present reports on security status and incidents to management.
  5. Stay current with the latest security trends, threats, and technology solutions.
  6. Understands, reviews, and interprets vulnerability assessment and scanning results, reduce false positive findings, and act as security advisor to business unit partners.
  7. Creates detailed risk assessment reports which explain identified technical and logical security findings, describes potential business risks, and presents prioritized recommendations.
  8. Develop and maintain documentation for security processes and compliance requirements.
  9. Contributes to the ongoing enhancement of the company's security assessment capabilities through the development and implementation of improved methodology, processes, infrastructure, tools, and deliverables.
  10. Maintains knowledge with current emerging technologies and advancements within Cybersecurity.
  11. Provides expertise and solutions for others as a subject matter expert.
  12. Monitor and enforce guidelines for best practices in security and compliance.
  13. Orchestrate daily compliance requirements and tasks as required.
  14. Review and respond to escalated security events.
  15. Proactively hunting for vulnerabilities and threats within our environment.
  16. Maintain knowledge of adversary tactics, techniques, and procedures (TTP).
  17. Provide timely and relevant updates to appropriate stakeholders and decision makers.
  18. Monitor and analyze security systems to detect and respond to security incidents.
  19. Investigate security breaches and other security-related incidents.

What we are looking for:

  • Experience:
    • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field. 
    • 2-3+ years of hands-on experience with the design, implementation, and operation of enterprise vulnerability management.
    • 2-3+ years experience supporting diverse IT systems, processes, or capabilities in large organizations
    • 2-3+ years of solid understanding of industry best practices for hands on, security vulnerability remediation.
    • 2-3+ years of experience in incident response and/or computer forensics. Extensive experience within an enterprise scale organization; including hands-on experience of complex data centre environments, preferably in the finance or similarly regulated sector 
    • 2-3+ years with SolarWinds (or other, similar tools) running in an enterprise environment.
    • Extensive experience with core vulnerability management scanners (e.g. Qualys, Tenable etc.).
    • Strong knowledge of OWASP Top 10 and the ability to articulate application security risks and determine threat level.
    • Technical understanding of a range of enterprise (on-premise) IT and cloud-based architectures and technologies such as networking, server infrastructure, operating systems, web applications and databases.
  • Skills and attitudes
    • An understanding of mapping and scanning applications and systems, including port scanning, identifying services and configurations, spidering, application flow charting, and session analysis
    • Technical understanding of current cybersecurity threats and trends
    • Knowledge and experience with the Windows and Linux operating systems
    • Ability to correlate data from multiple data sources to create a more accurate picture of cyber threats and vulnerabilities.
    • Ability to research, analyze data, and derive facts.
    • Familiarity with automated tools used to discover system and web application vulnerabilities such as Nessus, Nmap, Qualys, R7 etc.…
    • Knowledge of system and/or web application vulnerabilities and risk assessment methodologies such as Common Vulnerability Scoring System (CVSS) or Open Web Application Security Project (OWASP) Risk Rating Methodology
    • Strong technical skills related to at least one of the following areas: Information Security, Incident Response, Network Security, Windows Security, UNIX/Linux Security, and Web application Security.
    • Able to multitask, prioritize, and resolve multiple inquiries at once.
    • Excellent communication (oral and written), interpersonal, organizational, and presentation skills.
    • Strong work ethic and self-motivation.
    • Ability to work independently, be creative, results-oriented, and adaptable, and have strong written and verbal communication skills.
  • Bonus Points:
    • Preferred certifications: Net+, Security+, OSCP, CEH, CISSP, GIAC (GSEC, GEVA, GPEN etc.)

What we offer

  • Make a positive impact on the lives of our customers via financial inclusion
  • Professional development opportunities 
  • International exposure & work experience
  • Company swag
  • Legally required benefits
Stori
Stori
Apps Financial Services FinTech Information Services Information Technology

0 applies

5 views

Other Jobs from Stori

Sr Backend Engineer Go (Hybrid)

Mexico City, Mexico Remote Hybrid

Data Analytics Engineer Sr

Mexico City, Mexico

Senior Data Scientist

Mexico City, Mexico

Sr Backend Engineer Go/JS (Hybrid)

Mexico City, Mexico Remote Hybrid

Data Scientist Sr Manager (Hybrid)

Mexico City, Mexico Remote Hybrid

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 389 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • Salaries for the engineering jobs on our site range from $100K-$200K. On average, senior engineer positions on our EchoJobs are about $160K.
  • The EchoJobs positions have been sourced and vetted from the top companies to work for in the US as a software engineer, including LinkedIn and other reputable job sites. We also have syndicated jobs from companies that have just raised funding, as well as those that have great unique products and culture. From all of these sources, our founder, Morgan, has also resourced the company's authenticity in terms of their website, public appearance, and more.
  • Yes, our users asked us for just this, so now our search filters allow you to search for your top jobs via location, as well as by onsite, remote, or both. Approximately 30% of our jobs are remote, so you’ve got the best options for you!
  • We have not yet implemented this option, but are considering doing so in the future. For the moment, you would need to cancel your subscription, and resubscribe when you wanted to come back.
  • We add new jobs to EchoJobs every day! We scan our sources for the newest jobs, verify them, and post them to EchoJobs within minutes. We add about 2,000-3,000 new jobs for you each day!
  • From starting your job search to getting hired, the entire job search process can take us software engineers anywhere between 3-6 months. However, at EchoJobs, we’re striving to shorten this duration by finding the best, newest jobs for you, so you can do less job searching, and more applying.
  • We’d recommend checking EchoJobs daily, as we add new jobs to the site each day. Additionally, if you got a chance to read our previous email on “what makes EchoJobs different from any other job search tools,” we also recommended that you set a job alert based on your job filters, so if you get emails on those new jobs, you could be checking more than once per day.
  • If you decide to continue with us after the 1-month trial, we definitely recommend this, as we all know it usually takes 3-6 months to find a quality job as a software engineer these days. So to best support you, we just adjusted our membership options at EchoJobs to monthly, 3 months, or 12 months (this option is more for passive job seekers looking a little bit for the future if they want to come back to work or make a job switch potentially. This lets you see what’s out there in case an even better fit job becomes available.)
  • EchoJobs is truly the only job site of its kind. We want to be THE spot for you to find the best job for you, and haven’t encountered any other company doing this. Other job sites are in niches besides software engineering or focus on a small portion of engineering jobs (like a specific coding language). In the words of Morgan, our founder, “I think what makes EchoJobs different is the amount of jobs, frequency that we add new jobs (we add 2,000-3,000 new jobs daily!), and the powerful search engines to find exactly the job you want more easily and efficiently. We can provide you with the most jobs that are vetted by us, we’ll continually find more new jobs for you, and we make it easier for you to apply and get hired.

What Fellow Engineers Say