Search...

Lead Security Engineer

ARQ ( Prev DolarApp ) logo
ARQ ( Prev DolarApp )

ARQ is a financial services platform that lets users in Latin America hold global currencies, make cross-border payments, invest in international markets, and spend worldwide with a card.

Darwin 74, Interior 301, Colonia Anzures, Alcaldía Miguel Hidalgo, C.P. 11590, Ciudad de México, Mexico
About ARQ ( Prev DolarApp )

ARQ serves travelers, investors, and professionals across Latin America who need access to global currencies and financial markets. Users can hold digital dollars and euros, receive and send international payments via dedicated US and European account details, invest in US stocks and ETFs, and spend globally with a card at market conversion rates. The platform is available across Mexico, Argentina, Colombia, and Brazil.

View jobs by ARQ ( Prev DolarApp )

Skills

About the Role

You will establish and mature security practices across application security, security operations, and governance, risk, and compliance. You will define application, cloud, AI, detection, incident-response, and vendor-security approaches; conduct assessments; handle complex reviews; and mentor engineers without formal people-management responsibility.

Requirements

  • 7+ years of information security experience, including building or substantially maturing a security function or program
  • 2+ years of experience at a regulated fintech, bank, or payment company
  • Hands-on cloud infrastructure security expertise in AWS and Kubernetes
  • Experience driving application security programs, including threat modelling, secure code review, CI/CD hardening, and API security testing
  • Ability to define security guardrails for AI and agentic tooling, including LLM integrations, MCP servers, and automated workflows
  • Detection engineering experience, including designing detection strategy and mentoring others in rule writing
  • Experience with endpoint security tooling, identity and access management architecture, Google Workspace, Okta, Cloudflare Access, SSO, and SCIM
  • Experience designing or significantly evolving vendor security assessment or third-party due diligence programs
  • Written and verbal communication skills for representing security decisions to leadership and cross-functional stakeholders
  • Business-fluent English

Responsibilities

  • Drive the application security roadmap, including threat modelling, secure code review, API security testing, and security pipeline architecture
  • Define security guardrails for AI and agentic workflows, including prompts, destructive actions, and data exposure
  • Set technical direction for detection engineering, alert pipelines, and automated response across the security stack
  • Own incident response readiness by designing playbooks, leading tabletop exercises, and acting as technical lead during major incidents
  • Set standards for cloud security assessments across AWS and Kubernetes
  • Own and improve the vendor security assessment and third-party due diligence framework
  • Mentor mid-level and senior engineers by reviewing detection logic, assessments, and playbooks

Benefits

  • Stock options
  • Discretionary performance bonus