SecOps Engineer

Posted 11 Days Ago
Be an Early Applicant
Hiring Remotely in Colombia
Remote
Mid level
Fintech • Financial Services
The Role
Own and operate security controls across endpoints, infrastructure, connectivity, and data protection. Implement XDR, DLP, SASE, MDM, SIEM, and SOAR capabilities; manage endpoint hardening, patching, encryption, and compliance; improve detection and incident response automation; integrate cloud and endpoint logs; and support phishing, impersonation, and brand-abuse response in collaboration with IT and engineering.
Summary Generated by Built In
About Addi

We are a leading financial platform, building the future of payments, shopping, and banking—a world where consumers and merchants can transact effortlessly, grow together and where we create abundance and generate pride in them. Today, we serve over 2 million customers and partner with more than 20,000 merchants, making Addi Colombia’s fastest-growing marketplace.

We provide banking solutions (deposits, payments, unsecured credit) and commerce services (e-commerce, marketing) using state-of-the-art technology, bridging the financial gap for millions and redefining how people experience financial freedom. As the country’s leading Buy Now, Pay Later provider, we have secured regulatory approval to operate as a bank, unlocking even greater opportunities for our customers. In the past year, we have also achieved profitability, reinforcing the strength of our business model and our ability to scale sustainably.

Our mission has earned the trust of world-class investors, including Andreessen Horowitz, Architect Capital, GIC, Goldman Sachs, Greycroft, Monashees, Notable Capital, Quona Capital, Union Square Ventures, Victory Park Capital, and more, who back our vision for the future. With their support, we are not just growing—we are transforming Latin America’s financial ecosystem and shaping the next generation to shop, pay, and bank in Colombia.

But what truly sets us apart is how we build. We are a conscious company, driven by deep experience in scaling technology, services and products, and we live by our values every day.

About the Role

This is where you come in. Below, you’ll find what this role is all about—the impact you’ll drive, the challenges you’ll tackle, and what it takes to thrive at Addi. If you’re ready to be part of something big, keep reading.

What’s the mission you’ll drive

Own the implementation and day-to-day operation of security controls across endpoints, infrastructure, secure connectivity, and data protection, working closely with IT and engineering to detect threats early, respond quickly, and protect Addi’s environment at scale.

What you will do
  • Execute the migration to the selected XDR platform across endpoints and infrastructure, achieving ≥95% endpoint coverage by May 2025, reducing false positives by ≥30%, and supporting a Mean Time to Detect (MTTD) of under 1 hour for high-severity incidents through stable, reliable XDR operations.

  • Implement and operate DLP and SASE controls to secure user access, SaaS usage, and data flows, enforcing DLP policies across ≥90% of managed users and devices, reducing high-risk data exposure events by ≥30%, and ensuring minimal impact to user productivity, with SASE fully deployed by end of April 2025.

  • Deploy and operate a centralized MDM solution to manage and secure corporate endpoints, achieving ≥95% device enrollment by May 2025, enforcing baseline security configurations, and reducing endpoint-related security incidents through consistent policy enforcement.

  • Implement and maintain endpoint security policies including encryption, OS hardening, patching, and access controls, ensuring ≥95% compliance with defined device security baselines and timely remediation of non-compliant devices, with core device control policies completed by end of Q3 2026.

  • Operate and continuously improve SIEM detections and SOAR playbooks for security events across critical platforms, reducing Mean Time to Respond (MTTR) by ≥50%, automating ≥30% of repetitive response actions, and ensuring Google Workspace, AWS, XDR, and MDM logs are fully integrated into SIEM by June 2026.

  • Support brand protection operations by monitoring phishing, impersonation, and brand abuse activity, ensuring ≥70% of confirmed brand abuse cases are detected and remediated within SLAs, and implementing automated takedown workflows to reduce customer impact by end of Q3 2026.

What we’re looking for
  • Proven Experience in Security Operations & Control Implementation

    • Hands-on experience implementing and operating security controls across endpoints, infrastructure, secure connectivity, and data protection in cloud-first environments.

    • At least 3 years of experience working with XDR platforms (e.g., CrowdStrike, Cortex, Sentinel) and MDM solutions (e.g., Google Workspace, JumpCloud, or similar).

    • Demonstrated ability to deploy and operate SASE / Zero Trust, VPN, and DLP solutions, including troubleshooting production control failures.

  • Demonstrates Strong Capability in Detection, Response & Automation

    • Experienced in operating security detections, alerts, and response workflows within SIEM and XDR platforms, including integrations with AWS, Google Workspace, and endpoint tools.

    • Executes incident response actions using defined playbooks and escalates effectively based on severity and impact.

    • Familiar with SOAR concepts and automation of repetitive security operations tasks to improve response efficiency.

  • Possesses Solid Expertise in Endpoint & Device Security Management

    • Proven experience deploying and managing MDM solutions to enforce endpoint security baselines at scale.

    • Strong knowledge of device hardening, encryption, patching, application control, web filtering, and secure access controls.

    • Ability to monitor device compliance and remediate non-compliant endpoints in a timely and efficient manner.

  • Track Record of Operational Excellence & Reliability

    • Demonstrates strong operational discipline, including documentation, monitoring, alert follow-up, and incident tracking.

    • Effectively manages multiple operational priorities while maintaining stability and reliability of security controls.

    • Proactively identifies operational gaps and contributes to continuous improvement of security operations.

  • Experienced in Cross-Functional Collaboration & Communication

    • Works effectively with IT, engineering, and infrastructure teams to deploy, operate, and improve security controls.

    • Communicates incidents, operational issues, and risks clearly and concisely to both technical and non-technical stakeholders.

    • Follows established processes while providing constructive feedback to improve tooling, workflows, and controls.

Why join us?
  • Work on a problem that truly matters – We are redefining how people shop, pay, and bank in Colombia, breaking down financial barriers and empowering millions. Your work will directly impact customers' lives by creating more accessible, seamless, and fair financial services.

  • Be part of something big from the ground up – This is your chance to help shape a company, influencing everything from our technology and strategy to our culture and values. You won’t just be an employee—you’ll be an owner

  • Unparalleled growth opportunity – The market we’re tackling is massive, and we’re growing faster than almost any fintech lender at our stage. If you’re looking for a high-impact role in a company that’s scaling fast, this is it.

  • Join a world-class team – Work alongside top-tier talent from around the world, in an environment where excellence, ownership, and collaboration are at the core of everything we do. We care deeply about what we build and how we build it—and we want you to be a part of it.

  • Competitive compensation & meaningful ownership – We believe in rewarding our talent. You’ll receive a generous salary, equity in the company, and benefits that go beyond the basics to support your growth.

How the hiring process looks like

We believe in a fast, transparent, and engaging hiring experience that allows both you and us to determine if there's a great fit. Here’s what our process looks like:

  • Step 1: People Interview (30 min)
    A conversation with a recruiter or hiring manager to get to know you, your experience, and what you're looking for. We’ll also share more about Addi, our culture, and the role.

  • Step 2: Initial Interview (60 min)
    A more in-depth conversation with our Head of Cybersecurity, where we explore your skills, experience, and problem-solving approach. We want to understand how you think and work.

  • Step 3: Deep Dive Interview (60 min)
    You'll meet future colleagues and cross-functional team members to get a feel for how we work together. We’re looking for strong contributors and cultural fits, so bring your questions, too!

  • Step 4: Case Study (3-5 Days)
    You may receive a real-world challenge or case study to complete. This is a chance to showcase your expertise and how you approach key problems relevant to the role.

  • Step 5: Co-Founder Interview
    If there’s a strong match, you’ll have a final conversation with our Founder to align on expectations, cultural fit and ensure mutual excitement. From there, we’ll move quickly to an offer and discuss next steps.


We value efficiency and respect for your time, so we aim to complete the process as quickly as possible. Our goal is to make this experience insightful and exciting for you, just as much as it is for us. Regardless of the outcome, we are committed to always providing feedback, ensuring that you walk away with valuable insights from your experience with us.

Skills Required

  • Hands-on experience implementing and operating security controls across endpoints, infrastructure, secure connectivity, and data protection in cloud-first environments.
  • At least 3 years of experience working with XDR platforms such as CrowdStrike, Cortex, or Sentinel and MDM solutions such as Google Workspace, JumpCloud, or similar.
  • Experience deploying and operating SASE, Zero Trust, VPN, and DLP solutions, including troubleshooting production control failures.
  • Experience operating security detections, alerts, and response workflows in SIEM and XDR platforms, including AWS, Google Workspace, and endpoint integrations.
  • Experience executing incident response actions using defined playbooks and escalating based on severity and impact.
  • Familiarity with SOAR concepts and automation of repetitive security operations tasks.
  • Experience deploying and managing MDM solutions to enforce endpoint security baselines at scale.
  • Strong knowledge of device hardening, encryption, patching, application control, web filtering, and secure access controls.
  • Ability to monitor device compliance and remediate non-compliant endpoints efficiently.
  • Strong operational discipline, including documentation, monitoring, alert follow-up, and incident tracking.
  • Ability to manage multiple operational priorities while maintaining security-control stability and reliability.
  • Ability to identify operational gaps and contribute to continuous security operations improvement.
  • Ability to collaborate effectively with IT, engineering, and infrastructure teams.
  • Ability to communicate incidents, operational issues, and risks clearly to technical and non-technical stakeholders.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Bogotá
589 Employees
Year Founded: 2018

What We Do

Addi is a technology company that seeks to promote and enable digital commerce in Latin America. At Addi we want people to buy what they want, when they want, easily, quickly and transparently. As it should be.

Similar Jobs

Coupa Logo Coupa

Enterprise Architect

Artificial Intelligence • Fintech • Information Technology • Logistics • Payments • Business Intelligence • Generative AI
In-Office or Remote
Bogotá, Bogotá, D.C., COL
3000 Employees

Cloudflare Logo Cloudflare

Senior Customer Engineer, LATAM - MCR Bogotá, Colombia.

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
Colombia
4400 Employees

Shield AI Logo Shield AI

District Manager, LATAM

Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
In-Office or Remote
2 Locations

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sr. Sales Associate III

eCommerce • Fashion • Retail • Sales • Wearables • Design
Remote or Hybrid
14 Locations
16000 Employees
15-20 Hourly

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account