SecOps Engineer
Addi · Colombia · Remoto
Es un puesto remoto: contratan desde Colombia.
El aviso no publica el sueldo.
Lo publica Addi y está vigente desde el 4 de septiembre de 2026.
Toca Postularme y entra con tu cuenta de Google: te llevamos al aviso en Ashby y te ayudamos a armar el CV para este puesto.
PostularmeDescripción del puesto
ABOUT ADDI
We are a leading financial platform, building the future of payments, shopping, and banking—a world where consumers and merchants can transact effortlessly and grow together. Today, we serve over 3.6 million customers and partner with more than 55,000 merchants, making Addi Colombia’s fastest-growing marketplace.
With a state-of-the-art, technology-first approach, we provide banking solutions (deposits, payments, unsecured credit) and commerce services (e-commerce, marketing), bridging the financial gap for millions and redefining how people experience financial freedom. As the country’s leading Buy Now, Pay Later provider, we have secured regulatory approval to operate as a bank, unlocking even greater opportunities for our customers. In the past year, we have also achieved profitability, reinforcing the strength of our business model and our ability to scale sustainably.
Our mission has earned the trust of world-class investors, including Andreessen Horowitz, Architect Capital, GIC, Goldman Sachs, Greycroft, Monashees, Notable Capital, Quona Capital, Union Square Ventures, Victory Park Capital, and more, who back our vision for the future. With their support, we are not just growing—we are transforming Latin America’s financial ecosystem and shaping the next generation to shop, pay, and bank in Colombia.
But what truly sets us apart is how we build. We are a conscious company, driven by deep experience in scaling technology, services and products, and we live by our values https://co.addi.com/trabaja-con-nosotros#:~:text=%E2%80%A2%20We%20are%20owners,dentro%20del%20equipo. every day.
ABOUT THE ROLE
This is where you come in. Below, you’ll find what this role is all about—the impact you’ll drive, the challenges you’ll tackle, and what it takes to thrive at Addi. If you’re ready to be part of something big, keep reading.
WHAT’S THE MISSION YOU’LL DRIVE
Own the implementation and day-to-day operation of security controls across endpoints, infrastructure, secure connectivity, and data protection, working closely with IT and engineering to detect threats early, respond quickly, and protect Addi’s environment at scale.
WHAT YOU WILL DO
- Execute the migration to the selected XDR platform across endpoints and infrastructure, achieving ≥95% endpoint coverage by May 2025, reducing false positives by ≥30%, and supporting a Mean Time to Detect (MTTD) of under 1 hour for high-severity incidents through stable, reliable XDR operations.
- Implement and operate DLP and SASE controls to secure user access, SaaS usage, and data flows, enforcing DLP policies across ≥90% of managed users and devices, reducing high-risk data exposure events by ≥30%, and ensuring minimal impact to user productivity, with SASE fully deployed by end of April 2025.
- Deploy and operate a centralized MDM solution to manage and secure corporate endpoints, achieving ≥95% device enrollment by May 2025, enforcing baseline security configurations, and reducing endpoint-related security incidents through consistent policy enforcement.
- Implement and maintain endpoint security policies including encryption, OS hardening, patching, and access controls, ensuring ≥95% compliance with defined device security baselines and timely remediation of non-compliant devices, with core device control policies completed by end of Q3 2026.
- Operate and continuously improve SIEM detections and SOAR playbooks for security events across critical platforms, reducing Mean Time to Respond (MTTR) by ≥50%, automating ≥30% of repetitive response actions, and ensuring Google Workspace, AWS, XDR, and MDM logs are fully integrated into SIEM by June 2026.
- Support brand protection operations by monitoring phishing, impersonation, and brand abuse activity, ensuring ≥70% of confirmed brand abuse cases are detected and remediated within SLAs, and implementing automated takedown workflows to reduce customer impact by end of Q3 2026.
WHAT WE’RE LOOKING FOR
- Pro
Toca Postularme y entra con tu cuenta de Google: te llevamos al aviso en Ashby y te ayudamos a armar el CV para este puesto.
PostularmeAvisos parecidos
Preguntas frecuentes
¿Es remoto el puesto de SecOps Engineer?
Es un puesto remoto: contratan desde Colombia.
¿Cuánto paga?
El aviso no publica el sueldo.
¿Dónde se publicó este aviso?
En Ashby. DameTrabajo lo encontró ahí y te lleva a postularte en el aviso original.