Senior Security Engineer - Cloud & Platform Security
dLocal • ESWhy should you join dLocal?
dLocal enables the biggest companies in the world to collect payments in 40 countries in
emerging markets. Global brands rely on us to increase conversion rates and simplify
payment expansion effortlessly. As both a payments processor and a merchant of record
where we operate, we make it possible for our merchants to make inroads into the
world’s fastest-growing, emerging markets.
By joining us you will be a part of an amazing global team that makes it all happen, in a
flexible, remote-first dynamic culture with travel, health and learning benefits, among
others. Being a part of dLocal means working with around 1500 teammates from 30+
different nationalities and developing an international career that impacts millions of
people’s daily lives. We are builders, we never run from a challenge, we are customer-
centric, and if this sounds like you, we know you will thrive in our team.
We're not building a traditional security team. We are a lean, forward-thinking
organization that rapidly adopts the latest disruptive innovations to stay ahead of the
curve. We believe the future of defense is smart, efficient, and scaled, and we're
leveraging AI agents and modern platforms to build it (e.g., AI-assisted policy checks,
drift correlation, and AI-driven correlation of posture, CI/CD).
We are looking for a hands-on builder and executor who lives and breathes "secure-by-
default" infrastructure. This isn't just a compliance or audit role; it's a "full-stack"
security engineering position focused on prevention. You'll be an architect, an engineer,
and a key enabler, codifying security into every part of our cloud and CI/CD lifecycle.
In our environment, a small, senior team means massive impact. You won't just write
policies—you'll codify them as automated guardrails, design the hardened platforms our services run on, and build the "paved road" that makes security the easiest and fastest
path for all our engineers. You’ll partner closely with dLocal’s Cloud Platform/SRE teams
to deliver shared guardrails and ‘paved road’ services, not day-to-day platform
operations. This role is focused on prevention and platform engineering.
What You’ll Do:
multi-account AWS architectures, "golden" AMIs, and secure-by-default
container/Kubernetes (EKS) base images.
Infrastructure controls, golden Terraform modules, Helm charts, and admission
policies. You will measure adoption, drift detection, and exception aging while
preventing misconfigurations before they're deployed.
Kubernetes (e.g., admission controllers, least-privilege policies) and own the safe-
change processes for our layered edge defenses (WAF/CDN/anti-Bot), including pre-
prod testing, blast-radius limits, rollback patterns, and change metrics.
WAF) into centralized dashboards and our SIEM/SOAR with clear routing and
ownership, partnering with D&R to ensure signals are high-fidelity and actionable.
and Product teams to translate risks into actionable backlogs. You'll be mentoring
others on prevention-first design.
misconfiguration and drift containment. You will act as the senior subject-matter
expert for cloud/platform incidents, providing deep technical expertise to the IR
team.
What You Bring:
Security, or DevSecOps. You have a passion for building preventative solutions from
the ground up.
IAM boundaries, org SCPs) and expert-level, hands-on knowledge of building and
securing production environments.
baseline hardening (admission control, least privilege, runtime controls). You arefluent in IaC (Terraform, Pulumi, or Ansible) and have strong scripting/automation
skills (Python, Go, etc.).
WAFs, CDNs, and edge security platforms (e.g., Cloudflare, Akamai, AWS WAF).
compliance frameworks (CIS, NIST, OWASP, PCI) into actionable, prioritized
engineering work—not just checkbox-ticking.
engineers, document complex systems clearly, and influence other teams to adopt
security-first practices.
Nice to Have:
AWS WAF).
required.
How You’ll Work
services and "paved roads."
the Detection & Response (D&R) team for signal fidelity and automated containment
handoffs