Senior Cybersecurity Engineer at CodeRoad
—
Jul 27, 2026
—
Jul 29, 2026
What this job asks for AI summary
A senior-level security engineering role at a nearshore software services firm, responsible for designing and operating cloud security architectures, threat-detection pipelines, and incident response programs across multi-cloud environments. The position also involves embedding DevSecOps practices into CI/CD workflows, conducting vulnerability assessments and penetration testing, and ensuring compliance with frameworks such as ISO 27001, SOC 2, and GDPR. Suited to a hands-on security engineer comfortable owning both architecture and operations.
Senior level · 5+ years · Remote
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 2,500 people nationally plausibly meet what this posting asks for (information security analysts). range 1,500–4,500
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 29, 2026. It is a model, not a headcount.
Why we read it this way (8)
The role is based in Latin America and is fully remote; it is not a US-based position, so US labor-market benchmarks will not apply directly.
Compensation is described only as 'competitive USD' with no figures given.
The SOC classification is Medium confidence: the role blends security analysis/operations (15-1212) with substantial security engineering and automation work that overlaps with software development (15-1252). The primary day-to-day emphasis on threat detection, incident response, vulnerability management, and compliance tilts toward 15-1212.
AWS, Azure, and GCP are listed as 'or' alternatives in the requirements; AWS is used as the primary name with Azure and GCP in alternatives.
Python, Bash, and Go are listed as interchangeable scripting options; Python is the primary with the others in alternatives.
SAST, DAST, and IAST are listed together as a single security-testing requirement; SAST is the primary with DAST and IAST in alternatives.
XDR and EDR appear together as a paired platform type; XDR is primary with EDR as an alternative.
Security certifications (CISSP, CISM, CCSP, CEH) and IaC/container tools (Terraform, Checkov, Trivy, Docker, Kubernetes, K3s) all appear under the 'Nice to Have' section.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.