Logo for R2 Companies

Application Security Engineer (LatAm Only)

Role overview

Qualifications

  • 3–5 years of experience in application security, product security, or a similar role.
  • Hands-on experience with SAST/DAST tools (Snyk, Checkmarx, OWASP ZAP, Burp Suite, or equivalent).
  • Solid knowledge of OWASP Top 10 for web and APIs and real-world exploitability assessment.
  • English proficiency — written and spoken (required).

Responsibilities

  • Conduct secure code reviews for Go-based microservices and identify vulnerabilities early in the development cycle.
  • Perform security testing of APIs, web applications, and backend services before they reach production.
  • Establish and evolve secure coding standards, guardrails, and reusable patterns for engineering teams.
  • Lead threat modeling sessions with engineering and product teams at the design phase of new features and services.

About the company

R2 Companies logo

R2 Companies

The R2 platform is designed to programmatically manage the real estate investment process from end-to-end: R2 casts a wide net to originate and underwrite the very best investment opportunities, act decisively when an attractive risk-adjusted investment presents itself, and execute a disciplined plan to create sustainable value. R2 is an opportunistic firm that invests its own capital alongside a select group of institutional partners, making it an active and highly vested manager and operator. R2 currently owns and operates more than 6 million square feet of commercial real estate in Chicago, Austin, Nashville, Minneapolis & Milwaukee and has a multi-year track record of realizing superior risk-adjusted returns utilizing various investment strategies across market cycles. The R2 platform is designed to be nimble, able to quickly and deftly shift strategies and allocations in response to changing market conditions. The R2 team is a group of knowledgeable and motivated principals with experience in acquisitions, capital markets, development, leasing, and asset, property, and construction management. With this array of core competencies, R2 can directly control the success variables in any given investment. For more information, visit R2.me.

Company details

Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

At R2, we believe that small and medium businesses are the productive engine of society. Small and medium businesses (SMBs) make up over 90% of companies in Latin America, yet they face a trillion-dollar credit gap. Our mission is to unlock SMBs’ potential by providing financial solutions tailored to their needs. We are reimagining the financial infrastructure of Latin America, where SMBs’ financial needs are met without ever having to go to a bank.


R2 enables platforms across Latin America to embed financial services that SMBs can leverage, starting with revenue-based financing. We are a high-performing, close-knit team with talent from organizations such as Google, Amazon, Nubank, Uber, Capital One, Mercado Libre, Globant, and J.P. Morgan. 


We are entering a new phase of growth following a strategic investment from Ant International, focused on rapidly expanding our partner footprint, strengthening our credit and underwriting capabilities, and scaling operations across multiple markets. As part of this growth journey, eligible team members have the opportunity to participate in R2’s Phantom Share Program, a performance-based incentive designed to align our team with the company’s long-term success and value creation. We believe in building a culture of ownership, where those who help create value share meaningfully in it.


As an Application Security Engineer (IC3), you will ensure the operational efficiency of our IT systems and support the security posture of a growing fintech company. You’ll report to the Director of Infrastructure and work closely with our DevOps and Software Development teams. We’re looking for someone proactive, detail-oriented, and passionate about technology.


What You'll Do:



  • Conduct secure code reviews for Go-based microservices and identify vulnerabilities early in the development cycle.
  • Perform security testing of APIs, web applications, and backend services before they reach production.
  • Establish and evolve secure coding standards, guardrails, and reusable patterns for engineering teams.
  • Lead threat modeling sessions with engineering and product teams at the design phase of new features and services.
  • Define and enforce security gates in CI/CD pipelines:  SAST, DAST, SCA, and secrets scanning with blocking criteria for high-severity findings.
  • Own the DAST process end-to-end: tool selection, scheduling, escalation workflows, and remediation tracking.
  • Integrate container image scanning and infrastructure-as-code (IaC) security checks into deployment pipelines.
  • Support hardening initiatives across Kubernetes, ingress, and workloads.
  • Contribute to the security observability program by defining and tuning alerting rules for authentication anomalies and suspicious API usage.
  • Drive the adoption of secure development across engineering teams by providing guidance, training, and hands-on support.
  • Build and maintain security documentation, runbooks, and standards
  • Triage, prioritize, and track remediation of security findings across the platform.
  • Coordinate external penetration tests and work with vendors on scope, debriefs, and remediation plans.
  • Sit with product and business teams to understand risk from a product perspective.
  • Ensure there are no open high-severity findings older than 30 days.


Who You Are:

  • 3–5 years of experience in application security, product security, or a similar role.
  • Hands-on experience with SAST/DAST tools (Snyk, Checkmarx, OWASP ZAP, Burp Suite, or equivalent).
  • Solid knowledge of OWASP Top 10 for web and APIs and real-world exploitability assessment
  • Experience reviewing code in Go or similar compiled languages.
  • Familiarity with Kubernetes, containers, and cloud-native architectures.
  • Strong written and verbal communication, able to explain security risks clearly to both engineers and non-technical stakeholders.
  • Self-driven and comfortable working with autonomy in a fast-paced environment.
  • English proficiency — written and spoken (required).
  • Certifications such as OSCP, OSWE, CEH or eWPT.
  • Experience with Istio or service mesh security.
  • Familiarity with compliance frameworks such as ISO 27001, GDPR, or  SOC 2.
  • Threat modeling experience (STRIDE, PASTA, or similar).
  • Experience in fintech or regulated environments.


What We Offer:

  • The chance to join a high-impact, mission-driven fintech with regional scale
  • Cross-functional collaboration with exceptional teams across Latin America
  • Equipment provided by R2
  • Training budget for professional development
  • Career growth within R2


Location: São Paulo, Buenos Aires or Santiago. 


Compensation: 0

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at R2 Companies

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.