Why should you join dLocal?
dLocal enables the biggest companies in the world to collect payments in 40 countries in emerging markets. Global brands rely on us to increase conversion rates and simplify payment expansion effortlessly. As both a payments processor and a merchant of record where we operate, we make it possible for our merchants to make inroads into the world’s fastest-growing, emerging markets.
By joining us you will be a part of an amazing global team that makes it all happen. Being a part of dLocal means working with 1000+ teammates from 30+ different nationalities and developing an international career that impacts millions of people’s daily lives. We are builders, we never run from a challenge, we are customer-centric, and if this sounds like you, we know you will thrive in our team.
About Us & The Role
We are building the backbone of a modern, disruptive security organization. We believe that to stay ahead of adversaries, we must move faster, scale smarter, and leverage technology that others are afraid to touch.
This is a newly created area within the CISO’s office: The Security Platforms, AI, and Automation team. We are not looking for theoretical researchers; we are looking for practical builders. You won't just be maintaining tools; you will be building the "Central Nervous System" of our security department.
You will be the force multiplier that connects our data, automates our workflows, and empowers every other team—from Cyber Defense to GRC—to operate at 100x scale. Your mission starts with solid engineering: building the "glue" that connects our diverse security stack into a unified, measurable ecosystem. Once that foundation is set, you will leverage AI agents and modern protocols to take those automations to the next level.
What You’ll Do:
Engineer Secure-by-Default Foundations: Design, build, and maintain hardened,
multi-account AWS architectures, "golden" AMIs, and secure-by-default
container/Kubernetes (EKS) base images.
Automate Security via IaC: Be the expert in "Policy-as-Code." Publish and maintain
Infrastructure controls, golden Terraform modules, Helm charts, and admission
policies. You will measure adoption, drift detection, and exception aging while
preventing misconfigurations before they're deployed.
Own the Platform & Edge Defense: Configure and manage runtime security for
Kubernetes (e.g., admission controllers, least-privilege policies) and own the safe-
change processes for our layered edge defenses (WAF/CDN/anti-Bot), including pre-
prod testing, blast-radius limits, rollback patterns, and change metrics.
Generate High-Fidelity Signals: Integrate posture signals (CSPM, KSPM, CI/CD,
WAF) into centralized dashboards and our SIEM/SOAR with clear routing and
ownership, partnering with D&R to ensure signals are high-fidelity and actionable.
Enable & Mentor: Lead threat modeling exercises and partner with Platform, SRE,
and Product teams to translate risks into actionable backlogs. You'll be mentoring
others on prevention-first design.
Support Incident Response: Define platform incident playbooks for
misconfiguration and drift containment. You will act as the senior subject-matter
expert for cloud/platform incidents, providing deep technical expertise to the IR
team.
What You Bring:
A "Builder" Mindset: 4-8+ years of hands-on experience in Cloud Security, Platform
Security, or DevSecOps. You have a passion for building preventative solutions from
the ground up.
Deep Cloud-Native Expertise: Advanced AWS security architecture (multi-account,
IAM boundaries, org SCPs) and expert-level, hands-on knowledge of building and
securing production environments.
Mastery of Modern Stacks: Deep, practical experience with production EKS
baseline hardening (admission control, least privilege, runtime controls). You arefluent in IaC (Terraform, Pulumi, or Ansible) and have strong scripting/automation
skills (Python, Go, etc.).
Application & Edge Security: Hands-on experience configuring and tuning modern
WAFs, CDNs, and edge security platforms (e.g., Cloudflare, Akamai, AWS WAF).
A Pragmatic Risk-Based Approach: You can translate risks from threat models and
compliance frameworks (CIS, NIST, OWASP, PCI) into actionable, prioritized
engineering work—not just checkbox-ticking.
A Force-Multiplier: You have a leadership attitude to influence and mentor
engineers, document complex systems clearly, and influence other teams to adopt
security-first practices.
Nice to Have:
Experience with modern posture management tools (CSPM/KSPM/DSPM).
Experience with common, large-scale edge security stacks (e.g., Cloudflare, Akamai,
AWS WAF).
Multi-cloud experience (GCP, Azure) in addition to AWS.
Certifications like CKA/CKS, AWS Security Specialty, or OSCP are valued but not
required.
How You’ll Work
You will work through Cloud Platform/SRE teams to roll out guardrails as shared
services and "paved roads."
You'll coordinate with the Application Security team for threat modeling and with
the Detection & Response (D&R) team for signal fidelity and automated containment
handoffs
Why You'll Love It Here: This is a high-impact, high-ownership role. You'll join a small, senior team where
everyone contributes end-to-end. We're building a modern, intelligent, and automated
defense program from the ground up. If you're tired of legacy tools and "bolt-on"
security, and you want to build the future of proactive, automated cyber defense from the
code up, let's talk.
What do we offer?
Besides the tailored benefits we have for each country, dLocal will help you thrive and go that extra mile by offering you:
- Flexibility: we have flexible schedules and we are driven by performance.
- Fintech industry: work in a dynamic and ever-evolving environment, with plenty to build and boost your creativity.
- Referral bonus program: our internal talents are the best recruiters - refer someone ideal for a role and get rewarded.
- Learning & development: get access to a Premium Coursera subscription.
- Language classes: we provide free English, Spanish, or Portuguese classes.
- Social budget: you'll get a monthly budget to chill out with your team (in person or remotely) and deepen your connections!
- dLocal Houses: want to rent a house to spend one week anywhere in the world coworking with your team? We’ve got your back!
Flexibility in how you work: We focus on impact and productivity over fixed hours. This means our teams have flexible schedules and, depending on your role and location, you will combine self‑managed focus time with moments of in‑person connection in our collaboration hubs.
What happens after you apply?
Our Talent Acquisition team is invested in creating the best candidate experience possible, so don’t worry, you will definitely hear from us. We will review your CV and keep you posted by email at every step of the process!