Kavak

Kavak

Kavak is a disruptive brand in the automotive industry, offering a wide range of guaranteed and certified cars through a seamless e-commerce platform, app, and stores worldwide.

Automotive
1K-5K
Founded 2016
$2400M raised

Description

  • Design the organization’s AI security strategy, covering AI as attacker, attack vector, and target, including prompt injection, harness security, and guardrails.
  • Lead Kavak’s cybersecurity strategy with SOX, ISO 27001, and NIST as core compliance pillars.
  • Ensure compliance with SOX, ISO 27001, and NIST requirements.
  • Lead and develop the cybersecurity team, including recruiting and building the best regional talent.
  • Ensure coverage across AppSec, ProdSec, SecOps, IAM, and GRC, with hands-on execution when needed.
  • Own the security area’s budget, headcount, and tooling to optimize available resources.
  • Drive the transformation of Kavak’s security function by building cross-functional partnerships with Finance, AI, Platform, and Operations.
  • Execute and maintain incident response, business continuity and disaster recovery plans, pentesting, and organization-wide security awareness programs.

Requirements

  • Proven experience in cybersecurity with a track record in technical leadership roles.
  • Strong experience in application security or red teaming, including securing applications or executing attacks.
  • Experience securing cloud environments in GCP and AWS.
  • Experience with applications built in Python, Go, and Java.
  • Experience leading multidisciplinary teams in hypergrowth environments.
  • Preferred: experience in security for AI systems and large language models.
  • Strong command of SOX, ISO 27001, and NIST compliance frameworks.
  • Hands-on experience with Fortinet, Cortex, Netskope, and JumpCloud.
  • Technical builder mindset with strategic judgment and a hands-on approach.
  • Ability to communicate technical risk in financial and executive language.

Benefits

  • 15 days of vacation in the first year and 20 days starting in the second year.
  • Vacation premium of 25% of corresponding vacation pay.
  • 15 annual days of Christmas bonus (aguinaldo).
  • IMSS coverage with 100% salary contribution.
  • Stock options.
  • Company car for use during employment, valued between MXN $415,000 and $550,000 depending on level.
  • Meal vouchers of MXN $1,056 via Sí Vale.
  • Major medical insurance with MetLife, with optional dependent coverage at preferential cost.
  • Life insurance.
  • Employee car purchase benefit with 11% discount after 12 months, plus extended warranty options and preferential financing.
  • Friends and Family discounts, salary advance access, retail discounts, wellness programs, gym access, therapy discounts, and other employee savings programs.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Director, Detection Engineering & Threat Hunting

Huntress 251-1K Professional Services

Huntress is hiring a remote U.S.-based Director of Detection Engineering & Threat Hunting to lead the function’s strategy, structure, and execution as the company scales its cybersecurity platform.

Cybersecurity
15 minutes ago

Anti-Bot Engineer (Remote, Full-Time), PK [HR177]

Smart Working Internet Software & Services

Smart Working is hiring a remote Anti-Bot Engineer to design and operate large-scale web scraping systems that reliably extract data from heavily protected, fast-changing web environments.

Docker Go HTTP JavaScript Kubernetes Playwright Puppeteer Python Rust Selenium TLS
5 hours, 3 minutes ago

Security Engineer [IC3]

Great Notion Support Services Internet Software & Services

Sourcegraph is hiring a Security Engineer to strengthen the security of its code intelligence platform, with a primary focus on security operations across product, cloud, and customer deployments.

GCP Go Kubernetes SIEM Terraform TypeScript
6 hours, 41 minutes ago

Enterprise Security Engineer

DoorDash 10K-50K Air Freight & Logistics

DoorDash is hiring an Enterprise Security Engineer to help protect employees, endpoints, and corporate software across DoorDash, Wolt, and Deliveroo by operating security controls, automating workflows, and improving secure-by-default practices.

AWS GCP Go JIRA Linux macOS OAuth OpenID Connect Python SAML Terraform
6 hours, 56 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers