Marathon Talent

Marathon Talent is a human resources and talent advisory firm that helps companies hire top bilingual talent from Latin America through recruitment, fractional people and talent strategy, market insights, salary studies, and advisory/mentorship services.

Human Resources
1-10
Founded 2023

Description

  • Conduct secure code reviews for Go-based microservices and identify vulnerabilities early in development.
  • Perform security testing of APIs, web applications, and backend services before production releases.
  • Establish and evolve secure coding standards, guardrails, and reusable engineering patterns.
  • Lead threat modeling sessions with engineering and product teams during feature and service design.
  • Define and enforce security gates in CI/CD pipelines, including SAST, DAST, SCA, and secrets scanning.
  • Own the end-to-end DAST process, including tool selection, scheduling, escalation, and remediation tracking.
  • Integrate container image scanning and infrastructure-as-code security checks into deployment pipelines.
  • Support hardening efforts across Kubernetes, ingress, and workloads.
  • Define and tune security observability alerts for authentication anomalies and suspicious API usage.
  • Triage, prioritize, and track remediation of security findings across the platform.
  • Coordinate external penetration tests and work with vendors on scope, debriefs, and remediation plans.
  • Build and maintain security documentation, runbooks, and standards.

Requirements

  • 3–5 years of experience in application security, product security, or a similar role.
  • Hands-on experience with SAST/DAST tools such as Snyk, Checkmarx, OWASP ZAP, Burp Suite, or equivalent.
  • Solid knowledge of OWASP Top 10 for web and APIs and real-world exploitability assessment.
  • Experience reviewing code in Go or similar compiled languages.
  • Familiarity with Kubernetes, containers, and cloud-native architectures.
  • Strong written and verbal communication skills with the ability to explain security risks to technical and non-technical stakeholders.
  • Self-driven and comfortable working with autonomy in a fast-paced environment.
  • English proficiency in both written and spoken communication.
  • Certifications such as OSCP, OSWE, CEH, or eWPT are a plus.
  • Experience with Istio or service mesh security is a plus.
  • Familiarity with compliance frameworks such as ISO 27001, GDPR, or SOC 2 is a plus.
  • Threat modeling experience with STRIDE, PASTA, or similar is a plus.
  • Experience in fintech or regulated environments is a plus.

Benefits

  • Opportunity to join a high-impact, mission-driven fintech with regional scale.
  • Cross-functional collaboration with strong teams across Latin America.
  • Equipment provided by R2.
  • Training budget for professional development.
  • Career growth opportunities within R2.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Manager, Product Security

Tines 51-250 Construction & Engineering

Tines is seeking a Senior Manager, Product Security to lead and scale its product security program for cloud-native, AI-forward products while partnering with engineering and product leaders to manage risk and support growth.

AWS CI/CD DevSecOps Docker Kubernetes Penetration Testing Ruby Rust TypeScript
2 days, 18 hours ago

Application Security Engineer

Glean 11-50 Internet Software & Services

Glean is hiring a remote Application Security Engineer to lead vulnerability management and strengthen software supply-chain security across its Work AI platform.

AWS Burp Suite CI/CD Cybersecurity GCP Kubernetes Microservices
2 days, 18 hours ago

Lead Application Security Engineer

Remofirst 11-50 Professional Services

RemoFirst is hiring an application and cloud security engineer to secure its global Employer of Record platform, customer identity systems, infrastructure, and emerging AI initiatives across a distributed engineering organization.

AWS Django FastAPI Java Kafka Kubernetes MongoDB OpenID Connect Penetration Testing PostgreSQL Python RabbitMQ REST API SAML Secrets Management Spring Boot Terraform
2 days, 18 hours ago

Application Security Engineer II

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring an Application Security Engineer to triage and validate vulnerability submissions for major clients, communicate with researchers and customers, and support incident response across diverse security programs.

Burp Suite Nmap
3 days, 18 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers