About the job #979 - Fractional Security Engineer / Sandox Security Lead
Job Opportunity only available for professionals located in LATAM.
Our client is a modern AI production studio and lab revolutionizing video content creation with fully AI-driven tools. As they scale into more enterprise deals (e.g., supporting clients like PacSun, Zelle, and potential larger contracts), they need to strengthen the security posture of their proprietary Sandbox environment — the secure, client-facing platform for AI video production workflows, model integrations, content generation, and data handling.
This fractional role will focus on conducting a comprehensive security audit, implementing foundational controls, and building a robust, scalable security framework to support enterprise compliance and trust.
The ideal candidate is a hands-on security professional with experience in AI/ML production environments, cloud-native systems, and media/content platforms. They will work collaboratively with our full-stack AI engineering team and product leadership.
Requirements:
- Advanced English level (B2/C1/C2) to ensure fluent communication.
- 5+ years in cybersecurity, with 2+ years focused on cloud/AI/ML or SaaS platforms (preferably involving media, video, or creative tools).
Strong hands-on experience with:
– Cloud security (AWS, GCP, or Azure — IAM, VPC, WAF, GuardDuty/Security Hub, etc.)
– Container and orchestration security (Docker, Kubernetes)
– Secure coding practices, vulnerability management, and penetration testing concepts
– API security, OAuth, JWT, and modern auth frameworks - Familiarity with AI/ML production risks (model poisoning, data leakage, inference attacks, etc.) is a strong plus.
- Experience conducting security audits and building security programs from the ground up in fast-paced startup environments.
- Excellent communication and collaboration skills — able to translate technical risks for product/leadership stakeholders.
Nice-to-Haves:
- Prior work in creative industries, video production tools, or enterprise e-commerce.
- Certifications (e.g., CISSP, CISM, CCSP, AWS Security).
- Experience with FFmpeg/OpenCV ecosystems or AI content pipelines.
Responsibilities:
- Perform an initial security audit of the Sandbox environment, including architecture review, vulnerability assessment, data flows, AI model integrations, and access controls.
- Design and implement core security controls: authentication/authorization (e.g., SSO, RBAC, MFA), encryption (at-rest and in-transit), logging/monitoring, and secure API practices.
- Establish secure development and deployment practices (DevSecOps): CI/CD security scanning, container security (Docker/K8s), IaC security, and secrets management.
- Advise on compliance with relevant standards (e.g., SOC 2, ISO 27001, GDPR, or client-specific enterprise requirements) and help prepare for formal audits.
- Collaborate with the full-stack AI engineering team on secure integration of AI/ML models, video processing pipelines (e.g., FFmpeg/OpenCV-related), and cloud resources (AWS/GCP/Azure).
- Develop security documentation, policies, incident response playbooks, and training/guidance for the team.
- Identify and prioritize quick wins vs. longer-term roadmap items; provide regular progress updates and risk reports to leadership.
- Support ongoing security operations, threat monitoring, and response as needed (part-time scope).
What's in for you?
- Salary in USD.
- 100% Remote work.
- Contract duration: Short-term (Initial 3-6 months with option to extend based on enterprise needs and performance)
- Type of contract: Independent contractor with Venon Solutions LLC.
- Paid Holidays from the US Calendar.
- Working hours: 30-50% time commitment (~12-20 hours/week), with potential for more during audit/implementation phases. Flexible scheduling with dedicated core to Eastern Time (EST/EDT).