9 ΡΠ°ΡΠΎΠ² Π½Π°Π·Π°Π΄
Senior Product Security Engineer (Cybersecurity)
50Β 000 - 60Β 000$
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Π’Π΅ΠΊΡΡ:
TL;DR
Senior Product Security Engineer (Cybersecurity): Securing a modern web platform across the SDLC through architecture reviews, threat modeling, penetration testing, and secure-coding collaboration with an accent on web applications, APIs, authentication, and vulnerability management. Focus on operating SAST, DAST, and supply-chain scanning, translating findings into remediation work, and strengthening SOC 2 and ISO 27001 compliance evidence.
Location: Remote in Brazil
Compensation: $50Kβ$60K annually
Company
develops a software platform supported by product and platform engineering teams.
What you will do
- Partner with developers throughout the SDLC to embed security into product development.
- Lead security design and architecture reviews and conduct threat modeling for new features and services.
- Perform penetration testing of web applications and APIs and turn findings into prioritized remediation work.
- Conduct secure code reviews and help define secure-coding standards and security acceptance criteria.
- Operate and tune SAST, DAST, dependency, and supply-chain scanning tools.
- Contribute security evidence and rigor to SOC 2, ISO 27001, and similar compliance programs.
Requirements
- Strong professional experience in product or application security.
- Hands-on penetration testing experience with web applications and APIs.
- Deep knowledge of modern web applications, authentication and authorization, sessions, OAuth 2.0, OpenID Connect, and OWASP Top 10 risks.
- Experience with security design reviews, threat modeling, and integrating security into the SDLC.
- Strong communication skills for explaining security risks and remediation steps to developers.
- Must be able to work remotely from Brazil.
Nice to have
- Experience with OWASP ZAP, Burp Suite Community Edition, Semgrep, Trivy, Grype, or Nuclei.
- OSCP or another relevant offensive-security certification.
- Cloud security experience with AWS, Azure, or GCP, plus container or Kubernetes security.
- Experience supporting SOC 2, ISO 27001, or similar programs.
- Experience in enterprise or regulated environments.
Culture & Benefits
- Remote contract role based in Brazil.
- Collaborative security partnership with product and platform engineering teams.
- Security is embedded early in development rather than applied only before release.
- Success is measured through practical security processes, clear remediation paths, and early developer engagement.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β