Назад
Company hidden
9 часов Π½Π°Π·Π°Π΄

Senior Product Security Engineer (Cybersecurity)

50Β 000 - 60Β 000$
Π€ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹
remote (Ρ‚ΠΎΠ»ΡŒΠΊΠΎ Brazil)
Π’ΠΈΠΏ Ρ€Π°Π±ΠΎΡ‚Ρ‹
fulltime
Π“Ρ€Π΅ΠΉΠ΄
senior
Английский
b2
Π‘Ρ‚Ρ€Π°Π½Π°
Brazil
Вакансия ΠΈΠ· списка Hirify.GlobalВакансия ΠΈΠ· Hirify Global, списка ΠΌΠ΅ΠΆΠ΄ΡƒΠ½Π°Ρ€ΠΎΠ΄Π½Ρ‹Ρ… tech-ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΉ
Для мэтча ΠΈ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠ° Π½ΡƒΠΆΠ΅Π½ Plus

ΠœΡΡ‚Ρ‡ & Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠ΄

Для мэтча с этой вакансиСй Π½ΡƒΠΆΠ΅Π½ Plus

ОписаниС вакансии

ВСкст:
/
TL;DR
Senior Product Security Engineer (Cybersecurity): Securing a modern web platform across the SDLC through architecture reviews, threat modeling, penetration testing, and secure-coding collaboration with an accent on web applications, APIs, authentication, and vulnerability management. Focus on operating SAST, DAST, and supply-chain scanning, translating findings into remediation work, and strengthening SOC 2 and ISO 27001 compliance evidence.

Location: Remote in Brazil

Compensation: $50K–$60K annually

Company

hirify.global develops a software platform supported by product and platform engineering teams.

What you will do

  • Partner with developers throughout the SDLC to embed security into product development.
  • Lead security design and architecture reviews and conduct threat modeling for new features and services.
  • Perform penetration testing of web applications and APIs and turn findings into prioritized remediation work.
  • Conduct secure code reviews and help define secure-coding standards and security acceptance criteria.
  • Operate and tune SAST, DAST, dependency, and supply-chain scanning tools.
  • Contribute security evidence and rigor to SOC 2, ISO 27001, and similar compliance programs.

Requirements

  • Strong professional experience in product or application security.
  • Hands-on penetration testing experience with web applications and APIs.
  • Deep knowledge of modern web applications, authentication and authorization, sessions, OAuth 2.0, OpenID Connect, and OWASP Top 10 risks.
  • Experience with security design reviews, threat modeling, and integrating security into the SDLC.
  • Strong communication skills for explaining security risks and remediation steps to developers.
  • Must be able to work remotely from Brazil.

Nice to have

  • Experience with OWASP ZAP, Burp Suite Community Edition, Semgrep, Trivy, Grype, or Nuclei.
  • OSCP or another relevant offensive-security certification.
  • Cloud security experience with AWS, Azure, or GCP, plus container or Kubernetes security.
  • Experience supporting SOC 2, ISO 27001, or similar programs.
  • Experience in enterprise or regulated environments.

Culture & Benefits

  • Remote contract role based in Brazil.
  • Collaborative security partnership with product and platform engineering teams.
  • Security is embedded early in development rather than applied only before release.
  • Success is measured through practical security processes, clear remediation paths, and early developer engagement.

Π‘ΡƒΠ΄ΡŒΡ‚Π΅ остороТны: Ссли Ρ€Π°Π±ΠΎΡ‚ΠΎΠ΄Π°Ρ‚Π΅Π»ΡŒ просит Π²ΠΎΠΉΡ‚ΠΈ Π² ΠΈΡ… систСму, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡ iCloud/Google, ΠΏΡ€ΠΈΡΠ»Π°Ρ‚ΡŒ ΠΊΠΎΠ΄/ΠΏΠ°Ρ€ΠΎΠ»ΡŒ, Π·Π°ΠΏΡƒΡΡ‚ΠΈΡ‚ΡŒ ΠΊΠΎΠ΄/ПО, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡ‚Π΅ этого - это мошСнники. ΠžΠ±ΡΠ·Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΆΠΌΠΈΡ‚Π΅ "ΠŸΠΎΠΆΠ°Π»ΠΎΠ²Π°Ρ‚ΡŒΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡˆΠΈΡ‚Π΅ Π² ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΡƒ. ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β†’