Director Security Engineer (DevSecOps)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Director Security Engineer (DevSecOps): Driving application security and DevSecOps practices across 10 product verticals with an accent on security architecture, threat modeling, and automation. Focus on scaling security posture, reducing MTTD, and integrating SAST/DAST/SCA into CI/CD pipelines.
Location: Remote (Must be based in Brazil)
Company
is a workplace wellness platform that connects employees worldwide to fitness, mindfulness, therapy, and nutrition services via a single subscription.
What you will do
- Lead technical security strategy, defining architecture standards and secure coding guidelines aligned with OWASP ASVS, NIST SSDF, and BSIMM.
- Architect and implement DevSecOps pipelines integrating SAST, DAST, SCA, and container scanning.
- Drive threat modeling for critical product flows to identify and mitigate risks before production.
- Design centralized security telemetry and unify logs, WAF events, and fraud signals into a SIEM platform.
- Lead evaluation and implementation of security tools including PAM, API Gateway security, and container scanners.
- Mentor a team of 7-8 embedded DevSecOps engineers across product verticals.
Requirements
- At least 4 years in a senior technical leadership role focusing on security engineering.
- Deep expertise in SSDLC, threat modeling (STRIDE, PASTA), and distributed systems architecture.
- Hands-on experience with tools such as Snyk, Checkmarx, Burp Suite, Elastic, Splunk, and Trivy.
- Extensive knowledge of AWS or GCP, IAM, VPC security, and Kubernetes (EKS).
- Proficiency in at least two languages among Python, Go, Java, or JavaScript.
- Must be based in Brazil with professional proficiency in both Portuguese and English.
Culture & Benefits
- Free Gold+ membership for the employee and up to three family members.
- Wellz emotional wellbeing program providing 52 individual therapy sessions per year.
- Comprehensive health, dental, and life insurance.
- Flexible-first work model with home office reimbursement.
- 100% paid parental leave and comprehensive paid time off including birthday holidays.
- Access to world-class career growth platforms and personalized development roadmaps.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →