обновлено 14 часов назад
Security Analyst (AI/LLM Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Analyst (AI/LLM Security) (Application Security, Cloud, AI): Building and maintaining security solutions for modern web applications, APIs, cloud-native services, and AI/LLM-powered capabilities with an accent on vulnerability management, secure development, and AI security testing. Focus on analyzing and remediating application risks, automating security workflows, and operationalizing OWASP-based testing across the SDLC.
Location: Remote, Brazil
Company
Supply chain software provider developing technologies that help organizations streamline operations, reduce costs, and improve efficiency.
What you will do
- Scan applications and infrastructure for vulnerabilities using DAST, SAST, and software composition analysis tools.
- Analyze, validate, prioritize, and track findings through remediation while verifying fixes and reducing false positives.
- Partner with engineering and product teams on vulnerability assessment, remediation recommendations, threat modeling, design reviews, and secure coding practices.
- Secure modern web applications, REST APIs, microservices, cloud-native services, and AI/LLM-powered features.
- Use AI-assisted security tools and automation to improve analysis, triage, reporting, testing efficiency, and recurring workflows.
- Help define and operationalize AI security testing strategies based on the OWASP Top 10 for LLM Applications.
Requirements
- 5+ years of experience in Application Security, Product Security, or Vulnerability Management.
- Hands-on experience with DAST, SAST, web application security testing, and API security testing.
- Experience with AWS, Azure, OCI, and CSPM tools such as Wiz.
- Deep understanding of the OWASP Top 10, Secure SDLC principles, modern application architectures, and application security architecture.
- Experience collaborating directly with software development teams on vulnerability remediation.
- Strong analytical, documentation, verbal, and written communication skills, plus familiarity with the OWASP Top 10 for LLMs.
Nice to have
- Experience securing or testing LLM-powered applications in production.
- Familiarity with Burp Suite, ZAP, Snyk, Semgrep, Checkmarx, Veracode, or similar tools.
- Experience using AI to augment security testing or analysis.
- Strong scripting or automation skills with Python, Bash, or similar languages.
- Exposure to SOC 2 or ISO 27001 security controls related to application security.
Culture & Benefits
- Full-time remote work from Brazil.
- Focus on innovation, growth, inclusion, and meaningful work in supply chain technology.
- Equal-opportunity workplace with commitment to a safe and welcoming environment.
- Reasonable accommodations are available during the recruiting process.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
Security Engineer, Application & AI
Datadog
7 часов назад
Staff Application Security Engineer (AI)
244 000 - 305 000$
23 часа назад
Staff Product Security Engineer (AI Security)
154 000 - 205 000$
1 день назад
Senior SecOps Engineer (AWS)
2 дня назад
Application Security Engineer (AI)
1 день назад