Назад
Company hidden
3 часа назад

Application Security Engineer (Secure SDLC)

Формат работы
remote (только Brazil)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Brazil
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Application Security Engineer (Secure SDLC): Embedding security throughout the software development lifecycle to build secure applications with an accent on CI/CD integration and cloud-native security. Focus on implementing automated security tooling (SAST/DAST/SCA) and remediating vulnerabilities across AWS and Azure environments.

Location: Must be based in Brazil (Remote)

Company

hirify.global is the leading global software provider for fitness businesses of all sizes.

What you will do

  • Partner with engineering teams to identify, prioritize, and remediate application security risks throughout the SSDLC.
  • Implement and maintain security tooling (SAST, DAST, SCA, secret scanning) within CI/CD pipelines.
  • Conduct secure code reviews and provide remediation guidance to development teams.
  • Analyze penetration testing findings and coordinate the validation and fixing of identified issues.
  • Secure AWS and Azure cloud-native services, APIs, and containerized workloads.
  • Evaluate potential security risks for AI-enabled applications and Large Language Models (LLMs).

Requirements

  • Must be based in Brazil.
  • Professional proficiency in both Portuguese and English (written and verbal) is required.
  • 1–5 years of experience in Application Security, DevSecOps, Platform Engineering, or Cloud Engineering.
  • Practical experience with SSDLC, including secure design and automated security testing.
  • Familiarity with threat modeling (OWASP ASVS, STRIDE) and cloud security concepts (AWS/Azure).
  • Ability to read and troubleshoot code in modern languages such as Java, C#, Python, JavaScript/TypeScript, or Go.

Nice to have

  • Experience with Infrastructure as Code (Terraform, CloudFormation, Bicep).
  • Knowledge of container security (Docker, Kubernetes).
  • Familiarity with security and privacy standards like LGPD, GDPR, PCI DSS, or ISO 27001.
  • Understanding of modern authentication and API security (OAuth 2.0, OpenID Connect, JWT).
  • Experience supporting security champion programs or developer training.

Culture & Benefits

  • Quarterly collective "4 Days Off" breaks for the entire global team.
  • Comprehensive health, dental, and life insurance plans.
  • Meal and home office allowances.
  • Gym access subscription and educational partnership discounts.
  • Employee Assistance Program (EAP) providing psychological, legal, and financial support.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →