обновлено 20 дней назад
Application Security Engineer (Secure SDLC)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Application Security Engineer (Secure SDLC) (Application Security/DevSecOps): Embedding security across the software development lifecycle by integrating SAST, DAST, software composition analysis, secret scanning, and secure coding practices into CI/CD pipelines, with an accent on AWS and Azure cloud-native applications. Focus on automating security controls, reviewing vulnerabilities and penetration testing findings, securing APIs and containerized workloads, and evaluating AI-enabled applications and LLM integrations.
Location: Remote in Brazil
Company
provides software and data-driven solutions for fitness businesses, supporting club management, member engagement, and payment processing.
What you will do
- Partner with software engineering teams to identify, prioritize, and remediate application security risks across the secure software development lifecycle.
- Implement and maintain SAST, DAST, software composition analysis, and secret-scanning tools in CI/CD pipelines.
- Conduct secure code reviews, provide secure coding guidance, and support vulnerability remediation.
- Integrate security into CI/CD and Infrastructure as Code workflows with DevOps teams.
- Support application security reviews for AWS and Azure applications, APIs, cloud-native services, and containerized workloads.
- Contribute to security automation, governance, monitoring, documentation, and evaluation of AI-enabled applications and LLM integrations.
Requirements
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
- Professional proficiency in Portuguese and English is required.
- 1–5 years of experience in application security, software engineering, DevSecOps, platform engineering, or cloud engineering.
- Experience with SSDLC practices, including secure design, code review, automated security testing, and vulnerability remediation.
- Familiarity with SAST, DAST, software composition analysis, vulnerability assessment, penetration testing concepts, OWASP ASVS, and STRIDE.
- Basic AWS or Azure security knowledge, CI/CD experience, and the ability to read or troubleshoot code in a modern programming language.
Nice to have
- Experience with developer security training, security champion programs, Terraform, CloudFormation, Bicep, Docker, or Kubernetes.
- Experience securing AI-enabled applications or LLM integrations.
- Knowledge of OWASP Top 10, CWE, LGPD, GDPR, PCI DSS, or ISO 27001.
- Understanding of OAuth 2.0, OpenID Connect, JWT, and REST API security.
- Relevant security certifications or contributions to open-source and security automation initiatives.
Culture & Benefits
- Values-driven culture focused on inclusion, growth, collaboration, and belonging.
- Quarterly collective days off.
- Health, dental, and life insurance plans.
- Meal allowance, home office allowance, gym access, and educational discounts.
- Employee assistance program and partner discounts.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →