Назад
Company hidden
обновлено 20 дней назад

Application Security Engineer (Secure SDLC)

Формат работы
remote (только Brazil)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Brazil
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (Secure SDLC) (Application Security/DevSecOps): Embedding security across the software development lifecycle by integrating SAST, DAST, software composition analysis, secret scanning, and secure coding practices into CI/CD pipelines, with an accent on AWS and Azure cloud-native applications. Focus on automating security controls, reviewing vulnerabilities and penetration testing findings, securing APIs and containerized workloads, and evaluating AI-enabled applications and LLM integrations.

Location: Remote in Brazil

Company

hirify.global provides software and data-driven solutions for fitness businesses, supporting club management, member engagement, and payment processing.

What you will do

  • Partner with software engineering teams to identify, prioritize, and remediate application security risks across the secure software development lifecycle.
  • Implement and maintain SAST, DAST, software composition analysis, and secret-scanning tools in CI/CD pipelines.
  • Conduct secure code reviews, provide secure coding guidance, and support vulnerability remediation.
  • Integrate security into CI/CD and Infrastructure as Code workflows with DevOps teams.
  • Support application security reviews for AWS and Azure applications, APIs, cloud-native services, and containerized workloads.
  • Contribute to security automation, governance, monitoring, documentation, and evaluation of AI-enabled applications and LLM integrations.

Requirements

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • Professional proficiency in Portuguese and English is required.
  • 1–5 years of experience in application security, software engineering, DevSecOps, platform engineering, or cloud engineering.
  • Experience with SSDLC practices, including secure design, code review, automated security testing, and vulnerability remediation.
  • Familiarity with SAST, DAST, software composition analysis, vulnerability assessment, penetration testing concepts, OWASP ASVS, and STRIDE.
  • Basic AWS or Azure security knowledge, CI/CD experience, and the ability to read or troubleshoot code in a modern programming language.

Nice to have

  • Experience with developer security training, security champion programs, Terraform, CloudFormation, Bicep, Docker, or Kubernetes.
  • Experience securing AI-enabled applications or LLM integrations.
  • Knowledge of OWASP Top 10, CWE, LGPD, GDPR, PCI DSS, or ISO 27001.
  • Understanding of OAuth 2.0, OpenID Connect, JWT, and REST API security.
  • Relevant security certifications or contributions to open-source and security automation initiatives.

Culture & Benefits

  • Values-driven culture focused on inclusion, growth, collaboration, and belonging.
  • Quarterly collective days off.
  • Health, dental, and life insurance plans.
  • Meal allowance, home office allowance, gym access, and educational discounts.
  • Employee assistance program and partner discounts.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →