Назад
Company hidden
2 дня назад

Staff Security Engineer (AppSec)

Формат работы
remote (только Brazil)
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Brazil
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Security Engineer (AppSec) (Cloud Security): Building organization-wide application security standards and risk controls for a subscription platform serving millions of users globally with an accent on secure architecture, threat modeling, vulnerability management, and offensive security. Focus on leading cross-service incident response, red-team and penetration-testing initiatives, cloud security across AWS and GCP, and translating complex security trade-offs into strategic investments.

Location: Remote within Brazil only

Company

hirify.global operates a subscription-based workplace wellness platform connecting employees with fitness, mindfulness, therapy, nutrition, and sleep partners.

What you will do

  • Own multiple security domains end-to-end and serve as the technical authority for complex, cross-service security challenges.
  • Establish secure-by-design architecture standards, lead threat modeling, and define secure-coding benchmarks.
  • Lead complex incident responses and post-mortems, converting findings into systemic guardrails and platform-level prevention.
  • Direct red-team exercises and penetration-testing engagements, driving root-cause remediation with engineering teams.
  • Define security SLAs, SLOs, and KPIs and build monitoring for remediation, response times, and posture drift.
  • Partner with Engineering, Product, and Legal leadership on threat intelligence, compliance, and long-term security investments.

Requirements

  • Prior security engineering experience is mandatory.
  • Extensive experience in security engineering or software engineering with significant security impact in complex cloud environments.
  • Expertise in secure architecture, threat modeling, and organization-wide secure-coding standards.
  • Fluency in English and Portuguese.
  • Strong understanding of attacker TTPs, AWS/EKS, GCP/GKE, Istio, ArgoCD, SOC 2, ISO 27001, LGPD, and GDPR.
  • Experience mentoring engineering teams and making independent, high-stakes risk decisions.

Culture & Benefits

  • Flexible remote work model for this role, with home-office reimbursement.
  • hirify.global Gold+ membership and access to fitness and wellness resources.
  • Wellz emotional wellbeing program with therapy sessions and on-demand content.
  • Health, dental, and life insurance.
  • Paid time off, additional annual days off, birthday holiday, and 100% paid parental leave.
  • Career development platforms, learning sessions, personalized development roadmaps, and internal opportunities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →