Назад
Company hidden
2 мСсяца Π½Π°Π·Π°Π΄

Application Security Specialist | AppSec (Fintech)

Π€ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹
onsite
Π’ΠΈΠΏ Ρ€Π°Π±ΠΎΡ‚Ρ‹
fulltime
Π“Ρ€Π΅ΠΉΠ΄
lead
Английский
c1
Π‘Ρ‚Ρ€Π°Π½Π°
Brazil
Вакансия ΠΈΠ· списка Hirify.GlobalВакансия ΠΈΠ· Hirify Global, списка ΠΌΠ΅ΠΆΠ΄ΡƒΠ½Π°Ρ€ΠΎΠ΄Π½Ρ‹Ρ… tech-ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΉ
Для мэтча ΠΈ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠ° Π½ΡƒΠΆΠ΅Π½ Plus

ΠœΡΡ‚Ρ‡ & Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠ΄

Для мэтча с этой вакансиСй Π½ΡƒΠΆΠ΅Π½ Plus

ОписаниС вакансии

ВСкст:
/
TL;DR
Application Security Specialist | AppSec (Fintech): Leading AppSec strategy and technical mentorship while securing payment technology through threat modeling, vulnerability management, and security tooling. Focus on configuring SAST, DAST, and SCA in CI/CD pipelines, securing APIs and secrets, and reviewing code across multiple programming languages.

Location: Curitiba, Brazil β€” on-site

Company

hirify.global is a fintech building global payment infrastructure that connects digital businesses with consumers across 21 emerging markets.

What you will do

  • Lead the Application Security strategy and provide technical mentorship to junior, mid-level, and senior security analysts.
  • Architect and oversee threat modeling sessions across product squads to identify architectural flaws and security requirements early.
  • Drive global security projects and communicate security risks and standards in English to international stakeholders.
  • Manage vulnerabilities identified through SAST, DAST, and SCA, providing actionable remediation guidance and code-fix support.

Requirements

  • Hands-on experience configuring and tuning SAST, DAST, and SCA tooling within CI/CD pipelines.
  • Strong expertise in API security and secret management, including REST/GraphQL APIs, tokens, certificates, and secrets.
  • Experience with tools such as HashiCorp Vault or AWS Secrets Manager.
  • Ability to review and secure code in multiple stacks, including Java, Python, Go, Node, or .NET.
  • Advanced to fluent English communication is required for technical discussions, documentation, and collaboration with distributed teams.

Nice to have

  • Advanced security certifications such as OSWE, CASE, CSSLP, or CISSP.
  • Experience automating security guardrails or internal tools for secrets and vulnerability triage.
  • Participation in bug bounty programs, open-source security projects, or security conferences such as OWASP Global AppSec.

Culture & Benefits

  • Annual performance bonus based on company results.
  • Monthly meal allowance and medical and dental plans with dependent coverage.
  • Financial assistance for undergraduate, graduate, and MBA programs.
  • Budgets for courses, certifications, and workshops, plus language classes.
  • Semi-flexible hours, a birthday day off, a year-end break, and physical and mental well-being programs.

Π‘ΡƒΠ΄ΡŒΡ‚Π΅ остороТны: Ссли Ρ€Π°Π±ΠΎΡ‚ΠΎΠ΄Π°Ρ‚Π΅Π»ΡŒ просит Π²ΠΎΠΉΡ‚ΠΈ Π² ΠΈΡ… систСму, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡ iCloud/Google, ΠΏΡ€ΠΈΡΠ»Π°Ρ‚ΡŒ ΠΊΠΎΠ΄/ΠΏΠ°Ρ€ΠΎΠ»ΡŒ, Π·Π°ΠΏΡƒΡΡ‚ΠΈΡ‚ΡŒ ΠΊΠΎΠ΄/ПО, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡ‚Π΅ этого - это мошСнники. ΠžΠ±ΡΠ·Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΆΠΌΠΈΡ‚Π΅ "ΠŸΠΎΠΆΠ°Π»ΠΎΠ²Π°Ρ‚ΡŒΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡˆΠΈΡ‚Π΅ Π² ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΡƒ. ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β†’