Назад
Company hidden
7 часов назад

Application Security Specialist | AppSec (Fintech)

Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
c1
Страна
Brazil
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Specialist | AppSec (Fintech): Leading AppSec strategy and technical mentorship while securing payment technology through threat modeling, vulnerability management, and security tooling. Focus on configuring SAST, DAST, and SCA in CI/CD pipelines, securing APIs and secrets, and reviewing code across multiple programming languages.

Location: Curitiba, Brazil — on-site

Company

hirify.global is a fintech building global payment infrastructure that connects digital businesses with consumers across 21 emerging markets.

What you will do

  • Lead the Application Security strategy and provide technical mentorship to junior, mid-level, and senior security analysts.
  • Architect and oversee threat modeling sessions across product squads to identify architectural flaws and security requirements early.
  • Drive global security projects and communicate security risks and standards in English to international stakeholders.
  • Manage vulnerabilities identified through SAST, DAST, and SCA, providing actionable remediation guidance and code-fix support.

Requirements

  • Hands-on experience configuring and tuning SAST, DAST, and SCA tooling within CI/CD pipelines.
  • Strong expertise in API security and secret management, including REST/GraphQL APIs, tokens, certificates, and secrets.
  • Experience with tools such as HashiCorp Vault or AWS Secrets Manager.
  • Ability to review and secure code in multiple stacks, including Java, Python, Go, Node, or .NET.
  • Advanced to fluent English communication is required for technical discussions, documentation, and collaboration with distributed teams.

Nice to have

  • Advanced security certifications such as OSWE, CASE, CSSLP, or CISSP.
  • Experience automating security guardrails or internal tools for secrets and vulnerability triage.
  • Participation in bug bounty programs, open-source security projects, or security conferences such as OWASP Global AppSec.

Culture & Benefits

  • Annual performance bonus based on company results.
  • Monthly meal allowance and medical and dental plans with dependent coverage.
  • Financial assistance for undergraduate, graduate, and MBA programs.
  • Budgets for courses, certifications, and workshops, plus language classes.
  • Semi-flexible hours, a birthday day off, a year-end break, and physical and mental well-being programs.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →