Information Security Engineer, AppSec

Jobtailor

São Paulo

Presencial

BRL 90 000 - 180 000

Tempo integral

Há 4 dias
Torna-te num dos primeiros candidatos

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Jobtailor in São Paulo seeks a security tester to plan and run security tests across internal and external solutions within the secure development pipeline. You will document vulnerabilities, guide the development teams, and help implement security champions and risk guidance.

The role requires experience in SAST/DAST, threat modeling, and application pen-testing across web, mobile, and REST APIs, with knowledge of SSL and SSDLC. Certifications are a plus.

Qualificações

  • Bachelor’s degree in Information Technology, Computer Science, Information Systems, or a related field.
  • Experience with secure development methodologies, including shift-left security and security by design.
  • Experience with SAST and DAST solutions in secure pipelines and DevSecOps environments.
  • Experience with web, mobile, and REST API applications.
  • Experience with threat modeling.
  • Experience conducting application penetration tests.
  • Knowledge of SSL and SSDLC methodologies.
  • Knowledge of application vulnerabilities and classification methodologies.
  • Certifications such as CEH, eWPTx, OSWA, or CBBH are a plus.
  • Knowledge of Go, Python, Java, and Kotlin is a plus.

Responsabilidades

  • Plan and conduct security testing for all solutions developed internally or externally within the secure development pipeline, using SAST and DAST automation as well as penetration testing in QA environments.
  • Document vulnerabilities and manage them across teams.
  • Support the Development team in identifying potential security risks through guidance and security champion programs.
  • Participate in meetings with business and development teams, providing guidance on security implementation.
  • Conduct penetration tests and produce security reports and assessments.

Conhecimentos

SAST Automation
DAST Automation
Penetration Testing
Secure Development Methodologies
Threat Modeling
Web Application Security
Mobile Application Security
REST API Security
SSL Knowledge

Formação académica

Bachelor’s degree in IT / CS / Information Systems
Certifications such as CEH, eWPTx, OSWA, or CBBH

Ferramentas

Go
Python
Java
Kotlin

Descrição da oferta de emprego

  • Plan and conduct security testing for all solutions developed internally or externally within the secure development pipeline, using SAST and DAST automation as well as penetration testing in QA environments.
  • Document vulnerabilities and manage them across teams.
  • Support the Development team in identifying potential security risks through guidance and security champion programs.
  • Participate in meetings with business and development teams, providing guidance on security implementation.
  • Conduct penetration tests and produce security reports and assessments.
Requirements
  • Bachelor’s degree in Information Technology, Computer Science, Information Systems, or a related field.
  • Experience with secure development methodologies, including shift-left security and security by design.
  • Experience with SAST and DAST solutions in secure pipelines and DevSecOps environments.
  • Experience with web, mobile, and REST API applications.
  • Experience with threat modeling.
  • Experience conducting application penetration tests.
  • Knowledge of SSL and SSDLC methodologies.
  • Knowledge of application vulnerabilities and classification methodologies.
  • Certifications such as CEH, eWPTx, OSWA, or CBBH are a plus.
  • Knowledge of Go, Python, Java, and Kotlin is a plus.
Core Competencies

Demonstrates expertise in security testing methodologies, including SAST, DAST, and penetration testing, while effectively managing vulnerabilities and collaborating with development teams to enhance security practices. Proficient in secure development methodologies and threat modeling, with a strong understanding of application vulnerabilities.

Highest-signal resume keywords
  • SAST Automation
  • DAST Automation
  • Penetration Testing
  • Secure Development Methodologies
  • Threat Modeling
Hard Skills
  • Application Penetration Testing
  • Security Vulnerability Management
  • SSL Knowledge
  • SSDLc Methodologies
  • Web Application Security
  • Mobile Application Security
  • REST API Security
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Information Security Analyst
Information Security Analyst

Jobtailor • Maringá

Presencial
BRL 150 000 - 230 000
Information Security Analyst, Mid-Level
Information Security Analyst, Mid-Level

Jobtailor • São Paulo

Presencial
BRL 150 000 - 210 000
Senior Application Security Engineer - 100% REMOTE
Senior Application Security Engineer - 100% REMOTE

Cibernos • Brasil

Presencial
BRL 180 000 - 300 000
Senior Security and Operations Analyst
Senior Security and Operations Analyst

Jobtailor • São Paulo

Presencial
BRL 90 000 - 150 000
Infrastructure and Digital Security Manager
Infrastructure and Digital Security Manager

Jobtailor • São Paulo

Presencial
BRL 320 000 - 460 000
Information Security Consultant – Mid-Level
Information Security Consultant – Mid-Level

Jobtailor • São Paulo

Presencial
BRL 100 000 - 167 000
Senior/Lead AppSec Engineer ID71672
Senior/Lead AppSec Engineer ID71672

AgileEngine, LLC. • Brasília

Presencial
BRL 180 000 - 290 000
Growth without limits
Competitive compensation
Flexibility — 100% remote
+3
Senior/Lead AppSec Engineer ID71672
Senior/Lead AppSec Engineer ID71672

AgileEngine, LLC. • Salvador

Teletrabalho
BRL 180 000 - 320 000
Growth without limits
Competitive compensation
Flexibility: 100% remote with flexible
+3
Software Engineering Analyst
Software Engineering Analyst

Jobtailor • Fortaleza

Presencial
BRL 120 000 - 180 000
Espec I - Segurança da Informação - (AppSec)
Espec I - Segurança da Informação - (AppSec)

Safra • São Paulo

Presencial