Security Analyst manage DAST, SAST experience 90% english

Infios

Brasil

Presencial

BRL 120 000 - 240 000

Tempo integral

há 21 horas
Torna-te num dos primeiros candidatos

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Infios is seeking a Security Analyst to join our Threat and Vulnerability Management (TVM) Team. You will help build and maintain security solutions to safeguard our systems and data, focusing on identifying, analyzing, and remediating security risks across applications and AI‑powered features.

In this hands‑on role, you will partner with development and product teams, apply OWASP Top 10 guidance for web apps and APIs, and drive secure SDLC practices through tooling, automation, and AI‑augmented

Qualificações

  • 5+ years of experience in Application Security, Product Security, or Vulnerability Management.
  • Experience with cloud platforms like AWS, Azure, and OCI and CSPM tools (WIZ).
  • Strong hands‑on experience with DAST and SAST tools, Web Application and API Security Testing.
  • Deep understanding of OWASP Top 10 and Secure SDLC principles.
  • Excellent documentation and communication skills (both verbal and written).
  • Analytical problem‑solving skills and knowledge of application security architecture.
  • Experience working directly with software development teams on remediation.
  • Solid understanding of modern application architectures (REST APIs, microservices, cloud).
  • Familiarity with OWASP Top 10 for LLMs.

Responsabilidades

  • Scan vulnerabilities using industry‑leading tools in applications and infrastructure.
  • Conduct and manage DAST, SAST, and software composition analysis (SCA) activities.
  • Analyze vulnerability scan results, validate findings, reduce false positives, and prioritize risk.
  • Collaborate directly with development teams to assess identified vulnerabilities and deliver precise, actionable remediation recommendations.
  • Track vulnerabilities through remediation and verify fixes.
  • Act as a trusted AppSec advisor to engineering and product teams.
  • Use expertise in OWASP Top 10 and common web application and API attack methods.
  • Support secure development practices, threat modeling, and design reviews.
  • Contribute to secure coding guidance, patterns, and best practices.

Conhecimentos

Application Security
Cloud Security
DAST/SAST
OWASP Top 10
Remediation Collaboration
AI Security Testing
Scripting (Python)

Ferramentas

Burp Suite
ZAP
Snyk
Semgrep
Checkmarx
Veracode

Descrição da oferta de emprego

If you are looking for a meaningful career where people work and act with passion, rethink the existing and always strive to find the best solution - you have come to the right place. We develop future technologies to relentlessly make supply chains better.

We are a leader in supply chain software solutions, helping organizations streamline operations, reduce costs, and improve efficiency.

Description

Infios is seeking a Security Analyst to join our Threat and Vulnerability Management (TVM) Team, who will be instrumental in building and maintaining security solutions within the organization to safeguard its systems and data.

This is a hands‑on role for a security professional who is passionate about identifying, analyzing, and remediating application and AI‑related security risks in close partnership with development and product teams.

You will play a key role in securing modern web applications, APIs, cloud‑native services, and emerging AI/LLM‑powered capabilities, while helping mature our secure development and AI security practices across the organization.

Key Responsibilities
Application Security & Vulnerability Management
  • Scan vulnerabilities using industry‑leading tools in applications and infrastructure.
  • Conduct and manage DAST, SAST, and software composition analysis (SCA) activities.
  • Analyze vulnerability scan results, validate findings, reduce false positives, and prioritize risk.
  • Collaborate directly with development teams to assess identified vulnerabilities and deliver precise, actionable remediation recommendations.
  • Track vulnerabilities through remediation and verify fixes.
  • Act as a trusted AppSec advisor to engineering and product teams.
  • Use expertise in OWASP Top 10 and common web application and API attack methods.
  • Support secure development practices, threat modeling, and design reviews.
  • Contribute to secure coding guidance, patterns, and best practices.
Automation & AI-Augmented Security
  • Leverage AI-powered tools (e.g., Copilot‑style tooling, AI‑assisted scanners) to:
    • Improve vulnerability analysis
    • Accelerate triage and reporting
    • Enhance testing efficiency
  • Identify opportunities to automate repetitive security tasks and workflows.
  • Contribute to continuous improvement of TVM and AppSec tooling and processes.
AI & LLM Security
  • Lead and support security testing of AI and LLM‑powered features across the organization.
  • Assess and test for risks outlined in the OWASP Top 10 for LLM Applications.
  • Help define and operationalize AI security testing strategies within the SDLC.
Required Qualifications
  • 5+ years of experience in Application Security, Product Security, or Vulnerability Management
  • Experience with cloud platforms like AWS, Azure, and OCI and CSPM tools (WIZ).
  • Strong hands‑on experience with DAST and SAST tools, Web Application and API Security Testing.
  • Deep understanding of OWASP Top 10 and Secure SDLC principles.
  • Excellent documentation and communication skills (both verbal and written).
  • Analytical problem‑solving skills and knowledge of application security architecture.
  • Experience working directly with software development teams on remediation.
  • Solid understanding of modern application architectures (REST APIs, microservices, cloud).
  • Familiarity with OWASP Top 10 for LLMs.
Preferred / Nice-to-Have
  • Experience testing or securing LLM‑powered applications in production.
  • Familiarity with security testing tools such as:
    • Burp Suite, ZAP, Snyk, Semgrep, Checkmarx, Veracode, or similar
  • Experience using AI to augment security testing or analysis.
  • Strong scripting or automation skills (Python, Bash, etc.).
  • Exposure to SOC 2 / ISO 27001 security controls related to AppSec.

At Infios, we're not just looking for employees; we're looking for partners in innovation, growth, and purpose. Meeting you where you are to create the future you need is at the core of who we are and what we do. Whether you're at the beginning of your career or a seasoned expert, we meet you on your journey, equipping you with the tools and opportunities to build the future you envision. Together, we will relentlessly work toward one common goal - making supply chains better.

At Infios, we're not just looking for employees; we're looking for partners in innovation, growth, and purpose. Meeting you where you are to create the future you need is at the core of who we are and what we do. Whether you're at the beginning of your career or a seasoned expert, we meet you on your journey, equipping you with the tools and opportunities to build the future you envision. Together, we will relentlessly work toward one common goal - making supply chains better.

We believe the future is better when supply chains work better.

We are an equal‑opportunity employer and committed to inclusion in the workplace.

At Infios, we believe that inclusion is a fundamental cornerstone of our success. We are committed to creating a safe and welcoming environment where every individual’s unique experiences and perspectives are valued—whether they look, think, move, believe, or love differently.

All qualified applicants will receive consideration for employment without regard to race, color, ethnicity, national origin, sex, sexual orientation, gender identity, marital status, pregnancy, religion, age, disability, veteran status, genetic information, or any other characteristic protected by law.

Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this role. If you require assistance or accommodation due to a disability during the recruiting process, please let us know at jobs@infios.com

Körber Supply Chain Software is now Infios.
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Software Engineer
Software Engineer

Infios • Brasil

Presencial
BRL 90 000 - 120 000
Senior Systems Developer
Senior Systems Developer

Infios • Blumenau

Híbrido
BRL 120 000 - 150 000
Inclusive workplace
Career growth opportunities
Remote work flexibility
Technical Support L1
Technical Support L1

Infios • Brasil

Presencial
Inclusive work environment
Opportunities for professional growth
Mid-Level Support Analyst II
Mid-Level Support Analyst II

Infios • Brasil

Presencial
Competitive compensation and benefits
Career progression opportunities
Collaborative work environment
Solution Consultant L3
Solution Consultant L3

Infios • Brasil

Presencial
Support Operations Analyst
Support Operations Analyst

Infios • Brasil

Presencial
Senior Software Engineer
Senior Software Engineer

Infios US, Inc. • Brasil

Teletrabalho
BRL 120 000 - 180 000
Equipped with tools for professional growth
Commitment to inclusion and diversity
Quality Engineer
Quality Engineer

Infios • Brasil

Presencial
BRL 90 000 - 140 000
Service Desk Analyst
Service Desk Analyst

Infios • Brasil

Presencial
Cloud Reliability Engineer
Cloud Reliability Engineer

Infios US, Inc. • Brasil

Presencial
BRL 120 000 - 150 000