- Implement security controls across the development lifecycle, from design to deployment, as part of the AppSec program.
- Conduct Threat Modeling sessions with product squads to identify architectural risks before implementation.
- Manage and optimize SAST, DAST and SCA tools, prioritizing findings based on real business risk rather than only isolated technical severity.
- Maintain the Security Champions program, empowering developers to be the first line of defense.
- Validate the architecture of new projects and API integrations, ensuring compliance with OWASP ASVS and internal standards.
- Manage the vulnerability remediation workflow with engineering, addressing root causes rather than just symptoms.
- Translate technical risks into business impact for Product Owners and stakeholders. Automate security validations in CI/CD pipelines and maintain metrics such as remediation SLAs and defect density.
Requirements
- Hands-on experience in Application Security across the full SDLC.
- Experience with threat modeling and architecture review of applications and APIs. Proficiency with SAST, DAST and SCA, and integrating these tools into CI/CD pipelines.
- Knowledge of OWASP ASVS, OWASP Top 10 and SAMM.
- Familiarity with microservices, containers (Docker, Kubernetes) and cloud security (AWS, GCP or Azure).
- Strong development or automation background, with the ability to propose scalable solutions as code.
- Availability for hybrid work: must attend our office in the Morumbi area of São Paulo once a month for four consecutive days, usually during the last or first week of the month (Creditas in Person).
Core Competencies
Demonstrates expertise in Application Security throughout the software development lifecycle, with a strong focus on threat modeling, vulnerability management, and compliance with security standards such as OWASP ASVS. Proficient in integrating security tools into CI/CD pipelines and translating technical risks into business impacts.
Highest-signal resume keywords
- Application Security
- Threat Modeling
- SAST, DAST, SCA
- OWASP ASVS
- Cloud Security
ATS Optimization Keywords
Hard Skills
- Application Security
- Threat Modeling
- SAST
- DAST
- SCA
- OWASP ASVS
- Microservices
- Containers
- Automation
- CI/CD
Soft Skills
- Communication
- Collaboration
- Problem-Solving
Industry Keywords
- Security Champions Program
- Vulnerability Remediation
- Architectural Risks
- Defect Density
- Remediation SLAs
Tools & Technologies
- Docker
- Kubernetes
- AWS
- GCP
- Azure