Security Engineer, AppSec

Jobtailor

São Paulo

Presencial

BRL 120 000 - 240 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Jobtailor in São Paulo is seeking an experienced Application Security professional to own the security lifecycle for software, perform threat modeling, and drive secure development practices across CI/CD pipelines.

You will manage SAST/DAST/SCA tooling, align with OWASP ASVS and security standards, and shape remediation efforts with engineering teams.

Qualificações

  • Hands-on experience in Application Security across the full SDLC.
  • Experience with threat modeling and architecture review of applications and APIs.
  • Proficiency with SAST, DAST and SCA, and integrating these tools into CI/CD pipelines.
  • Knowledge of OWASP ASVS, OWASP Top 10 and SAMM.
  • Familiarity with microservices, containers and cloud security.

Responsabilidades

  • Implement security controls across the development lifecycle, from design to deployment, as part of the AppSec program.
  • Conduct Threat Modeling sessions with product squads to identify architectural risks before implementation.
  • Manage and optimize SAST, DAST and SCA tools, prioritizing findings based on real business risk.
  • Maintain the Security Champions program, empowering developers to be the first line of defense.
  • Validate the architecture of new projects and API integrations, ensuring compliance with OWASP ASVS and internal standards.
  • Manage the vulnerability remediation workflow with engineering, addressing root causes rather than just symptoms.
  • Translate technical risks into business impact for Product Owners and stakeholders. Automate security validations in CI/CD pipelines and maintain metrics such as remediation SLAs and defect density.

Conhecimentos

Application Security
Threat Modeling
CI/CD
Automation
Cloud Security
Vulnerability Management
Security in SDLC

Ferramentas

Docker
Kubernetes
AWS
GCP
Azure

Descrição da oferta de emprego

  • Implement security controls across the development lifecycle, from design to deployment, as part of the AppSec program.
  • Conduct Threat Modeling sessions with product squads to identify architectural risks before implementation.
  • Manage and optimize SAST, DAST and SCA tools, prioritizing findings based on real business risk rather than only isolated technical severity.
  • Maintain the Security Champions program, empowering developers to be the first line of defense.
  • Validate the architecture of new projects and API integrations, ensuring compliance with OWASP ASVS and internal standards.
  • Manage the vulnerability remediation workflow with engineering, addressing root causes rather than just symptoms.
  • Translate technical risks into business impact for Product Owners and stakeholders. Automate security validations in CI/CD pipelines and maintain metrics such as remediation SLAs and defect density.
Requirements
  • Hands-on experience in Application Security across the full SDLC.
  • Experience with threat modeling and architecture review of applications and APIs. Proficiency with SAST, DAST and SCA, and integrating these tools into CI/CD pipelines.
  • Knowledge of OWASP ASVS, OWASP Top 10 and SAMM.
  • Familiarity with microservices, containers (Docker, Kubernetes) and cloud security (AWS, GCP or Azure).
  • Strong development or automation background, with the ability to propose scalable solutions as code.
  • Availability for hybrid work: must attend our office in the Morumbi area of São Paulo once a month for four consecutive days, usually during the last or first week of the month (Creditas in Person).
Core Competencies

Demonstrates expertise in Application Security throughout the software development lifecycle, with a strong focus on threat modeling, vulnerability management, and compliance with security standards such as OWASP ASVS. Proficient in integrating security tools into CI/CD pipelines and translating technical risks into business impacts.

Highest-signal resume keywords
  • Application Security
  • Threat Modeling
  • SAST, DAST, SCA
  • OWASP ASVS
  • Cloud Security
ATS Optimization Keywords
Hard Skills
  • Application Security
  • Threat Modeling
  • SAST
  • DAST
  • SCA
  • OWASP ASVS
  • Microservices
  • Containers
  • Automation
  • CI/CD
Soft Skills
  • Communication
  • Collaboration
  • Problem-Solving
Industry Keywords
  • Security Champions Program
  • Vulnerability Remediation
  • Architectural Risks
  • Defect Density
  • Remediation SLAs
Tools & Technologies
  • Docker
  • Kubernetes
  • AWS
  • GCP
  • Azure
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Analista de Segurança da Informação Pleno – Desenvolvimento Seguro
Analista de Segurança da Informação Pleno – Desenvolvimento Seguro

Jobtailor • Barueri

Presencial
BRL 180 000 - 260 000
Tech Lead – Cyber Security
Tech Lead – Cyber Security

Jobtailor • Belo Horizonte

Presencial
BRL 180 000 - 240 000
Analista de Segurança da Informação Sênior
Analista de Segurança da Informação Sênior

Jobtailor • São Paulo

Presencial
BRL 120 000 - 190 000
Engenheiro de Cybersegurança Sênior
Engenheiro de Cybersegurança Sênior

Jobtailor • São Paulo

Presencial
BRL 180 000 - 260 000
Especialista em Engenharia de Segurança da Informação
Especialista em Engenharia de Segurança da Informação

Jobtailor • São Paulo

Presencial
BRL 180 000 - 260 000
Senior Information Security Analyst – AppSec
Senior Information Security Analyst – AppSec

Jobtailor • São Paulo

Presencial
BRL 200 000 - 320 000
Appsec | Security Analyst | Mid e Senior(Remote)
Appsec | Security Analyst | Mid e Senior(Remote)

AI/R • Brasil

Presencial
BRL 120 000 - 160 000
Senior Software Architect
Senior Software Architect

Jobtailor • São Paulo

Híbrido
BRL 180 000 - 260 000
Senior Analista de Segurança em TI
Senior Analista de Segurança em TI

Jobtailor • Florianópolis

Presencial
BRL 134 000 - 223 000
Analista de Segurança da Informação Sênior
Analista de Segurança da Informação Sênior

GOK | Digital Innovation • Brasil

Presencial
BRL 180 000 - 280 000