Job Description
Legrand has an exciting opportunity for a Security Engineer III to join the ZPE Systems Team in Blumenau, BR. We are seeking a Security Engineer III to drive application and product security across the ZPE Cloud and Nodegrid product lines. Based in Blumenau and working with engineering teams in Brazil, the United States, and Europe, this role embeds security into the software development lifecycle, facilitates threat modeling and secure design review, and works directly with development teams to identify and remediate vulnerabilities before they reach customers. The primary focus is cloud and web application security, with growing exposure to embedded product security.
Responsibilities
Main Responsibilities:
Application & Product Security
- Conduct security code reviews and provide practical remediation guidance to development teams
- Build out, tune, and maintain the SAST, DAST, SCA, and secrets scanning toolchain within CI/CD pipelines
- Triage vulnerability findings, assign severity, and drive remediation to closure with owning teams
- Develop secure coding guidelines, reusable patterns, and developer security training material
- Manage software supply chain risk, including SBOM generation and CVE triage and response
- Scope and coordinate third-party penetration tests; perform targeted internal assessments
Secure Design & Architecture
- Facilitate threat modeling for new features, services, and system designs
- Perform security design reviews and document mitigations and accepted risks
- Develop and maintain security reference architectures and reusable design patterns for product teams
- Contribute to the design of authentication, authorization, and secrets management for product services
- Define encryption and key management requirements for product data at rest and in transit
- Evaluate and recommend application and cloud security tooling
Compliance Support
- Implement and evidence the technical controls required by ISO 27001, SOC 2, and the EU Cyber Resilience Act
- Provide technical input to customer security questionnaires and RFI/RFP responses
Leadership & Collaboration
- Mentor engineers on secure development practices and help establish a security champions program
- Contribute to the product security roadmap with Product and Engineering leadership
- Act as the security point of contact in design and architecture discussions
- Conduct regular Knowledge Sharing Sessions (KSS) on security topics and emerging threats
- Communicate effectively across Brazil, US, and EU time zones, in English, written and verbal
Profile
QUALIFICATIONS
- 5+ years in security engineering or software engineering, with at least 2 years focused on application or product security
- Professional working proficiency in English, written and spoken, sufficient for customer-facing documentation and cross-region collaboration; fluent Portuguese
- Demonstrated experience performing security code review across more than one language
- Proven experience integrating and tuning security tooling within CI/CD pipelines
- Experience with threat modeling and secure design review
- Familiarity with at least one major compliance framework (ISO 27001 or SOC 2) from a control implementation perspective
- Experience producing technical security documentation for internal and customer audiences
- Availability for occasional international travel
Desirable (not Required)
- Experience helping establish or mature an application security practice
- Experience with embedded or hardware product security: secure boot, TPM, firmware signing, SBOM
- Familiarity with EU Cyber Resilience Act, FIPS 140-3, or Common Criteria obligations
- Certifications such as CompTIA Security+, CISSP, OSCP, CKS, or a cloud security certification; sponsorship available
- Contributions to open-source security projects, security research, or conference speaking
Skills/Knowledge/Abilities
Technical Skills
- Reading and reviewing application code in Go, Python, or similar; scripting for security automation
- Cloud security controls and architecture on at least one major provider; GCP preferred
- Application authentication and authorization: OAuth 2.0, OIDC, SAML, RBAC
- Applied cryptography: TLS, encryption, hashing, PKI, certificate and key management
- Container and Kubernetes security, IaC scanning, and policy as code
- CI/CD platforms such as GitLab CI, Jenkins, GitHub Actions, or ArgoCD
- Practical experience with SAST, DAST, SCA, and secrets scanning tooling
Knowledge Areas
- OWASP Top 10, OWASP ASVS, and common web and API vulnerability classes
- Threat modeling frameworks: STRIDE, PASTA, MITRE ATT&CK
- Secure SDLC practices and DevSecOps methodologies
- Software supply chain security: SBOM, dependency management, CVE triage
- Security compliance and regulatory requirements: NIST CSF, CIS Controls, ISO 27001, SOC 2, LGPD
Abilities
- Explain complex security concepts clearly to technical and non-technical audiences
- Influence engineering teams and drive remediation without direct authority
- Balance security requirements against business needs and delivery timelines
- Work autonomously across distributed teams and time zones with strong ownership
About Legrand
ABOUT US
Legrand is the global specialist in electrical and digital building infrastructures. Our comprehensive offering of solutions for residential, commercial, and data center markets makes us a benchmark for customers worldwide. We harness technological and societal trends with lasting impacts on buildings with the purpose of improving life by transforming the spaces where people live, work, and meet with electrical and digital infrastructures and connected solutions that are simple, innovative, and sustainable. Legrand is a global, publicly traded company listed on the Euronext (Legrand SA EPA: LR). For more information, visit www.legrandgroup.com/en
About Legrand North And Central America
Legrand, North & Central America (LNCA) is a leader in the AV, Lighting & Controls, Electrical, and Data Center markets. LNCA offers comprehensive medical, dental, and vision coverage, as well as distinctive benefits like a high employer 401K match, paid time off (PTO) and holiday pay, short-term and long-term disability benefit plans, above-benchmark paid maternity and parental leave, bonus opportunities in accordance with the Company’s incentive plans, paid time off to volunteer, and an active/growing Employee Resource Group network. For more information, visit legrand.us
About Legrand’s Data Center Power And Control Division
The industry-leading brands of Approved Networks, Ortronics, Raritan, Server Technology, and Starline empower Legrand’s Data, Power & Control to produce innovative solutions for data centers, building networks, and facility infrastructures. Our division designs, manufactures, and markets world-class products for a more productive and sustainable future. The exceptional reliability of our technologies results from decades of proven performance and a dedication to research and development.
http://www.legrand.us
http://www.youtube.com/legrandna
http://www.linkedin.com/company/44580
http://twitter.com/legrandNA
Equal Opportunity Employer