Senior Application Security Engineer - 100% REMOTE

Cibernos

Brasil

Presencial

BRL 180 000 - 300 000

Tempo integral

Há 2 dias
Torna-te num dos primeiros candidatos

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Cibernos is seeking a Senior Application Security Engineer to protect a growing portfolio of cloud-based applications. You will lead Secure Software Development practices, advise developers on secure coding, and oversee SAST/DAST across the SDLC.

You will work with AWS security, Kubernetes, and Docker, perform threat modelling, manage penetration testing and bug bounty programs, and help maintain ISO 27001 and SOC 2 compliance. Excellent communication and analytical skills required.

Qualificações

  • 5+ years of experience in Application Security.
  • CISSP certification is required.
  • Proficiency in PHP or Java.
  • Strong knowledge of OWASP Top 10, Web App Security, API Security, and Threat Modelling.
  • Experience with Cloud Native environments, Kubernetes and Docker.
  • Knowledge of AWS Security.
  • Experience with DevSecOps and CI/CD methodologies.
  • Ability to interpret penetration testing reports and manage remediation.
  • Knowledge of SAST/DAST and application security tools.
  • Understanding of vulnerability management, threat detection, incident response, and general cybersecurity principles.
  • Knowledge of ISO 27001 and SOC 2.

Responsabilidades

  • Drive Secure Software Development lifecycle across development and QA teams.
  • Advise developers on application security, secure coding, and OWASP Top 10.
  • Integrate SAST, DAST and vulnerability analysis tools throughout SDLC/CI-CD pipelines.
  • Analyse security tool findings and assist remediation with developers.
  • Conduct security-focused code reviews and identify root causes.
  • Participate in threat modelling and security risk assessments early in design.
  • Oversee the penetration testing programme and coordinate external providers.
  • Manage vulnerabilities from bug bounty programme and prioritize fixes.
  • Collaborate with external SOC to investigate incidents and use Microsoft Sentinel.
  • Maintain ISO 27001 ISMS and SOC 2 Type II compliance.

Conhecimentos

Application Security
Cybersecurity
DevSecOps
Threat Modelling
Secure Coding
SAST/DAST
Vulnerability Management
Cloud Native
AWS Security
Incident Response

Formação académica

CISSP certification
Bachelor's degree in Computer Science / Engineering / IT

Ferramentas

Kubernetes
Docker
CI/CD
Penetration Testing
Microsoft Sentinel

Descrição da oferta de emprego

We are looking for a Senior Application Security Engineer to join the security team and play a key role in protecting a growing portfolio of cloud-based applications and services.

Key Responsibilities
  • Drive and oversee the implementation of Secure Software Development best practices across development and QA teams.
  • Advise developers and technical teams on application security, secure coding, and the OWASP Top 10.
  • Integrate and manage SAST, DAST, and vulnerability analysis tools throughout the SDLC and CI/CD pipelines.
  • Analyse security tool findings and help developers understand and effectively remediate vulnerabilities.
  • Conduct security-focused code reviews, identifying vulnerabilities, root causes, and potential attack vectors.
  • Participate in threat modelling and security risk assessments from the early stages of application design.
  • Manage the penetration testing programme, coordinating external providers, reviewing reports, and following up on remediation activities.
  • Manage and assess vulnerabilities identified through the bug bounty programme, prioritising findings according to risk and ensuring timely remediation.
  • Work closely with the external SOC to investigate and resolve security incidents, particularly application-level vulnerabilities tracked through Microsoft Sentinel.
  • Contribute to maintaining the ISO 27001 ISMS and SOC 2 Type II compliance.
  • Contribute to security risk management and maintain the security risk register.
  • Act as a trusted point of contact for clients and stakeholders regarding Application Security matters.
  • Keep IT and senior management informed about security risks, vulnerabilities, progress, and key initiatives.
Requirements
  • 5+ years of experience in Application Security, Cybersecurity, DevSecOps, or a similar role.
  • CISSP certification.
  • Practical experience with at least one programming language, preferably PHP or Java.
  • Bachelor's degree in Computer Science, Engineering, IT, or a related field. Professional experience will be considered highly valuable.
  • Strong knowledge of OWASP Top 10, Web Application Security, API Security, and Threat Modelling.
  • Experience with Cloud Native environments, particularly Kubernetes and Docker.
  • Knowledge of AWS Security.
  • Experience with DevSecOps and CI/CD methodologies and practices.
  • Ability to interpret penetration testing reports and manage vulnerability remediation.
  • Knowledge of SAST/DAST and application security tools.
  • Understanding of vulnerability management, threat detection, incident response, and general cybersecurity principles.
  • Knowledge of ISO 27001 and/or SOC 2.
  • Strong analytical and problem-solving skills with excellent attention to detail.
  • Excellent communication skills and the ability to work effectively with both technical and non-technical stakeholders.
Nice to Have
  • Hands-on experience conducting penetration testing.
  • Certifications such as CEH, OSCP, or CREST.
  • Experience with Bug Bounty programmes.
  • Experience working with development teams in Agile/DevOps environments.
  • Experience working in regulated environments or with ISO 27001 / SOC 2 requirements.
Ready for your next challenge?

Join a project where you will have the opportunity to strengthen application security, work with advanced cloud and security technologies, and make a real impact across the software development lifecycle.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Senior/Lead AppSec Engineer ID71672
Senior/Lead AppSec Engineer ID71672

AgileEngine, LLC. • Brasília

Presencial
BRL 180 000 - 290 000
Growth without limits
Competitive compensation
Flexibility — 100% remote
+3
Senior/Lead AppSec Engineer ID71672
Senior/Lead AppSec Engineer ID71672

AgileEngine, LLC. • Salvador

Teletrabalho
BRL 180 000 - 320 000
Growth without limits
Competitive compensation
Flexibility: 100% remote with flexible
+3
Application Security Engineer
Application Security Engineer

Velozient • Brasil

Teletrabalho
BRL 421 000 - 527 000
15 days PTO
1 floating day
3 sick days
+1
Mid-Level Information Security Analyst
Mid-Level Information Security Analyst

Jobtailor • São Paulo

Presencial
BRL 90 000 - 150 000
Senior Information Security Analyst – AppSec
Senior Information Security Analyst – AppSec

Jobtailor • São Paulo

Presencial
BRL 200 000 - 320 000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

AgileEngine • Brasil

Híbrido
BRL 456 000 - 609 000
Professional growth
Competitive compensation
Flextime
+1
Infrastructure Security Engineer (AWS) - Remote
Infrastructure Security Engineer (AWS) - Remote

Cibernos • Brasil

Presencial
BRL 140 000 - 210 000
Senior AppSec / DevSecOps
Senior AppSec / DevSecOps

Jobtailor • São Paulo

Presencial
BRL 180 000 - 260 000
Senior Project Security Analyst
Senior Project Security Analyst

Jobtailor • São Paulo

Presencial
BRL 180 000 - 240 000
Senior Security Consultant, Application Security
Senior Security Consultant, Application Security

IOActive, Inc. • Brasil

Híbrido
BRL 380 000 - 887 000
Competitive compensation
Access to world-class technical teams
Flexibility to work remotely
+1