Senior AppSec / DevSecOps

Jobtailor

São Paulo

Presencial

BRL 180 000 - 260 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Jobtailor is seeking an experienced Application Security Lead in São Paulo to drive threat modeling, secure design, and AI security across the development lifecycle. The role requires hands-on expertise in SAST/DAST/SCA tools, API protection, and cloud security, with a focus on shifting security left and fostering a security-aware culture.

You will collaborate with engineering and architecture teams, lead security initiatives for AI, and define controls to mitigate risks in AI-enabled

Qualificações

  • Experience with application security tools (SAST, SCA, DAST).
  • Experience integrating security into CI/CD pipelines.
  • Knowledge of vulnerability management and tracking tools.
  • Experience with API protection and API security concepts.
  • Familiarity with AI tools in development and AI risk in apps.
  • Strong knowledge of OWASP frameworks and secure coding practices.
  • Bachelor’s degree and relevant certifications are a plus.

Responsabilidades

  • Act as technical reference for Application Security and threat modeling.
  • Lead Threat Modeling sessions (STRIDE) for new initiatives.
  • Define Secure Design practices aligned with OWASP ASVS, SAMM, Top 10.
  • Collaborate with development teams to shift security left.
  • Lead AI-related security initiatives across the SDLC.
  • Identify and mitigate risks in AI-enabled applications.
  • Support safe use of AI tools and promote secure coding.
  • Define API security controls and privilege management.
  • Develop and maintain security guidelines, playbooks, and training.

Conhecimentos

Threat Modeling
AppSec/DevSecOps
OWASP Top 10
Secure Design
AI Security
Risk Assessment
CI/CD Integration
Threat Modeling (STRIDE)
Security Architecture
Vulnerability Management
Cloud Security
JavaScript/Java

Formação académica

Bachelor’s degree in Information Technology or related fields

Ferramentas

Fortify
Checkmarx
Veracode
Snyk
OWASP Dependency-Check
WebInspect
Azure DevOps
GitHub Actions
Jira
OAuth2/OpenID Connect/JWT

Descrição da oferta de emprego

Responsibilities
  • Act as the technical reference for Application Security, with a focus on threat modeling and security by design
  • Lead Threat Modeling sessions (e.g., STRIDE) for new initiatives, architectural changes and integrations, identifying risks early
  • Define and evolve Secure Design practices, ensuring adherence to frameworks such as OWASP ASVS, SAMM and Top 10
  • Work closely with development and software architecture teams to incorporate security from the outset (shift-left)
  • Lead security initiatives related to the use of Artificial Intelligence throughout the development lifecycle
  • Identify and mitigate risks in applications that use AI (e.g., prompt injection, data leakage, model abuse)
  • Support the safe use of AI-based tools (e.g., copilots, code generation tools)
  • Apply best practices based on emerging guidance such as OWASP Top 10 for LLM Applications
  • Explore the use of AI to scale AppSec activities (e.g., vulnerability triage, automated analysis)
  • Define security requirements and standards for applications, APIs and services
  • Ensure security requirements are clear, prioritized and measurable
  • Contribute to defining controls for API security (authentication, authorization, rate limiting, etc.)
  • Support contextualized vulnerability management
  • Prioritize risks considering technical and business impact
  • Work with teams to define remediation strategies
  • Contribute to the evolution of the Application Security maturity model
  • Structure and evolve practices aligned with OWASP SAMM
  • Create and maintain guidelines, standards and playbooks
  • Promote a security culture and strengthen security awareness across the organization
  • Act as the technical Application Security reference for development teams
  • Lead enablement initiatives (workshops, trainings and dissemination of best practices)
Requirements
  • Experience with application security tools:
    • SAST (e.g., Fortify, Checkmarx, Veracode, etc.)
    • SCA (e.g., Snyk, OWASP Dependency-Check)
    • DAST (e.g., WebInspect)
    • ASPM platforms
  • Experience integrating security into CI/CD pipelines (Azure DevOps, GitHub Actions or similar)
  • Knowledge of vulnerability management and tracking tools (e.g., SSC Fortify, Jira)
  • Experience with API protection:
    • API Gateway, WAF, Rate Limiting
  • Familiarity with AI tools and platforms applied to development (e.g., copilots, code assistants, AI agents)
  • Strong knowledge of Application Security (AppSec) and DevSecOps
  • Hands‑on experience with:
    • Threat Modeling (e.g., STRIDE, abuse cases)
    • Secure Design / Secure Architecture
  • Deep knowledge of major OWASP frameworks:
    • OWASP Top 10
    • OWASP API Security Top 10
    • OWASP ASVS
    • OWASP SAMM
  • API security knowledge:
    • OAuth2, OpenID Connect, JWT
    • Authentication, authorization and access control
  • Development knowledge:
    • Languages such as JavaScript/Node.js, Java or similar
    • Secure coding best practices
    • Knowledge of cloud environments (Azure, AWS or GCP) and distributed architectures
  • AI security (relevant differential):
    • Interest in applying AI to scale AppSec (automation, analysis, etc.)
    • Knowledge or experience with risks in AI-enabled applications:
      • Prompt Injection
      • Data Leakage
      • Model Abuse / Misuse
      • Familiarity with OWASP Top 10 for LLM Applications
    • Ability to assess risks and propose controls for solutions that use AI
  • Bachelor’s degree in Information Technology or related fields
  • Desired certifications:
    • CSSLP (Certified Secure Software Lifecycle Professional)
    • GWAPT / OSCP / OSWE
    • AZ-500, AWS Security Specialty or similar (cloud security)
    • DevSecOps or AppSec-related certifications
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Senior Information Security Analyst – AppSec
Senior Information Security Analyst – AppSec

Jobtailor • São Paulo

Presencial
BRL 200 000 - 320 000
Mid-Level Information Security Analyst
Mid-Level Information Security Analyst

Jobtailor • São Paulo

Presencial
BRL 90 000 - 150 000
Senior Security Analyst
Senior Security Analyst

Jobtailor • São Paulo

Presencial
BRL 120 000 - 240 000
Senior Project Security Analyst
Senior Project Security Analyst

Jobtailor • São Paulo

Presencial
BRL 180 000 - 240 000
Security Engineer, AppSec
Security Engineer, AppSec

Jobtailor • São Paulo

Híbrido
BRL 120 000 - 240 000
Analista de Segurança da Informação Pleno – Desenvolvimento Seguro
Analista de Segurança da Informação Pleno – Desenvolvimento Seguro

Jobtailor • Barueri

Presencial
BRL 180 000 - 260 000
Offensive Security Specialist
Offensive Security Specialist

Jobtailor • São Paulo

Presencial
BRL 180 000 - 300 000
Senior Information Security Analyst, Pentester
Senior Information Security Analyst, Pentester

Jobtailor • Barueri

Presencial
BRL 120 000 - 180 000
Cybersecurity Specialist – DevSecOps
Cybersecurity Specialist – DevSecOps

Jobtailor • São Paulo

Presencial
BRL 180 000 - 240 000
Senior Information Security Analyst – Data Protection & AI
Senior Information Security Analyst – Data Protection & AI

Jobtailor • São Paulo

Presencial
BRL 120 000 - 180 000