Senior Information Security Analyst – AppSec

Jobtailor

São Paulo

Presencial

BRL 200 000 - 320 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Jobtailor is seeking an experienced Application Security Technical Lead in São Paulo to drive the Secure SDLC and integrate security from design through production. You will lead AppSec programs, establish secure standards, and mentor development squads to adopt best practices.

Responsibilities include analyzing vulnerabilities, prioritizing fixes by CVSS and business impact, and enhancing security controls in Azure DevOps and GitHub pipelines.

Qualificações

  • Strong experience in Application Security (AppSec).
  • Practical experience with Secure SDLC.
  • Solid knowledge of web and API vulnerability exploitation.
  • Experience with SAST and SCA tools.
  • Experience with Snyk, Checkmarx, Veracode, or equivalent tools.
  • Strong knowledge of OWASP Top 10 and OWASP API Security Top 10.
  • Knowledge of OWASP ASVS v2 and threat modeling (STRIDE/PASTA/ DREAD).
  • Experience with Azure DevOps and/or GitHub, CI/CD.
  • Knowledge of REST APIs, OAuth2, OIDC, JWT, and Keycloak.
  • Experience in secure code analysis and working with security teams.

Responsabilidades

  • Act as the technical lead for the AppSec program and Secure SDLC.
  • Define secure development standards and security gates.
  • Promote secure development culture via training and workshops.
  • Lead AppSec program and enhance security controls in pipelines.
  • Validate vulnerabilities using CVSS, context, and exploitability.
  • Analyze vulnerabilities in source code and reproduce proofs.

Conhecimentos

AppSec expertise
Secure SDLC
Vulnerability analysis
Threat modeling
Azure DevOps
GitHub
CI/CD
REST APIs
OAuth2
OIDC
JWT
Keycloak
SAST
SCA
RASP
DAST
IAST
OWASP Top 10
OWASP API Security Top 10
OWASP ASVS v2
Snyk
Checkmarx
Veracode
Kubernetes
Containers
SBOM

Ferramentas

GitHub
Keycloak
RASP
DAST
IAST
API Gateway Solutions

Descrição da oferta de emprego

  • Act as the technical lead for the Application Security program, driving continuous evolution of the Secure SDLC and ensuring security is integrated from solution design through production deployment.
  • Define secure development standards, Security Gates, Security by Design, Security by Default, Threat Modeling, minimum security requirements, and Security Champions; support Security Architecture in adopting best practices.
  • Promote a secure development culture through training, workshops, and technical support to development squads.
  • Technically lead the Application Security (AppSec) program, ensuring continuous improvement of the Secure SDLC and enhancing security controls in development pipelines (Azure DevOps and GitHub).
  • Validate vulnerabilities identified by tools, prioritizing based on CVSS, business context, and exploitability.
  • Technically analyze vulnerabilities found in source code.
  • Reproduce vulnerabilities when necessary to provide technical proof.
Requirements
  • Strong experience in Application Security (AppSec).
  • Practical experience with Secure SDLC.
  • Solid knowledge of web and API vulnerability exploitation.
  • Experience with SAST and SCA tools.
  • Experience with Snyk, Checkmarx, Veracode, or equivalent tools.
  • Strong knowledge of OWASP Top 10.
  • Strong knowledge of OWASP API Security Top 10.
  • Knowledge of OWASP ASVS v2.
  • Experience in Threat Modeling (STRIDE, PASTA and/or DREAD).
  • Experience with Azure DevOps and/or GitHub.
  • Experience with CI/CD.
  • Knowledge of Git.
  • Knowledge of REST APIs.
  • Knowledge of OAuth2.
  • Knowledge of OIDC.
  • Knowledge of JWT.
  • Knowledge of Keycloak or equivalent solutions.
  • Experience in secure code analysis.
  • Good communication skills with development teams.
  • Advanced English.
  • Nice to have / Differentials:
  • Experience with RASP.
  • Experience with DAST.
  • Experience with IAST.
  • Experience with API Gateway solutions (Apigee, Kong, AWS API Gateway, Azure API Management).
  • Experience with Salt Security.
  • Experience with Kubernetes.
  • Experience with containers.
  • Experience with supply chain security.
  • Knowledge of SBOM.
  • Knowledge of Sigstore/Cosign.
  • Experience in financial environments.
  • Knowledge of NIST SSDF.
  • Knowledge of OWASP SAMM.
  • Knowledge of LGPD (Brazilian Data Protection Law).
Core Competencies

Demonstrates expertise in Application Security (AppSec) with a focus on Secure SDLC, vulnerability analysis, and threat modeling. Proficient in utilizing security tools and frameworks to enhance security practices within development pipelines.

Highest-signal resume keywords
  • Application Security (AppSec)
  • Secure SDLC
  • Vulnerability Analysis
  • Threat Modeling
  • Azure DevOps
ATS Optimization Keywords
Hard Skills
  • SAST Tools
  • SCA Tools
  • OWASP Top 10
  • OWASP API Security Top 10
  • OWASP ASVS v2
  • Secure Code Analysis
  • REST APIs
  • OAuth2
  • OIDC
  • JWT
Soft Skills
  • Good Communication Skills
Industry Keywords
  • NIST SSDF
  • OWASP SAMM
  • LGPD
  • Financial Environments
  • Supply Chain Security
Tools & Technologies
  • Snyk
  • Checkmarx
  • Veracode
  • GitHub
  • CI/CD
  • Keycloak
  • RASP
  • DAST
  • IAST
  • API Gateway Solutions
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Analista de Segurança da Informação Pleno – Desenvolvimento Seguro
Analista de Segurança da Informação Pleno – Desenvolvimento Seguro

Jobtailor • Barueri

Presencial
BRL 180 000 - 260 000
Mid-Level Information Security Analyst
Mid-Level Information Security Analyst

Jobtailor • São Paulo

Presencial
BRL 90 000 - 150 000
Senior Project Security Analyst
Senior Project Security Analyst

Jobtailor • São Paulo

Presencial
BRL 180 000 - 240 000
Senior AppSec / DevSecOps
Senior AppSec / DevSecOps

Jobtailor • São Paulo

Presencial
BRL 180 000 - 260 000
Senior Information Security Analyst, Pentester
Senior Information Security Analyst, Pentester

Jobtailor • Barueri

Presencial
BRL 120 000 - 180 000
Senior Information Security Analyst
Senior Information Security Analyst

Jobtailor • São Paulo

Presencial
BRL 120 000 - 190 000
COE Specialist – DevSecOps
COE Specialist – DevSecOps

Jobtailor • São Paulo

Presencial
BRL 240 000 - 350 000
Offensive Security Specialist
Offensive Security Specialist

Jobtailor • São Paulo

Presencial
BRL 180 000 - 300 000
Security Engineer, AppSec
Security Engineer, AppSec

Jobtailor • São Paulo

Híbrido
BRL 120 000 - 240 000
Solutions Architecture Specialist – Cyber Security
Solutions Architecture Specialist – Cyber Security

Jobtailor • São Paulo

Presencial
BRL 240 000 - 360 000