Job Search and Career Advice Platform

Ativa os alertas de emprego por e-mail!

SR Application Security Engineer - Argentina, Brazil, Spain, Romania & Uruguay

dLocal

Brasil

Teletrabalho

BRL 120.000 - 160.000

Tempo integral

Hoje
Torna-te num dos primeiros candidatos

Cria um currículo personalizado em poucos minutos

Consegue uma entrevista e ganha mais. Sabe mais

Resumo da oferta

A global fintech company in Brazil is seeking a Security Engineer to enhance their software assurance model. You will implement security designs, conduct reviews, and lead training initiatives. The ideal candidate has over 5 years of experience, strong programming skills in languages like Java or Python, and familiarity with various security frameworks. Enjoy a remote-first work culture with flexible schedules and numerous learning opportunities.

Serviços

Remote work flexibility
Fintech dynamic environment
Premium Coursera subscription
Referral bonus program
Social budget for team-building

Qualificações

  • Experience in security design reviews for new features and product releases.
  • Perform code reviews and advise developers on remediation techniques.
  • Facilitate internal training on security topics.

Responsabilidades

  • Implement a security assurance model in delivery pipeline.
  • Perform security design reviews.
  • Triage and respond to security inquiries.

Conhecimentos

Strong proficiency in programming languages like Java, GoLang, Python, NodeJS/TypeScript
5+ years of experience in software assurance model
Ability to manually fix security flaws
Experience designing secure web services and APIs
Familiarity with threat modeling frameworks
Familiarity with OWASP verification guidelines
Experience with security tools like Burp Suite, Qualys
Knowledge of SAST/DAST/IAST/SCA security sensors
In-depth knowledge of application security frameworks
Familiarity with Cloud platforms (AWS preferred)
Ability to lead teams in security problem resolution
Experience securing LLMs and generative AI applications

Ferramentas

Burp Suite
Tenable
Github
ECS/EKS
Descrição da oferta de emprego
Why should you join dLocal?

dLocal enables the biggest companies in the world to collect payments in 40 countries in emerging markets. Global brands rely on us to increase conversion rates and simplify payment expansion effortlessly. As both a payments processor and a merchant of record where we operate, we make it possible for our merchants to make inroads into the world’s fastest-growing, emerging markets.

By joining us you will be a part of an amazing global team that makes it all happen, in a flexible, remote-first dynamic culture with travel, health and learning benefits, among others. Being a part of dLocal means working with 1000+ teammates from 30+ different nationalities and developing an international career that impacts millions of people’s daily lives. We are builders, we never run from a challenge, we are customer-centric, and if this sounds like you, we know you will thrive in our team.

What will I be doing?
  • Implement a software assurance model designed to address security defects early in the delivery pipeline
  • Perform security design reviews for new features and product releases
  • Perform code reviews and advise developers on remediation techniques
  • Design controls to detect and respond to common attacks on our platform
  • Tech talks in high technical level to engineers
  • Triage and respond to external inquiries around security vulnerabilities
  • Facilitate internal training on various security topics to raise awareness and interest
What skills will I need to have?
  • Strong proficiency in at least one programming language like Java, goLang, Python and/or NodeJS/TypeScript and also knowledge in any scripting languages
  • 5+ years of hands‑on experience working with developers in building a software assurance model
  • Demonstrate the ability to manually fix/mitigate security flaws on web applications and APIs code-level
  • Experience designing secure web services, APIs and microservice architectures
  • Familiarity with threat modeling frameworks in cloud‑base environments (OWASP, STRIDE, MITRE, etc)
  • Familiarity with OWASP verification guidelines (ASVS), OWASP Top 10s (web, API, LLM) and NIST special publications
  • Experience with application/development security tools, including but not limited to: Burp Suite, Qualys/WAS (Tenable or similar), Apiiro (Wiz, GHAS, or similar), Github (Gitlab, Bitbucket or similar), ECS/EKS, Github Actions, etc
  • Familiarity with the implementation and maintenance of SAST/DAST/IAST/SCA security sensors in a development pipeline
  • In‑depth knowledge of OWASP10, SANS25 and other world‑known application security frameworks
  • Understanding of a complete SDLC and how to make it secured (S‑SDLC)
  • Familiarity with Cloud platforms (AWS preferably)
  • Ability to lead people to problem resolution when it comes to Security (Integrate teams, especially the Engineering Team)
  • Experience on how to secure LLMs and generative AI applications
Will be considered a plus:
  • Certified in any related security development certifications like CSSLP, CASE or others
  • Exposure to PCI‑DSS, ISO27001 and/or SOC2 framework or any other relevant security standard will be valued
  • Extensive knowledge of security architectures, both monoliths and microservices, including how they are developed and operate at scale
  • Have had developed a personal or enterprise software/script with focus on security (exploitation of vulnerabilities, hardening automation, API integration for security
What do we offer?
  • Remote work: work from anywhere or one of our offices around the globe!*
  • Flexibility: we have flexible schedules and we are driven by performance.
  • Fintech industry: work in a dynamic and ever‑evolving environment, with plenty to build and boost your creativity.
  • Referral bonus program: our internal talents are the best recruiters - refer someone ideal for a role and get rewarded.
  • Learning & development: get access to a Premium Coursera subscription.
  • Language classes: we provide free English, Spanish, or Portuguese classes.
  • Social budget: you'll get a monthly budget to chill out with your team (in person or remotely) and deepen your connections!
  • dLocal Houses: want to rent a house to spend one week anywhere in the world coworking with your team? We’ve got your back!

*For people based in Montevideo (Uruguay) applying to non-IT roles, 55% monthly attendance to the office is required

What happens after you apply?

Our Talent Acquisition team is invested in creating the best candidate experience possible, so don’t worry, you will definitely hear from us. We will review your CV and keep you posted by email at every step of the process!

Also, you can check out ourwebpage,Linkedin,Instagram, andYoutubefor more about dLocal!

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta um ficheiro em formato PDF, DOC, DOCX, ODT ou PAGES até 5 MB.