Full-time - Long Term
Remote - LATAM
Description
We are looking for an Application Security Engineer based in Latin America to work on a long-term project for one of our clients, a Non-profit Organization based in New York. Our client is a nonprofit organization that offers free, 24/7, confidential mental health support via text message, in English and Spanish.The person in this role will lead application security across the engineering organization, with a focus on securing the software development lifecycle, partnering with engineering teams on secure design and code reviews, and supporting the broader security program across identity, cloud, and security operations.
Responsibilities
- Partner with engineering teams to conduct architecture reviews, threat modeling, and secure code reviews for critical features, including authentication, encryption, and sensitive data handling.
- Lead application security reviews across services, including manual and automated code review, dynamic testing, and business logic analysis.
- Provide guidance and mentorship to engineers on application security, and lead complex or high-risk security reviews and threat modeling activities.
- Integrate and maintain SAST, DAST, and SCA tooling within CI/CD pipelines, and implement secrets detection to prevent exposure of credentials and API keys.
- Perform hands-on security testing of web applications, APIs, and cloud infrastructure to identify risks and guide remediation.
- Review AI-assisted and AI-generated code for security risks, including code produced with tools such as Claude and GitHub Copilot, and help define security guardrails for AI-assisted development.
- Drive vulnerability management for application-layer findings, from identification and triage through remediation, and maintain supporting security documentation, including threat models and security requirements.
- Support and evolve the bug bounty or vulnerability disclosure program, including vulnerability triage, response, and process improvements.
- Build and scale developer-facing security programs, including secure coding training, security champions programs, and reusable security patterns for authentication, authorization, encryption, and secret handling.
- Respond to security incidents, conduct investigations, and participate in on-call rotations alongside the security team.
- Support broader security initiatives as needed, including cloud security reviews, identity and access management, and security operations.
- Create, maintain, and improve product security processes, and ensure security considerations are incorporated throughout the product life cycle.
Requirements
- Advanced Level of English
- 8+ years of experience working in application security or a related security engineering discipline, including experience building or scaling an AppSec program.
- Strong knowledge of common web and API vulnerabilities, including OWASP Top 10, secure coding practices, and business logic security.
- Hands-on experience working with SAST, DAST, and SCA tools and integrating security checks into CI/CD pipelines.
- Experience leading threat modeling and security architecture reviews for critical and high-risk systems.
- Experience reviewing AI-assisted or AI-generated code, including code produced with tools such as Claude and GitHub Copilot, for security risks.
- Experience participating in on-call rotations and supporting security incident response.
- Strong communication skills, with the ability to communicate security findings and remediation guidance effectively to engineering teams.
- Experience working with API security and authentication and authorization frameworks such as OAuth, SAML, and SSO.
Bonus Points
- Bachelor’s Degree in Computer Science, Systems Engineering or related fields.
- Familiarity with cloud security fundamentals on AWS.
- Experience building or running a security champions program.
- Background in penetration testing or offensive security, including certifications such as OSCP.
- Familiarity with Infrastructure as Code (IaC) tools such as Terraform or CDK and reviewing IaC for security issues.
- Experience securing data platforms or pipelines that handle sensitive data, such as Databricks or Unity Catalog.
- Experience using AI tools to scale security work, such as AI-assisted threat modeling.