Product Security Engineer (remote in Brazil)

knowbe4

United States

Remote

USD 120,000 - 150,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Company-wide bonuses tied to monthly销售
Employee referral bonuses
Adoption assistance
Tuition reimbursement
Certification reimbursement
Certification completion bonuses

Job summary

KnowBe4 is seeking a mid-level Product Security Engineer to strengthen application security across web, mobile, and traditional platforms. You will perform hands-on penetration testing, review source code, and work shoulder-to-shoulder with engineering teams as release velocity increases.

You will plan automated and manual security assessments, triage findings, and drive remediation to closure while embedding secure coding practices throughout the SDLC.

Qualifications

  • Background in application security, penetration testing, or red teaming.
  • Strong hands-on experience running automated tooling and manual tests against web, mobile, and traditional applications.
  • Ability to read and reason about source code in Ruby, PHP, Go, JavaScript, or Python.
  • Knowledge of OWASP Top 10 and CWE concepts.
  • Strong written and spoken English for collaboration with international teams.

Responsibilities

  • Plan and execute security assessments and penetration tests across web, mobile, and traditional apps.
  • Read and analyze source code to surface vulnerabilities and propose fixes.
  • Partner with engineers to triage findings and drive remediation to closure.
  • Maintain threat models and build automations to streamline security testing.
  • Embed secure coding practices across the software development lifecycle.

Skills

Application security
Penetration testing
Code review
OWASP Top 10
Ruby/PHP/Go/JS/Python

Tools

Burp Suite
SAST/DAST scanners
Dependency scanners

Job description

Role overview

A mid-level Product Security Engineer is needed to strengthen application security across web, mobile, and traditional platforms. The role centers on hands-on penetration testing and source-code review, working shoulder-to-shoulder with engineering teams as release velocity increases.

Responsibilities
  • Plan and execute combined automated and manual security assessments and penetration tests against web, mobile, and conventional applications.
  • Read and analyze source code in several programming languages to surface vulnerabilities and recommend fixes before and after deployment.
  • Partner with engineers to triage findings, prioritize risk, and drive remediation to closure.
  • Maintain threat models and build automations that streamline recurring security testing work.
  • Embed secure coding practices throughout the software development lifecycle in collaboration with product and development teams.
Requirements
  • Background in application security, penetration testing, or red teaming.
  • Strong hands-on experience running both automated tooling and manual tests against web, mobile, and traditional applications.
  • Ability to read and reason about source code in multiple languages such as Ruby, PHP, Go, JavaScript, or Python.
  • Working knowledge of common web application vulnerability classes (for example OWASP Top 10 and CWE categories) and core information security concepts.
  • Strong written and spoken technical English for collaboration with international teams.
  • A collaborative, team-oriented mindset.
Nice to have
  • Cloud experience with environments such as AWS and Terraform.
  • Familiarity with security tooling like Burp Suite, SAST and DAST scanners, and dependency scanners.
  • Python scripting or hands-on use of AI-assisted security workflows.
  • Relevant certifications such as OSCP, OSWE, GPEN, or CISSP.
Benefits and work setup
  • Company-wide bonuses tied to monthly sales targets, employee referral bonuses, adoption assistance, tuition reimbursement, certification reimbursement, and certification completion bonuses.
  • Remote role based in Brazil.
  • Resume submission in English is required.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Product Security Engineer
Senior Product Security Engineer

Tessera Labs • United States

Remote
USD 120,000 - 180,000
Information Security Platform Engineer (remote in Brazil)
Information Security Platform Engineer (remote in Brazil)

knowbe4 • United States

Remote
USD 110,000 - 160,000
Bonus program
Referral bonuses
Adoption assistance
+3
Product Security Engineer
Product Security Engineer

Modernhealth • United States

Remote
USD 101,000 - 140,000
health and insurance coverage
flexible time off
family-support programs
+4
Product Security Engineer
Product Security Engineer

GoMining • Town of Poland (NY)

On-site
USD 120,000 - 190,000
Professional growth support
Flexible hours
Vacation and holidays
Product Security Engineer
Product Security Engineer

GoMining • Georgia

On-site
USD 120,000 - 180,000
Professional growth
Remote or hybrid format
Vacation and holidays
+3
Application Security Engineer - Senior
Application Security Engineer - Senior

platacard • United States

Hybrid
USD 120,000 - 180,000
Relocation with visa support
Flexible work office or remote
Healthcare coverage
+3
Product Security Engineer Remote - US
Product Security Engineer Remote - US

Secure State.IQ • United States

Remote
USD 120,000 - 180,000
Security Engineer
Security Engineer

xbowcareers • United States

Remote
USD 140,000 - 210,000
Competitive salary
Equity or incentive plan
401k plan
Application Security Engineer
Application Security Engineer

Prediktive • New York (NY)

Remote
USD 130,000 - 190,000
Application Security Engineer
Application Security Engineer

Placements24 • United States

Remote
USD 90,000 - 130,000
Flexible remote work
Professional development opportunities
Security-focused culture