
Application Security Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Brazil.
• Develop and enhance ROIT’s Application Security and DevSecOps strategy.
• Implement ongoing security practices throughout the software development lifecycle (Secure SDLC).
• Integrate security tools and measures into CI/CD pipelines.
• Implement and improve practices for SAST, DAST, SCA, Secret Scanning, Container Scanning, and IaC Scanning.
• Establish and advocate for secure standards relating to APIs, microservices, Kubernetes, and cloud workloads.
• Assist engineering teams in identifying, prioritizing, and addressing vulnerabilities.
• Engage in threat modeling, architectural reviews, and the establishment of security controls.
• Support efforts associated with ISO 27001, compliance, risk management, and audits.
• Monitor critical vulnerabilities, risks, and incidents concerning application security.
• Automate security processes and controls whenever feasible.
• Foster a security-oriented culture across technical teams by taking a consultative and collaborative approach.
• Contribute to the organization’s technical advancement by promoting modern security practices.
• Bachelor’s degree in Computer Science, Software Engineering, Information Systems, Information Security, or a related discipline.
• Significant experience in Application Security, DevSecOps, or Software Engineering Security.
• Experience in cloud-native environments and distributed architectures.
• Familiarity with CI/CD pipelines and security automation.
• Understanding of web application security.
• Knowledge of REST APIs and authentication/authorization mechanisms.
• Understanding of Kubernetes and container technologies.
• Knowledge of security practices in AWS, Azure, or GCP environments.
• Awareness of the OWASP Top 10.
• Understanding of threat modeling techniques.
• Knowledge of vulnerability management processes.
• Experience with tools for SAST, DAST, SCA, Container Security, Secret Detection, and IaC Security.
• Familiarity with contemporary engineering and automation practices.
• Understanding of compliance and security frameworks, particularly ISO 27001.
• Preferred qualifications include experience in high-scale B2B SaaS environments; work at technology companies or fintechs; knowledge of event-driven architectures and microservices; experience developing AI-driven security automations; relevant security, cloud, or DevSecOps certifications; and experience in regulated environments with highly sensitive data.
• Competitive salary and performance-based bonuses.
• Comprehensive health benefits including medical, dental, and vision coverage.
• Opportunities for professional development and training.
• Flexible work hours and remote work options.
• Collaborative and innovative work environment.
Hotel Engine
Bolder Apps
Planar
AcuityMD
Get handpicked remote jobs straight to your inbox weekly.