Remotery

Application Security Specialist, AI Security

Posted Aug 19

This is a fully remote position, open to applicants in Brazil.

📋 Description

• Serve as the technical expert, defining, evaluating, and maintaining application security, secure development, and artificial intelligence processes in collaboration with Engineering teams at Conta Simples.

• Organize the AppSec & AI Security program, manage vulnerability assessments, conduct threat modeling, and oversee code reviews.

• Implement, uphold, and enhance secure development methodologies, integrating SAST, DAST, and SCA into the CI/CD pipeline with security gates determined by criticality.

• Oversee the complete lifecycle of vulnerabilities: triage, impact-based prioritization, defining SLAs, and tracking remediation efforts.

• Conduct Ethical Hacking assessments along with web/API and mobile penetration testing.

• Develop and execute STRIDE threat modeling for key workflows and integrations with third-party financial APIs.

• Generate security requirements for system design.

• Perform source code evaluations with a focus on security and promote best practices for input/output validation, authentication/authorization, and secrets management.

• Direct security architecture evaluations and the development of secure platforms, facilitating Security by Design principles.

• Head the Security Champions program and initiatives to raise developer awareness.

• Compile technical documentation and assess Information Security controls and procedures.

• Encourage continuous enhancement and compliance with PCI-DSS, BACEN (Brazilian Central Bank) regulations, and LGPD (Brazilian Data Protection Law).

• Engage with a distributed financial platform utilizing microservices and a technology stack based on Cloudflare, AWS, and GCP.


⛳️ Requirements

• Extensive experience in application security and/or offensive security, collaborating closely with development teams.

• Practical experience in integrating SAST and DAST into CI/CD processes and managing vulnerability programs.

• Proficient in STRIDE and assessing risks based on likelihood and impact.

• Familiar with SAST/DAST/SCA tools including Veracode, Checkmarx, SonarQube, Snyk, and OWASP ZAP.

• Experience with penetration testing tools such as Burp Suite, Nmap, Semgrep, Trivy, and relevant open-source tools.

• Understanding of frameworks and references such as OWASP ASVS, OWASP Top 10, OWASP LLM, MITRE ATT&CK, NIST, CIS, and SANS.

• Knowledge of contemporary JavaScript frameworks, specifically Node.js with TypeScript and React.

• Entrepreneurial spirit (self-motivated), high energy, exceptional verbal and written communication skills, and a strong ability to collaborate with developers.

• A Bachelor's degree completed or in progress in Technology fields such as Computer Science, Information Systems, Information Security, or related fields (not mandatory).

• Active involvement in the community, including CTFs, bug bounty programs, research papers, and write-ups.

• Offensive certifications like OSCP, OSWE, CEH, or equivalent qualifications are advantageous.

• Demonstrated experience in code review and practical secure development.

• Familiarity with PCI-DSS, BACEN resolutions 4.658/4.893, and banking regulations.

• Experience in payment fintech environments.

• Familiarity with artificial intelligence, including AI agents and MCP.


🏝️ Benefits

• Comprehensive health plan with no monthly fees or copays for our #Simplers and up to two legal dependents.

• Complete dental plan without monthly fees or copays for our #Simplers and up to two legal dependents.

• Flexible food credit on the iFood Benefícios card.

• Home office allowance provided via the iFood Benefícios card.

• Wellhub access extended to legal dependents (children and spouses).

• Birthday off.

• Partnerships with educational institutions.

• Zenklub (Mental Health) — a mental health platform offering four free therapy sessions per month for each Simpler.

• Life insurance coverage.

• Extended parental leave (180 days for maternity and 45 days for paternity), also available for adoptive parents.

• Childcare allowance for children up to one year old.

• Onhappy (Travel) — travel benefits with exclusive discounts on hotels, flights, and experiences.

• Guapeco (Pet Health) — a pet health partnership offering special conditions.

People also viewed

FRSecure23 hours ago

Information Security Assessor

US flagArizona, +10 more statesFull-timeCybersecurity / Security Engineer$85k – $95k/year
ApplyView job
Synack, Inc.1 day ago

Manager, Information Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$150k – $180k/year
ApplyView job
Coinbase1 day ago

Product Security Engineer

CA flagCanada OnlyFull-timeCybersecurity / Security EngineerC$154k/year
ApplyView job
GoodLeap1 day ago

Senior Security Engineer, Product Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$146k – $185k/year
ApplyView job
6sense1 day ago

Senior Security Assurance Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$141.2k – $180.1k/year
ApplyView job
Vultr1 day ago

Physical Security System Designer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$90k – $10k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers