
Application Security Specialist, AI Security
Posted Aug 19

Posted Aug 19
This is a fully remote position, open to applicants in Brazil.
• Serve as the technical expert, defining, evaluating, and maintaining application security, secure development, and artificial intelligence processes in collaboration with Engineering teams at Conta Simples.
• Organize the AppSec & AI Security program, manage vulnerability assessments, conduct threat modeling, and oversee code reviews.
• Implement, uphold, and enhance secure development methodologies, integrating SAST, DAST, and SCA into the CI/CD pipeline with security gates determined by criticality.
• Oversee the complete lifecycle of vulnerabilities: triage, impact-based prioritization, defining SLAs, and tracking remediation efforts.
• Conduct Ethical Hacking assessments along with web/API and mobile penetration testing.
• Develop and execute STRIDE threat modeling for key workflows and integrations with third-party financial APIs.
• Generate security requirements for system design.
• Perform source code evaluations with a focus on security and promote best practices for input/output validation, authentication/authorization, and secrets management.
• Direct security architecture evaluations and the development of secure platforms, facilitating Security by Design principles.
• Head the Security Champions program and initiatives to raise developer awareness.
• Compile technical documentation and assess Information Security controls and procedures.
• Encourage continuous enhancement and compliance with PCI-DSS, BACEN (Brazilian Central Bank) regulations, and LGPD (Brazilian Data Protection Law).
• Engage with a distributed financial platform utilizing microservices and a technology stack based on Cloudflare, AWS, and GCP.
• Extensive experience in application security and/or offensive security, collaborating closely with development teams.
• Practical experience in integrating SAST and DAST into CI/CD processes and managing vulnerability programs.
• Proficient in STRIDE and assessing risks based on likelihood and impact.
• Familiar with SAST/DAST/SCA tools including Veracode, Checkmarx, SonarQube, Snyk, and OWASP ZAP.
• Experience with penetration testing tools such as Burp Suite, Nmap, Semgrep, Trivy, and relevant open-source tools.
• Understanding of frameworks and references such as OWASP ASVS, OWASP Top 10, OWASP LLM, MITRE ATT&CK, NIST, CIS, and SANS.
• Knowledge of contemporary JavaScript frameworks, specifically Node.js with TypeScript and React.
• Entrepreneurial spirit (self-motivated), high energy, exceptional verbal and written communication skills, and a strong ability to collaborate with developers.
• A Bachelor's degree completed or in progress in Technology fields such as Computer Science, Information Systems, Information Security, or related fields (not mandatory).
• Active involvement in the community, including CTFs, bug bounty programs, research papers, and write-ups.
• Offensive certifications like OSCP, OSWE, CEH, or equivalent qualifications are advantageous.
• Demonstrated experience in code review and practical secure development.
• Familiarity with PCI-DSS, BACEN resolutions 4.658/4.893, and banking regulations.
• Experience in payment fintech environments.
• Familiarity with artificial intelligence, including AI agents and MCP.
• Comprehensive health plan with no monthly fees or copays for our #Simplers and up to two legal dependents.
• Complete dental plan without monthly fees or copays for our #Simplers and up to two legal dependents.
• Flexible food credit on the iFood Benefícios card.
• Home office allowance provided via the iFood Benefícios card.
• Wellhub access extended to legal dependents (children and spouses).
• Birthday off.
• Partnerships with educational institutions.
• Zenklub (Mental Health) — a mental health platform offering four free therapy sessions per month for each Simpler.
• Life insurance coverage.
• Extended parental leave (180 days for maternity and 45 days for paternity), also available for adoptive parents.
• Childcare allowance for children up to one year old.
• Onhappy (Travel) — travel benefits with exclusive discounts on hotels, flights, and experiences.
• Guapeco (Pet Health) — a pet health partnership offering special conditions.
FRSecure
Synack, Inc.
Coinbase
GoodLeap
Get handpicked remote jobs straight to your inbox weekly.