Application Security Specialist – Cyber Defense

Posted Sep 29

This is a fully remote position, open to applicants in Brazil.

📋 Description

• Develop and enhance ROIT’s Application Security and DevSecOps strategy.

• Implement ongoing security practices throughout the software development lifecycle (Secure SDLC).

• Integrate security tools and controls into CI/CD pipelines.

• Implement and further develop SAST, DAST, SCA, Secret Scanning, Container Scanning, and IaC Scanning practices.

• Define and advocate for secure standards for APIs, microservices, Kubernetes, and cloud workloads.

• Assist engineering teams in identifying, prioritizing, and addressing vulnerabilities.

• Engage in threat modeling, architecture reviews, and defining security controls.

• Support initiatives related to ISO 27001, compliance, risk management, and audits.

• Monitor critical vulnerabilities, risks, and incidents related to application security.

• Automate security processes and controls wherever feasible.

• Foster a security culture among technical teams through a consultative and collaborative approach.

• Contribute to the organization’s technical maturity in contemporary security practices.


⛳️ Requirements

• Bachelor’s degree in Computer Science, Software Engineering, Information Systems, Information Security, or a related field.

• Strong experience in Application Security, DevSecOps, or Software Engineering Security.

• Experience in cloud-native environments and with distributed architectures.

• Familiarity with CI/CD pipelines and security automation.

• Understanding of web application security.

• Knowledge of REST APIs and authentication/authorization mechanisms.

• Proficiency with Kubernetes and container technologies.

• Knowledge of security practices in AWS, Azure, or GCP environments.

• Familiarity with the OWASP Top 10.

• Understanding of threat modeling concepts.

• Knowledge of vulnerability management processes.

• Experience with tools related to SAST, DAST, SCA, Container Security, Secret Detection, and IaC Security.

• Awareness of modern engineering and automation methodologies.

• Familiarity with compliance and security frameworks, especially ISO 27001.

• Preferred qualifications: experience in high-scale B2B SaaS environments; background in technology companies or fintechs; knowledge of event-driven architectures and microservices; experience in building automations using AI in security; certifications in security, cloud, or DevSecOps; experience in regulated environments handling highly critical data.


🏝️ Benefits

• [Insert benefits here]

• [Insert additional benefits here]

People also viewed

Integrity3601 day ago

Security Engineer

UA flagUkraine OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Rackspace Technology1 day ago

Security Engineer IV

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$119.6k – $175.4k/year
ApplyView job
Efficient Computer1 day ago

Director of Information Security

US flagCalifornia, +2 more statesFull-timeCybersecurity / Security Engineer$180k – $230k/year
ApplyView job
Presidio1 day ago

Senior Director, Cybersecurity Advisory Services

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Presidio1 day ago

Senior Director, Cybersecurity Advisory Services

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
XBOX1 day ago

Senior Security Engineer

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$102.8k – $190.2k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers