
Application Security Specialist – Cyber Defense
Posted Sep 29

Posted Sep 29
This is a fully remote position, open to applicants in Brazil.
• Develop and enhance ROIT’s Application Security and DevSecOps strategy.
• Implement ongoing security practices throughout the software development lifecycle (Secure SDLC).
• Integrate security tools and controls into CI/CD pipelines.
• Implement and further develop SAST, DAST, SCA, Secret Scanning, Container Scanning, and IaC Scanning practices.
• Define and advocate for secure standards for APIs, microservices, Kubernetes, and cloud workloads.
• Assist engineering teams in identifying, prioritizing, and addressing vulnerabilities.
• Engage in threat modeling, architecture reviews, and defining security controls.
• Support initiatives related to ISO 27001, compliance, risk management, and audits.
• Monitor critical vulnerabilities, risks, and incidents related to application security.
• Automate security processes and controls wherever feasible.
• Foster a security culture among technical teams through a consultative and collaborative approach.
• Contribute to the organization’s technical maturity in contemporary security practices.
• Bachelor’s degree in Computer Science, Software Engineering, Information Systems, Information Security, or a related field.
• Strong experience in Application Security, DevSecOps, or Software Engineering Security.
• Experience in cloud-native environments and with distributed architectures.
• Familiarity with CI/CD pipelines and security automation.
• Understanding of web application security.
• Knowledge of REST APIs and authentication/authorization mechanisms.
• Proficiency with Kubernetes and container technologies.
• Knowledge of security practices in AWS, Azure, or GCP environments.
• Familiarity with the OWASP Top 10.
• Understanding of threat modeling concepts.
• Knowledge of vulnerability management processes.
• Experience with tools related to SAST, DAST, SCA, Container Security, Secret Detection, and IaC Security.
• Awareness of modern engineering and automation methodologies.
• Familiarity with compliance and security frameworks, especially ISO 27001.
• Preferred qualifications: experience in high-scale B2B SaaS environments; background in technology companies or fintechs; knowledge of event-driven architectures and microservices; experience in building automations using AI in security; certifications in security, cloud, or DevSecOps; experience in regulated environments handling highly critical data.
• [Insert benefits here]
• [Insert additional benefits here]
Integrity360
Rackspace Technology
Efficient Computer
Presidio
Get handpicked remote jobs straight to your inbox weekly.