
AppSec, Security Analyst, Mid and Senior
Posted 2 hours ago

Posted 2 hours ago
This is a fully remote position, open to applicants in Brazil.
• Monitor, evaluate, and respond to security incidents, recognizing threats and establishing containment and remediation strategies.
• Identify, evaluate, and track the resolution of vulnerabilities across applications, systems, infrastructure, and cloud environments.
• Engage in vulnerability, risk, and security incident management processes.
• Assist with security testing, technical evaluations, and regular audits.
• Contribute to the advancement and implementation of Security by Design and DevSecOps practices, ensuring security is integrated throughout the software development lifecycle.
• Collaborate closely with development teams to identify and address application vulnerabilities.
• Create and update information security policies, procedures, standards, and controls.
• Generate technical reports concerning risks, vulnerabilities, incidents, and threats.
• Aid in monitoring compliance and security requirements, taking into account frameworks and regulations such as ISO, NIST, and LGPD (Brazilian Data Protection Law).
• Advocate for the dissemination of best practices and enhance internal awareness regarding Information Security.
• Keep track of threats, vulnerabilities, and market trends, suggesting ongoing enhancements to security controls.
• Familiarity with Application Security (AppSec).
• Understanding of SOC / Security Operations.
• Knowledge of cloud security, particularly within Azure environments.
• Proficiency in Offensive Security / Penetration Testing.
• Insight into DevSecOps methodologies.
• Awareness of vulnerability and risk management practices.
• Competence in security incident response and management.
• Preferred knowledge in Information Security.
• Familiarity with OWASP and common application vulnerabilities.
• Experience with Azure DevOps.
• Understanding of DevSecOps principles and Security by Design practices.
• Knowledge of security in Cloud/Azure environments.
• Insight into vulnerability and incident management.
• Awareness of frameworks and best practices such as NIST and ISO 27001.
• Familiarity with LGPD and data protection standards.
• Knowledge of tools and methodologies for monitoring, analysis, and incident response.
• Opportunity to work in a dynamic and innovative environment.
• Access to professional development and training programs.
• Competitive salary and benefits package.
• Collaborative and supportive team culture.
Proficio
StarTekk
CyberSheath
Cresol Cooperativa
Get handpicked remote jobs straight to your inbox weekly.