
Information Security Specialist – Architecture, Application Security
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Brazil.
• Enhance the security architecture.
• Integrate security measures into the process, starting from initial architectural choices through to product development and operations.
• Elevate secure development maturity.
• Detect systemic vulnerabilities and examine their root causes.
• Transform vulnerabilities into scalable architectural enhancements.
• Fortify infrastructure and cloud security.
• Anticipate threats utilizing Threat Modeling techniques.
• Develop reusable security standards.
• Automate security controls.
• Influence architecture, development, and infrastructure standards.
• Collaborate across functions with Infrastructure, Cloud, Software Engineering, and Cybersecurity teams.
• Act as a technical reference in Information Security.
• Substantial experience in Information Security, with a strong technical foundation in security architecture.
• Proficiency in application architecture, infrastructure, and distributed environments.
• Experience with security protocols in AWS and/or Google Cloud Platform environments.
• Comprehensive knowledge of Application Security and secure development practices.
• Familiarity with Secure SDLC and DevSecOps methodologies.
• Experience with Threat Modeling techniques.
• Extensive understanding of major vulnerability classes in applications, APIs, infrastructure, and cloud environments.
• Capability to perform root-cause analyses of vulnerabilities and suggest structural solutions.
• Knowledge of authentication, authorization, identity management, and access controls.
• Understanding of OAuth 2.0, OpenID Connect, SSO, MFA, and related technologies.
• Familiarity with cryptography, digital certificates, PKI, and secrets management.
• Knowledge of API security, microservices, and distributed architectures.
• Acquainted with containers, Kubernetes, and their critical security concepts.
• Awareness of CI/CD processes and the integration of security controls into pipelines.
• Familiar with SAST, DAST, SCA, and IaC analysis tools.
• Knowledge of frameworks and references such as OWASP, NIST, and CIS Benchmarks.
• Proficiency in automation using Python, Go, PowerShell, or other programming languages.
• Ability to convey complex technical risks into clear decisions for varied audiences.
• Strong technical influencing abilities and the capability to work collaboratively across different teams.
• Experience in building digital banks and/or financial institutions.
• Meal and food allowance provided via an iFood card.
• Daily transportation allowance on an iFood card.
• Health insurance with the company covering 100% of the premium (with co-payment).
• TotalPass membership.
• Access to Star Bem and Avus health and discount platforms.
• Childcare assistance in accordance with applicable collective bargaining agreements.
• Day off during your birthday month.
• Birthday voucher.
• Annual PPR bonus program.
• No dress code policy.
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.