Remotery

Security Engineer – DevSecOps, AppSec

Posted Jul 27

This is a fully remote position, open to applicants in Brazil.

📋 Description

• Implement and oversee SAST, DAST, and SCA tools within the CI/CD pipeline (Bitbucket/GitHub/GitLab).

• Develop, maintain, operate, and enhance the Secrets Manager and Vault.

• Conduct continuous secret scanning in repositories and drive the remediation of findings in collaboration with development teams.

• Execute security-focused code reviews on critical functionalities — including authentication, authorization, external integrations, and the handling of sensitive data.

• Strengthen infrastructure by managing Terraform state, IAM policies, AWS configurations, and Security Groups.

• Assist in the remediation of technical issues identified from security analysis tools, external penetration tests, and internal scans.

• Establish and lead the Security Champions program — identifying key points within development squads and structuring ongoing training.

• Perform threat modeling for new features and critical integrations alongside product and engineering teams.

• Define and document security requirements throughout the SDLC — from design to deployment.

• Evaluate the security of internal and external APIs, partner integrations, and authentication processes.


⛳️ Requirements

• Practical experience with CI/CD pipelines and the integration of security tools (SAST, SCA, secret scanning) into the development workflow.

• In-depth knowledge of AWS services: IAM, S3, Lambda, Security Groups, VPC, KMS, and best practices in cloud security.

• Experience with infrastructure as code (Terraform) — capable of identifying and addressing security vulnerabilities in IaC.

• Familiarity with the OWASP Top 10 and OWASP API Security Top 10, with the ability to apply these principles in code and architecture evaluations.

• Proficiency in writing scripts and automations for analysis and remediation (Python or Bash).

• Ability to read and interpret code in at least one programming language utilized in the product.

• Strong critical thinking and risk analysis skills.

• Proactive mindset: initiative and foresight.

• Effective interpersonal communication with development teams.

• Technical independence.

• Strong collaboration and teamwork abilities.

• Skills in teaching and knowledge transfer.

• Results-oriented focus on delivery and outcomes.


🏝️ Benefits

• Contract (PJ) with 30 days of paid leave.

• Health insurance with monthly premiums fully covered by the company (for contractors after 6 months).

• Dental plan (available for contractors after 6 months).

• Life insurance coverage.

• Complete equipment kit provided.

• Home office allowance of R$180.00/month.

• Day off during your birthday month.

• Discount on Gympass.

• No dress code — be yourself!

• Extended maternity and paternity leave.

People also viewed

ASG Technologies6 hours ago

IT Security Director

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$165k – $190k/year
ApplyView job
CrowdStrike6 hours ago

Associate Security Engineer

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$70k – $95k/year
ApplyView job
Culmen International7 hours ago

Border Security Trainer

US flagUnited States OnlyFreelanceCybersecurity / Security Engineer
ApplyView job
Threatscape7 hours ago

Security Consultant – Purview

GB flagUnited Kingdom, +1 more countryFull-timeCybersecurity / Security Engineer£35k – £47k/year
ApplyView job
Unity8 hours ago

Staff Security Architect

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$160.3k – $305.4k/year
ApplyView job
Truist10 hours ago

Cybersecurity Group Manager

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers