
Senior Full-Stack Security Engineer – International Project
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Brazil.
• Assess and verify security vulnerabilities found within React, TypeScript, JavaScript, and Node.js code.
• Trace vulnerabilities from source code in Bitbucket through API interactions, browser behavior, and deployment setups.
• Apply solutions for vulnerabilities in both front-end and Node.js applications.
• Leverage AI to analyze extensive codebases.
• Work alongside security controls for AI agents capable of interfacing with enterprise systems.
• Develop unit, integration, end-to-end (E2E), and security regression tests.
• Re-execute security scans and provide documentation to resolve vulnerabilities in Jira, Security Workbench, Archer, or similar systems.
• Collaborate with developers as well as Product, AppSec, QA, DevOps, and Platform Security teams.
• Identify recurring vulnerability trends and create reusable secure development guidelines or automated remedies.
• Enhance security measures in pull requests, branch policies, build pipelines, and release gates.
• Investigate false positives and record risk-based decisions when immediate remediation isn't feasible.
• Assist in security evaluations, penetration testing, incident-related remediation, and monitoring vulnerability trends.
• Robust experience in securing Node.js services, APIs, and Backend-for-Frontend (BFF) applications.
• Proficiency in React components, hooks, context, routing, state management, and SSR as applicable.
• Expertise in securely managing user-controlled data within components, forms, URLs, query parameters, and client-side state.
• Capability to analyze pull requests, branches, commit history, and repository configurations.
• Familiarity with XSS, dangerouslySetInnerHTML, DOM-based XSS, client-side open redirects, browser storage, source maps, CSP, authorization controls, data leakage, and supply chain vulnerabilities.
• Knowledge of secure SQL and NoSQL queries, command execution, uploads/downloads, path and URL parameters, HTTP headers, serialization/deserialization, sessions/tokens, and SSRF.
• Experience with Checkmarx, Veracode, Fortify, SonarQube, Snyk Code, or Semgrep.
• Over 5 years of experience in front-end or full-stack software engineering.
• At least 3 years of direct involvement with application security, secure coding, or vulnerability remediation in DevSecOps environments.
• Strong expertise in React, TypeScript, JavaScript, Node.js, HTML, CSS, and HTTP.
• Familiarity with Git and Bitbucket in enterprise settings.
• Proven track record in tracking vulnerabilities from detection through to remediation and closure validation.
• Experience with web applications that manage sensitive data.
• Ability to collaborate with application, security, QA, DevOps, and infrastructure teams.
• Advanced English proficiency for daily communication.
• Nice to have: experience with AI assistant/agent security, AI agents for development, agentic platforms, LLM security, GitHub/GitLab, information security research, security automation, and utilizing AI to identify and resolve vulnerabilities.
• Work arrangement: 100% remote.
• Meal and/or food allowance.
• Well-Being Program: psychological, legal, social, and financial support.
• Health and dental insurance.
• Life insurance.
• Wellhub.
• Discount partnerships with Sucesu, Target Trust, Sesc, and Seprorgs.
• Company anniversary bonus.
• Employee referral bonus for successful hires.
• Childcare assistance.
• CLT employment contract, 44 hours per week.
Cloudiax
Cisco
Cisco
Skylight
Get handpicked remote jobs straight to your inbox weekly.