
Senior Security Engineering Analyst – AppSec
Posted 6 hours ago

Posted 6 hours ago
This is a fully remote position, open to applicants in Brazil.
• Define and enhance the corporate Secure Software Development Life Cycle (SSDLC) process.
• Establish essential security requirements for applications.
• Define and implement Security Gates within development and CI/CD workflows.
• Integrate security controls and requirements throughout the application lifecycle.
• Foster the development of a secure development culture across the organization.
• Engage in projects from the initial conception and architectural phases.
• Conduct security evaluations of proposed solutions and architectures.
• Identify risks and vulnerabilities, proposing appropriate mitigation strategies.
• Utilize Threat Modeling and Security by Design methodologies.
• Collaborate closely with architects, developers, DevOps, and other technical teams.
• Identify, analyze, and rectify application vulnerabilities.
• Assist development teams in adopting Secure Coding practices.
• Perform code reviews with a focus on security.
• Evaluate APIs, microservices, containers, and software components.
• Address vulnerabilities and risks associated with dependencies, code, infrastructure, and configurations.
• Integrate security tools into CI/CD pipelines.
• Work with SAST, DAST, SCA, Secret Scanning, IaC Scanning, and Container Security solutions.
• Support the implementation and management of SBOMs.
• Define criteria and policies for Security Gates.
• Advocate for the automation of security controls throughout pipelines.
• Operate in AWS environments, assisting in the implementation of secure architectures.
• Evaluate cloud security configurations and controls.
• Utilize resources such as AWS API Gateway and AWS Security Hub.
• Assist in identifying and remediating risks related to cloud infrastructure and applications.
• Experience in medium- to large-scale corporate environments.
• Direct experience working with development teams.
• Proven experience in defining or evolving security processes and controls.
• Familiarity with SSDLC — Secure Software Development Life Cycle.
• Understanding of Security by Design principles.
• Knowledge of Threat Modeling techniques.
• Awareness of the OWASP Top 10 vulnerabilities.
• Familiarity with OWASP ASVS.
• Expertise in Secure Coding practices.
• Understanding of API Security requirements.
• Knowledge of Application Architecture.
• Familiarity with Microservices Architecture.
• Understanding of DevOps processes and CI/CD methodologies.
• Experience in application vulnerability management.
• Proficient with SAST, DAST, SCA, Secret Scanning, IaC Scanning, Container Security, SBOM, CI/CD, and DevSecOps practices.
• Experience with AWS services.
• Familiarity with AWS API Gateway.
• Knowledge of AWS Security Hub functionalities.
• Understanding of cloud security and architecture best practices.
• Open to applicants with disabilities (PwD).
• Remote work opportunities available.
Alcoa
McKesson
Zillow
Truelogic Software
Get handpicked remote jobs straight to your inbox weekly.