Staff Security Engineer – AppSec

Posted Sep 9

This is a fully remote position, open to applicants in Brazil.

📋 Description

• Establish security architecture standards in collaboration with Engineering and Product teams, particularly for applications utilizing LLMs, agents, and RAG pipelines.

• Develop architectural blueprints for new systems along with technical migration plans for legacy systems.

• Detect vulnerabilities, evaluate risks, and assist in mitigating potential attacks.

• Engage in security incident analysis and response activities.

• Educate and promote awareness among development teams regarding best practices and the secure use of AI assistants.

• Formulate and execute security strategies for applications that incorporate LLMs and generative AI.

• Embed security practices from the outset of the software development lifecycle.

• Perform reviews of architecture, code, and design.

• Establish guardrails and standards addressing LLM risks, including prompt injection, insecure output handling, data leakage, excessive agency, and denial-of-wallet issues.

• Create guidelines for the safe utilization of AI-assisted development tools.

• Produce security standards and best practices documentation.

• Offer technical security guidance and training sessions.

• Utilize and comprehend automated validation tools within CI/CD processes, such as SAST, DAST, SCA, and Secret Scanning.

• Track threat trends, particularly those related to AI systems.

• Innovate solutions to intricate security challenges.

• Actively search for threats in both corporate and production settings.


⛳️ Requirements

• Bachelor's degree, either completed or currently in progress, in Information Security, Computer Science, Information Systems, Software Engineering, or a related field.

• Understanding of common attack vectors.

• Proven experience in conducting threat modeling.

• Familiarity with effective protection mechanisms for APIs and mobile applications.

• Knowledge of essential Cloud security services and concepts (AWS, Azure, or GCP).

• Awareness of security risks associated with applications that utilize LLMs and generative AI, including the OWASP Top 10 for LLM Applications and MITRE ATLAS.

• Capacity to identify areas for improvement, new solutions, and alerts.

• Skills in influencing and negotiation to guide teams effectively.

• Ability to work independently.

• Clear, direct, and assertive communication skills, with the capability to simplify complex issues into understandable terms.

• Proactive attitude in seeking or requesting information.

• Competence to collaborate effectively within multidisciplinary teams using agile methodologies.

• Proficiency in reading and communicating in English.

• Experience in participating in incidents and identifying root causes is a plus.

• Background with projects governed by financial sector regulations, like Bacen, PCI, and SOX, is a plus.

• Strong programming skills are an advantage.

• Practical experience with threat modeling and controls for LLM applications in production is a plus.

• Experience in securing APIs that expose AI models is a plus.

• Familiarity with developing policies and controls for the enterprise use of generative AI tools is a plus.

• Knowledge of the NIST AI RMF and ISO/IEC 42001 is a plus.


🏝️ Benefits

• Base salary.

• Variable compensation package (profit sharing, long-term incentive plan, or commission), based on role eligibility.

• Health and dental insurance with co-payments.

• Hospital Virtual Verde: telemedicine team available 24/7.

• Medication allowance.

• Meal and/or food allowance – Pluxee.

• Childcare assistance for children up to 5 years and 11 months old.

• Support for employees with children with disabilities.

• Life insurance.

• Fuel allowance or commuting assistance.

• Home office allowance for hybrid or remote contracts.

• Welcome kit for new parents.

• SESC partnership.

• Education benefit: in-house self-development platform (Studa and Stone Library).

• Acolhe360°: free emotional support.

• Quick massage and on-site clinic access.

• Optional benefits: Wellhub, TotalPass, Pet Club, Flash, Férias&Co, transportation vouchers, Allya, and educational partnerships.

People also viewed

Cloudiax14 hours ago

Information Security, Compliance & IKS Manager – ISO 27001

DE flagGermany OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Cisco16 hours ago

Senior Manager, Security Channel – Market Growth, Splunk

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$169.3k – $237.2k/year
ApplyView job
Cisco1 day ago

Senior Manager, Security Channel – Market Growth, Splunk

US flagArizona, +10 more statesFull-timeCybersecurity / Security Engineer$169.3k – $237.2k/year
ApplyView job
Skylight1 day ago

Senior Product Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$200k – $250k/year
ApplyView job
Sony Interactive Entertainment1 day ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads1 day ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers