
Staff Security Engineer – AppSec
Posted Sep 9

Posted Sep 9
This is a fully remote position, open to applicants in Brazil.
• Establish security architecture standards in collaboration with Engineering and Product teams, particularly for applications utilizing LLMs, agents, and RAG pipelines.
• Develop architectural blueprints for new systems along with technical migration plans for legacy systems.
• Detect vulnerabilities, evaluate risks, and assist in mitigating potential attacks.
• Engage in security incident analysis and response activities.
• Educate and promote awareness among development teams regarding best practices and the secure use of AI assistants.
• Formulate and execute security strategies for applications that incorporate LLMs and generative AI.
• Embed security practices from the outset of the software development lifecycle.
• Perform reviews of architecture, code, and design.
• Establish guardrails and standards addressing LLM risks, including prompt injection, insecure output handling, data leakage, excessive agency, and denial-of-wallet issues.
• Create guidelines for the safe utilization of AI-assisted development tools.
• Produce security standards and best practices documentation.
• Offer technical security guidance and training sessions.
• Utilize and comprehend automated validation tools within CI/CD processes, such as SAST, DAST, SCA, and Secret Scanning.
• Track threat trends, particularly those related to AI systems.
• Innovate solutions to intricate security challenges.
• Actively search for threats in both corporate and production settings.
• Bachelor's degree, either completed or currently in progress, in Information Security, Computer Science, Information Systems, Software Engineering, or a related field.
• Understanding of common attack vectors.
• Proven experience in conducting threat modeling.
• Familiarity with effective protection mechanisms for APIs and mobile applications.
• Knowledge of essential Cloud security services and concepts (AWS, Azure, or GCP).
• Awareness of security risks associated with applications that utilize LLMs and generative AI, including the OWASP Top 10 for LLM Applications and MITRE ATLAS.
• Capacity to identify areas for improvement, new solutions, and alerts.
• Skills in influencing and negotiation to guide teams effectively.
• Ability to work independently.
• Clear, direct, and assertive communication skills, with the capability to simplify complex issues into understandable terms.
• Proactive attitude in seeking or requesting information.
• Competence to collaborate effectively within multidisciplinary teams using agile methodologies.
• Proficiency in reading and communicating in English.
• Experience in participating in incidents and identifying root causes is a plus.
• Background with projects governed by financial sector regulations, like Bacen, PCI, and SOX, is a plus.
• Strong programming skills are an advantage.
• Practical experience with threat modeling and controls for LLM applications in production is a plus.
• Experience in securing APIs that expose AI models is a plus.
• Familiarity with developing policies and controls for the enterprise use of generative AI tools is a plus.
• Knowledge of the NIST AI RMF and ISO/IEC 42001 is a plus.
• Base salary.
• Variable compensation package (profit sharing, long-term incentive plan, or commission), based on role eligibility.
• Health and dental insurance with co-payments.
• Hospital Virtual Verde: telemedicine team available 24/7.
• Medication allowance.
• Meal and/or food allowance – Pluxee.
• Childcare assistance for children up to 5 years and 11 months old.
• Support for employees with children with disabilities.
• Life insurance.
• Fuel allowance or commuting assistance.
• Home office allowance for hybrid or remote contracts.
• Welcome kit for new parents.
• SESC partnership.
• Education benefit: in-house self-development platform (Studa and Stone Library).
• Acolhe360°: free emotional support.
• Quick massage and on-site clinic access.
• Optional benefits: Wellhub, TotalPass, Pet Club, Flash, Férias&Co, transportation vouchers, Allya, and educational partnerships.
Cloudiax
Cisco
Cisco
Skylight
Get handpicked remote jobs straight to your inbox weekly.