Senior Application Security Manager – Affirmative Action Position for Women

Job not on LinkedIn

🔥 18 minutes ago

🗣️🇧🇷🇵🇹 Portuguese Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of iFood

iFood

5001 - 10000 employees

🍽️ Food & Beverage

📦 Logistics

📣 Marketing

Food & Beverage • Logistics • Marketing

iFood is a leading food delivery platform based in Brazil, connecting customers with a wide array of restaurants and food options. The company leverages cutting-edge technology and artificial intelligence to improve customer experience, streamline operations, and enhance delivery logistics. iFood fosters a diverse and inclusive work environment, focusing on sustainability and the positive impact of its services on the community.

📋 Description

• Define the vision, roadmap and OKRs for Application Security, aligned with engineering and business goals. • Build, develop and retain a team of AppSec engineers and security architects; lead hiring, performance calibration, career planning and succession. • Manage budget, contracts and vendor relationships. • Report security posture to executive leadership. • Drive automation of security processes. • Articulate complex technical strategies at the executive level. • Create and manage automated controls (SAST, DAST, SCA, secret scanning, IaC scanning, container scanning) in CI/CD pipelines. • Manage quality gates and associated metrics. • Implement policy-as-code and admission controls in Kubernetes; ensure supply chain traceability (SBOM, artifact signing, provenance). • Operate the vulnerability management program. • Conduct and escalate threat modeling and secure design reviews for new systems and structural changes. • Define architectural standards for authentication and authorization, encryption and key management, secrets management, API security, multi-tenant isolation and service-to-service communication. • Evaluate risks of new technologies adopted by engineering. • Manage a distributed Security Champions program across product teams. • Define the secure coding curriculum and measurably raise engineering security maturity. • Act as technical escalation for application security incidents; lead blameless post-mortems and ensure corrective actions address root structural causes. • Support compliance and privacy requirements (PCI-DSS, SOC 2, ISO 27001, LGPD) by translating regulatory requirements into engineering controls.

🎯 Requirements

• Technical experience in DevSecOps, Offensive Security and Application Security Architecture. • Experience in governance of artificial intelligence risks applied to cybersecurity. • Ability to define and execute security strategies aligned with business objectives. • Experience leading, building and retaining AppSec and security architecture teams. • Familiarity with SAST, DAST, SCA, secret scanning, IaC scanning and container scanning. • Knowledge of CI/CD, quality gates, policy-as-code and Kubernetes. • Knowledge of SBOM, artifact signing and supply chain provenance. • Knowledge of threat modeling and secure design reviews. • Knowledge of authentication, authorization, encryption, key and secrets management, API security, multi-tenant isolation and service-to-service communication. • Familiarity with PCI-DSS, SOC 2, ISO 27001 and LGPD.

Apply Now

Similar Jobs

🔥 10 hours ago

RecargaPay

201 - 500

💼 Consulting

📦 Logistics

📣 Marketing

Cyber Security Specialist securing RecargaPay’s Brazilian digital payments platform. Owning incident response, detection engineering, cloud investigations, and SOAR automation within CSIRT.

AWS

Cloud

ElasticSearch

Linux

Python

🕒 2 days ago

NeoGuardian

11 - 50

💼 Consulting

🔒 Cybersecurity

Engenheiro de Cibersegurança monitorando SIEM, EDR e infraestrutura para a Neoguardian. Validando alertas, contendo ameaças e escalonando incidentes complexos em São Paulo, remotamente.

🗣️🇧🇷🇵🇹 Portuguese Required

DNS

TCP/IP

🕒 3 days ago

CI&T

5001 - 10000

💼 Consulting

🏥 Healthcare

📣 Marketing

Security remediation developer fixing PHP and AWS vulnerabilities for CI&T, an enterprise AI and technology transformation company. Researching findings, deploying fixes, and validating closure evidence for a US mortgage lender.

AWS

PHP

🕒 3 days ago

CI&T

5001 - 10000

💼 Consulting

🏥 Healthcare

📣 Marketing

Security remediation developer securing PHP and AWS systems for CI&T, an enterprise AI and technology transformation company. Researching vulnerabilities, implementing fixes, deploying remediation, and validating closure evidence for a US mortgage lender.

AWS

Docker

EC2

Laravel

PHP

SOAP

Symfony

Terraform

🕒 3 days ago

Rox Partner

51 - 200

💼 Consulting

🏥 Healthcare

📦 Logistics

Arquiteto de segurança GCP na Rox Partner, consultoria de dados em rápido crescimento. Projetando proteção para ambientes cloud, LLMs, agentes de IA e integrações corporativas.

🗣️🇧🇷🇵🇹 Portuguese Required

Cloud

Google Cloud Platform

Terraform