
201 - 500 employees
Founded 2018
💳 Fintech
🤝 B2B
💸 Finance
Fintech • B2B • Finance
Conta Simples is a financial platform designed for businesses that simplifies expense management and provides real-time insights into financial activities. The platform allows users to create corporate credit cards, manage payments via methods such as Pix and bank slips, and categorize expenses by cost centers. Conta Simples leverages artificial intelligence to generate insights for strategic financial management, aiming to streamline operational processes and improve efficiency for companies.
🔥 1 minute ago
🇧🇷 Brazil – Remote
⏰ Full Time
🟡 Mid-level
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
👻 Ghost score 10%
🗣️🇧🇷🇵🇹 Portuguese Required
Improve your chances of getting an interview by checking your resume score before you apply.

201 - 500 employees
Founded 2018
💳 Fintech
🤝 B2B
💸 Finance
Fintech • B2B • Finance
Conta Simples is a financial platform designed for businesses that simplifies expense management and provides real-time insights into financial activities. The platform allows users to create corporate credit cards, manage payments via methods such as Pix and bank slips, and categorize expenses by cost centers. Conta Simples leverages artificial intelligence to generate insights for strategic financial management, aiming to streamline operational processes and improve efficiency for companies.
• Act as the technical reference and define, assess and sustain application security, secure development and artificial intelligence processes at Conta Simples alongside Engineering teams • Structure the AppSec & AI Security program, vulnerability management, threat modeling and code review • Implement, maintain and improve secure development practices, integrating SAST, DAST and SCA into the CI/CD pipeline with security gates based on criticality • Manage vulnerabilities end-to-end: triage, impact-based prioritization, SLA definition and tracking of remediation • Perform Ethical Hacking tests and web/API and mobile penetration tests • Create and execute STRIDE threat modeling for critical flows and integrations with third-party financial APIs • Produce security requirements for design • Perform source code reviews with a security focus and guide best practices for input/output validation, authentication/authorization and secrets management • Lead security architecture assessments and the building of secure platforms, acting as an enabler for Security by Design • Lead the Security Champions program and developer awareness initiatives • Prepare technical reports and evaluate Information Security controls and processes • Promote continuous improvement and adherence to PCI-DSS, BACEN (Brazilian Central Bank) regulations and LGPD (Brazilian Data Protection Law) • Work on a distributed financial platform using microservices and a stack built on Cloudflare, AWS and GCP
• Solid experience in application security and/or offensive security, working closely with development teams • Hands-on experience integrating SAST and DAST into CI/CD and running vulnerability management programs • Experience with STRIDE and prioritizing risks by likelihood and impact • Familiarity with SAST/DAST/SCA tools such as Veracode, Checkmarx, SonarQube, Snyk and OWASP ZAP • Experience with penetration testing tools such as Burp Suite, Nmap, Semgrep, Trivy and related open-source tools • Knowledge of frameworks and references including OWASP ASVS, OWASP Top 10, OWASP LLM, MITRE ATT&CK, NIST, CIS and SANS • Knowledge of modern JavaScript stacks — Node.js with TypeScript and React • Entrepreneurial mindset (self-starter), high energy, excellent verbal and written communication, teamwork and ability to collaborate closely with developers • Bachelor's degree completed or in progress in Technology fields such as Computer Science, Information Systems, Information Security or related (not mandatory) • Engagement with the community such as CTFs, bug bounty programs, papers and write-ups • Offensive certifications like OSCP, OSWE, CEH or equivalents are a plus • Proven experience in code review and hands-on secure development • Knowledge of PCI-DSS, BACEN resolutions 4.658/4.893 and banking regulations • Experience in payment fintechs • Experience with artificial intelligence, such as AI agents and MCP
• Nationwide health plan with no monthly fee or copay for our #Simplers and up to 2 legal dependents • Nationwide dental plan with no monthly fee or copay for our #Simplers and up to 2 legal dependents • Flex food credit on the iFood Benefícios card • Home office allowance on the iFood Benefícios card • Wellhub extended to legal dependents (children and spouses) • Birthday-off • Partnerships with educational institutions • Zenklub (Mental Health) — mental health platform with 4 free therapy sessions per month for every Simpler • Life insurance • Extended parental leave (180 days for maternity and 45 days for paternity), also available to adoptive parents • Childcare allowance — for children up to 1 year old • Onhappy (Travel) — travel benefit with exclusive discounts on hotels, flights and experiences • Guapeco (Pet Health) — pet health partnership with special conditions
Apply Now🕒 Yesterday
Liderança de Application Security no iFood, empresa brasileira de tecnologia em delivery, fintech, mercado, farmácia e pet. Definição de estratégia, DevSecOps, arquitetura de segurança e cultura de engenharia.
🗣️🇧🇷🇵🇹 Portuguese Required
Kubernetes
🕒 Yesterday
Cyber Security Specialist securing RecargaPay’s Brazilian digital payments platform. Owning incident response, detection engineering, cloud investigations, and SOAR automation within CSIRT.
🇧🇷 Brazil – Remote
💰 $10M Debt Financing on 2022-07
⏰ Full Time
🟡 Mid-level
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
AWS
Cloud
ElasticSearch
Linux
Python
🕒 4 days ago
Engenheiro de Cibersegurança monitorando SIEM, EDR e infraestrutura para a Neoguardian. Validando alertas, contendo ameaças e escalonando incidentes complexos em São Paulo, remotamente.
🗣️🇧🇷🇵🇹 Portuguese Required
DNS
TCP/IP
🕒 4 days ago
Security Architect integrating Akamai security solutions for global customers. Analyzing traffic, configuring protections, and supporting cloud-to-edge security implementations.
🇧🇷 Brazil – Remote
💰 Post-IPO Equity on 2001-07
⏰ Full Time
🟢 Junior
🟡 Mid-level
👮♂️ Cybersecurity / Security Engineer
🚫👨🎓 No degree required
Cloud
DNS
🕒 4 days ago
Security remediation developer fixing PHP and AWS vulnerabilities for CI&T, an enterprise AI and technology transformation company. Researching findings, deploying fixes, and validating closure evidence for a US mortgage lender.
🇧🇷 Brazil – Remote
💰 $5.5M Venture Round on 2014-04
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
AWS
PHP