Senior Full-Stack Security Engineer – International Project

Job not on LinkedIn

🔥 19 hours ago

🇧🇷 Brazil – Remote

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 13%

infoinfo

🗣️🇧🇷🇵🇹 Portuguese Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Deliverit

Deliverit

1 - 10 employees

Founded 2021

🛍️ eCommerce

📦 Logistics

eCommerce • Logistics

Deliverit is a delivery service that shops from your desired market and delivers products directly to your door. They emphasize same-day delivery with no minimum order value and no price surcharges, promoting a contactless shopping experience. Their motto, 'fresh. fast. flexible,' highlights their commitment to efficient and customer-oriented service.

📋 Description

• Review and validate security vulnerabilities identified in React, TypeScript, JavaScript, and Node.js code • Trace vulnerabilities from source code in Bitbucket through API calls, browser behavior, and deployment configurations • Implement fixes for vulnerabilities in front-end and Node.js applications • Use AI to analyze large codebases • Work with security controls for AI agents capable of interacting with enterprise systems • Create unit, integration, end-to-end (E2E), and security regression tests • Re-run security scans and provide evidence to close vulnerabilities in Jira, Security Workbench, Archer, or equivalent systems • Collaborate with developers and Product, AppSec, QA, DevOps, and Platform Security teams • Identify recurring vulnerability patterns and create reusable secure development guidance or automated fixes • Improve security controls in pull requests, branch policies, build pipelines, and release gates • Investigate false positives and document risk-based decisions when remediation cannot be completed immediately • Support security reviews, penetration testing, incident-related remediation, and vulnerability trend monitoring

🎯 Requirements

• Strong experience securing Node.js services, APIs, and Backend-for-Frontend (BFF) applications • Knowledge of React components, hooks, context, routing, state management, and SSR where applicable • Knowledge of securely handling user-controlled data in components, forms, URLs, query parameters, and client-side state • Ability to analyze pull requests, branches, commit history, and repository configurations • Familiarity with XSS, dangerouslySetInnerHTML, DOM-based XSS, client-side open redirects, browser storage, source maps, CSP, authorization controls, data leakage, and dependency/software supply chain vulnerabilities • Knowledge of secure SQL and NoSQL queries, command execution, uploads/downloads, path and URL parameters, HTTP headers, serialization/deserialization, sessions/tokens, and SSRF • Experience with Checkmarx, Veracode, Fortify, SonarQube, Snyk Code, or Semgrep • 5+ years of experience in front-end or full-stack software engineering • 3+ years working directly with application security, secure coding, or vulnerability remediation in DevSecOps environments • Strong experience with React, TypeScript, JavaScript, Node.js, HTML, CSS, and HTTP • Experience with Git and Bitbucket in enterprise environments • Proven experience tracking vulnerabilities from identification through remediation and closure validation • Experience with web applications that handle sensitive data • Ability to work with application, security, QA, DevOps, and infrastructure teams • Advanced English proficiency for daily communication • Nice to have: experience with AI assistant/agent security, AI agents for development, agentic platforms, LLM security, GitHub/GitLab, information security research, security automation, and using AI to discover and remediate vulnerabilities

🏖️ Benefits

• Work arrangement: 100% remote • Meal and/or food allowance • Well-Being Program: psychological, legal, social, and financial support • Health and dental insurance • Life insurance • Wellhub • Discount partnerships with Sucesu, Target Trust, Sesc, and Seprorgs • Company anniversary bonus • Employee referral bonus for successful hires • Childcare assistance • CLT employment contract, 44 hours per week

Apply Now

Similar Jobs

🔥 19 hours ago

ASAAS

501 - 1000

💼 Consulting

🏥 Healthcare

🏨 Hospitality

Analista sênior de riscos e controles de segurança da informação na Asaas, fintech que maximiza a produtividade empresarial com tecnologia. Condução de riscos, controles, TPRM e governança.

🗣️🇧🇷🇵🇹 Portuguese Required

Cloud

🕒 Yesterday

GFT Technologies

10,000+ employees

💼 Consulting

🛡️ Insurance

🔒 Cybersecurity

Senior Cloud Security Engineer securing complex AWS infrastructure for GFT Technologies' regulated financial-services clients. Automating controls, managing vulnerabilities, and supporting compliance audits.

🗣️🇧🇷🇵🇹 Portuguese Required

AWS

Cloud

Terraform

VMware

🕒 Yesterday

Neon

1001 - 5000

💼 Consulting

🛡️ Insurance

💳 Fintech

Engenheiro especialista em segurança cloud liderando redes AWS, firewalls Palo Alto e soluções Zscaler na Neon. Automatização com Terraform e estratégia SASE/Zero Trust para proteger serviços financeiros.

🗣️🇧🇷🇵🇹 Portuguese Required

AWS

Azure

Cloud

Firewalls

Google Cloud Platform

TCP/IP

Terraform

🕒 2 days ago

ROIT

51 - 200

💼 Consulting

⚖️ Legal

☁️ SaaS

Analista de Segurança Ofensiva e Detecção na ROIT, empresa que fortalece sua estrutura de Cybersecurity. Simulando adversários e convertendo resultados em detecção e resposta.

🗣️🇧🇷🇵🇹 Portuguese Required

Cyber Security

Python

🕒 2 days ago

Montreal Oficial

1001 - 5000

🔒 Cybersecurity

☁️ SaaS

Arquiteto de Segurança em TI na Montreal, empresa brasileira de tecnologia. Definindo arquiteturas, criptografia e estratégias DevSecOps para aplicações móveis.

🗣️🇧🇷🇵🇹 Portuguese Required