Senior Information Security Engineer

Job not on LinkedIn

🔥 6 hours ago

🇧🇷 Brazil – Remote

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 18%

infoinfo

🗣️🇧🇷🇵🇹 Portuguese Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of DOMVS iT

DOMVS iT

51 - 200 employees

Founded 2014

💼 Consulting

🏥 Healthcare

🏢 Enterprise

Consulting • Healthcare • Enterprise

DOMVS iT is a Brazilian technology services company with over a decade of experience that provides IT staffing (Squad as a Service), managed squads, consulting, outsourcing, application management, and cloud & data services. The firm offers digital experience and product design services (Product Discovery, PDaaS), cloud architecture, FinOps, migrations, data masking/virtualization, and enterprise application support (including SAP), serving business customers across multiple cities and countries.

📋 Description

• Own the architecture and evolution of Lhasa’s security guardrail files (.md and equivalent formats), including structure, scope, versioning, update frequency, and integration with development tools • Define security requirements for AI engineers using AI to write code, covering data handling, authentication, injection prevention, and AI-specific vulnerability patterns • Establish and continuously improve secure-by-design principles for Lhasa’s software development • Continuously recalibrate guardrails as AI-powered programming tools, threat patterns, and product architecture evolve • Lead guardrail adoption across solution teams, resolving ambiguities and handling exceptions with clear justifications

🎯 Requirements

• Extensive information security experience, with a strong focus on application security or product security • Proven experience owning secure development frameworks, guardrail standards, or DevSecOps programs • Demonstrated experience integrating security into CI/CD pipelines and automating security gate controls • Experience leading application security assessments, including threat modeling, SAST/DAST, and penetration testing coordination • Previous experience working with, or in close and continuous collaboration with, software development teams • Track record of independently addressing complex product security challenges and delivering results across multiple teams • Advanced knowledge of application security, including the OWASP Top 10 and equivalent frameworks • Deep knowledge of vulnerability patterns in AI-generated code and how to address them at the framework and pipeline levels • Strong knowledge of AI-specific attack vectors, including prompt injection, data poisoning, model manipulation, and risks associated with agentic systems • Specialized knowledge of CI/CD tools and security gate implementation mechanisms, including SAST, DAST, dependency scanning, and secrets detection • Practical knowledge of ISO 27001, NIST, and ISO 42001 as applied to software products • CISSP, CEH, or equivalent certification (preferred) • Experience with secure design of AI systems or formal AI security assessment frameworks (preferred) • Familiarity with ISO 42001, the EU AI Act, or contributions to security standards or open-source security tools (preferred) • Previous experience in software development or DevSecOps engineering (preferred)

🏖️ Benefits

• The support needed to achieve professional success • A collaborative and innovative environment

Apply Now

Similar Jobs

🔥 14 hours ago

Digibee

51 - 200

💼 Consulting

📣 Marketing

📦 Logistics

Cloud Security Engineer integrando segurança a pipelines CI/CD e infraestrutura GCP na Digibee. Protegendo imagens de containers e governando vulnerabilidades na plataforma iPaaS cloud-native low-code.

🗣️🇧🇷🇵🇹 Portuguese Required

Cloud

Docker

Google Cloud Platform

Jenkins

Kubernetes

Open Source

Python

SDLC

Terraform

🕒 3 days ago

Deliverit

1 - 10

🛍️ eCommerce

📦 Logistics

Engenheiro Full-Stack Sênior corrigindo vulnerabilidades em aplicações React e Node.js na Deliver IT. Analisando código, executando scans e fortalecendo práticas DevSecOps.

🗣️🇧🇷🇵🇹 Portuguese Required

JavaScript

Node.js

NoSQL

React

SQL

TypeScript

🕒 3 days ago

ASAAS

501 - 1000

💼 Consulting

🏥 Healthcare

🏨 Hospitality

Analista sênior de riscos e controles de segurança da informação na Asaas, fintech que maximiza a produtividade empresarial com tecnologia. Condução de riscos, controles, TPRM e governança.

🗣️🇧🇷🇵🇹 Portuguese Required

Cloud

🕒 3 days ago

GFT Technologies

10,000+ employees

💼 Consulting

🛡️ Insurance

🔒 Cybersecurity

Senior Cloud Security Engineer securing complex AWS infrastructure for GFT Technologies' regulated financial-services clients. Automating controls, managing vulnerabilities, and supporting compliance audits.

🗣️🇧🇷🇵🇹 Portuguese Required

AWS

Cloud

Terraform

VMware

🕒 4 days ago

Neon

1001 - 5000

💼 Consulting

🛡️ Insurance

💳 Fintech

Engenheiro especialista em segurança cloud liderando redes AWS, firewalls Palo Alto e soluções Zscaler na Neon. Automatização com Terraform e estratégia SASE/Zero Trust para proteger serviços financeiros.

🗣️🇧🇷🇵🇹 Portuguese Required

AWS

Azure

Cloud

Firewalls

Google Cloud Platform

TCP/IP

Terraform