Application Security Specialist – Cyber Defense

Job not on LinkedIn

🔥 1 minute ago

🇧🇷 Brazil – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 25%

infoinfo

🗣️🇧🇷🇵🇹 Portuguese Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of ROIT

ROIT

51 - 200 employees

Founded 2016

💼 Consulting

⚖️ Legal

☁️ SaaS

Consulting • Legal • SaaS

ROIT is a Brazilian tax-technology company that provides an integrated ecosystem of SaaS solutions and AI-powered tools to help medium and large companies prepare for and manage the 2026 tax reform. Its offerings include an official tax-reform calculator that reprocesses SPED files and invoices, an Invoice-to-Pay automation suite (with ERP/SAP integrations), Tax Discovery for reclaiming taxes, regulatory consulting and education programs, and ongoing support for compliance and scenario planning.

📋 Description

• Develop and advance ROIT’s Application Security and DevSecOps strategy. • Implement continuous security practices throughout the software development lifecycle (Secure SDLC). • Integrate security tools and controls into CI/CD pipelines. • Implement and advance SAST, DAST, SCA, Secret Scanning, Container Scanning, and IaC Scanning practices. • Define and promote secure standards for APIs, microservices, Kubernetes, and cloud workloads. • Support engineering teams in identifying, prioritizing, and remediating vulnerabilities. • Participate in threat modeling, architecture reviews, and the definition of security controls. • Support initiatives related to ISO 27001, compliance, risk management, and audits. • Monitor critical vulnerabilities, risks, and application security incidents. • Automate security processes and controls whenever possible. • Promote a security culture among technical teams through a consultative and collaborative approach. • Contribute to the organization’s technical maturity in modern security practices.

🎯 Requirements

• Bachelor’s degree in Computer Science, Software Engineering, Information Systems, Information Security, or a related field. • Solid experience in Application Security, DevSecOps, or Software Engineering Security. • Experience working in cloud-native environments and with distributed architectures. • Experience with CI/CD pipelines and security automation. • Knowledge of web application security. • Knowledge of REST APIs and authentication/authorization. • Knowledge of Kubernetes and containers. • Knowledge of security in AWS, Azure, or GCP environments. • Knowledge of the OWASP Top 10. • Knowledge of threat modeling. • Knowledge of vulnerability management. • Experience with SAST, DAST, SCA, Container Security, Secret Detection, and IaC Security tools. • Knowledge of modern engineering and automation practices. • Familiarity with compliance and security frameworks, particularly ISO 27001. • Preferred qualifications: experience in high-scale B2B SaaS environments; experience at technology companies or fintechs; knowledge of event-driven architectures and microservices; experience building automations using AI applied to security; security, cloud, or DevSecOps certifications; experience in regulated environments involving highly critical data.

Apply Now

Similar Jobs

🔥 10 hours ago

DOMVS iT

51 - 200

💼 Consulting

🏥 Healthcare

🏢 Enterprise

Engenheiro Sênior de Segurança da Informação na DOMVS iT, liderando ISO 27001, plataformas de segurança e testes de vulnerabilidade. Governança de riscos de IA, cloud e compliance regulatório.

🗣️🇧🇷🇵🇹 Portuguese Required

Cloud

🔥 10 hours ago

DOMVS iT

51 - 200

💼 Consulting

🏥 Healthcare

🏢 Enterprise

Engenheiro sênior de segurança da informação definindo guardrails e práticas secure-by-design. Protegendo desenvolvimento de software e produtos de IA da DOMVS iT contra vulnerabilidades e ataques emergentes.

🗣️🇧🇷🇵🇹 Portuguese Required

Open Source

🔥 18 hours ago

Digibee

51 - 200

💼 Consulting

📣 Marketing

📦 Logistics

Cloud Security Engineer integrando segurança a pipelines CI/CD e infraestrutura GCP na Digibee. Protegendo imagens de containers e governando vulnerabilidades na plataforma iPaaS cloud-native low-code.

🗣️🇧🇷🇵🇹 Portuguese Required

Cloud

Docker

Google Cloud Platform

Jenkins

Kubernetes

Open Source

Python

SDLC

Terraform

🕒 3 days ago

Deliverit

1 - 10

🛍️ eCommerce

📦 Logistics

Engenheiro Full-Stack Sênior corrigindo vulnerabilidades em aplicações React e Node.js na Deliver IT. Analisando código, executando scans e fortalecendo práticas DevSecOps.

🗣️🇧🇷🇵🇹 Portuguese Required

JavaScript

Node.js

NoSQL

React

SQL

TypeScript

🕒 3 days ago

ASAAS

501 - 1000

💼 Consulting

🏥 Healthcare

🏨 Hospitality

Analista sênior de riscos e controles de segurança da informação na Asaas, fintech que maximiza a produtividade empresarial com tecnologia. Condução de riscos, controles, TPRM e governança.

🗣️🇧🇷🇵🇹 Portuguese Required

Cloud