Security Engineer – DevSecOps, AppSec

🔥 5 minutes ago

🇧🇷 Brazil – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 10%

infoinfo

🗣️🇧🇷🇵🇹 Portuguese Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Saipos | Sistema para Restaurante

Saipos | Sistema para Restaurante

51 - 200 employees

Founded 2017

🍽️ Food & Beverage

📦 Logistics

💼 Consulting

Food & Beverage • Logistics • Consulting

Saipos is a comprehensive restaurant management system that offers solutions for various types of food establishments, including delivery services, pizzerias, sushi bars, and franchises. With features like digital menus, automated delivery routing, and financial control, Saipos aims to enhance operational efficiency and improve customer service for its users. The software integrates with major delivery apps and is designed to streamline business processes within the food service industry, making it an ideal choice for over 10,000 restaurants looking to optimize their management practices.

📋 Description

• Implement and maintain SAST, DAST, and SCA tools in the CI/CD pipeline (Bitbucket/GitHub/GitLab) • Implement, maintain, operate, and enhance Secrets Manager and Vault • Perform continuous secret scanning across repositories and lead remediation of findings with development teams • Conduct security-focused code reviews for critical features, including authentication, authorization, external integrations, and sensitive data handling • Harden infrastructure, including Terraform state, IAM policies, AWS configurations, and Security Groups • Support the remediation of technical findings identified by security analysis tools, external penetration tests, and internal scans • Build and lead the Security Champions program by identifying points of contact within development squads and structuring ongoing training • Conduct threat modeling for new features and critical integrations in partnership with product and engineering teams • Define and document security requirements throughout the SDLC, from design through deployment • Assess the security of internal and external APIs, partner integrations, and authentication flows

🎯 Requirements

• Hands-on experience with CI/CD pipelines and integrating security tools (SAST, SCA, and secret scanning) into the development workflow. • Solid knowledge of AWS, including IAM, S3, Lambda, Security Groups, VPC, KMS, and cloud security best practices. • Experience with infrastructure as code (Terraform), including the ability to identify and remediate security issues in IaC. • Knowledge of the OWASP Top 10 and OWASP API Security Top 10, with the ability to apply them to code and architecture reviews. • Ability to write scripts and automations for analysis and remediation using Python or Bash. • Ability to read and interpret code in at least one programming language used by the product. • Critical thinking and risk analysis. • Proactivity, initiative, and the ability to anticipate needs. • Strong interpersonal communication skills when working with development teams. • Technical independence. • Collaboration and teamwork. • Ability to explain concepts clearly and transfer knowledge. • Strong ownership and results orientation. • Experience with Bitbucket (a plus). • Practical experience managing secrets with HashiCorp Vault and/or AWS Secrets Manager (a plus). • Familiarity with DAST tools (OWASP ZAP, Burp Suite) integrated into pipelines (a plus). • Knowledge of security for Docker containers and image repositories (a plus). • Experience applying CIS Benchmarks to AWS workloads (a plus). • Basic knowledge of mobile security or binary analysis (a plus). • Familiarity with cloud posture management tools (Wiz, Prisma Cloud, AWS Security Hub, GuardDuty) (a plus). • Experience conducting security reviews of serverless architectures (Lambda, API Gateway) (a plus). • Preferred certifications: AWS Certified Solutions Architect – Associate; AWS Certified Solutions Architect – Professional; AWS Certified Security – Specialty; Certified DevSecOps Professional (CDP) – Practical DevSecOps; HashiCorp Vault Associate.

🏖️ Benefits

• Contractor arrangement (PJ) with 30 days of paid time off • Health and dental insurance with premiums 100% covered by Saipos (copayments apply to consultations and exams) • Life insurance • Birthday month day off • Wellhub • Complete equipment package • Daily transportation allowance of BRL 22 for on-site work • Home office allowance of BRL 180.00 for professionals working remotely at least three days per week • Extended maternity and paternity leave

Apply Now

Similar Jobs

🔥 18 hours ago

Cooperativa Central Ailos

1001 - 5000

🛡️ Insurance

💼 Consulting

📦 Logistics

Especialista em segurança protegendo cloud, redes e operações SecOps da Central Ailos, cooperativa financeira. Operando controles Blue Team, monitoramento, resposta a incidentes e automação.

🗣️🇧🇷🇵🇹 Portuguese Required

AWS

Azure

Cloud

Firewalls

Google Cloud Platform

Kubernetes

Python

🕒 Yesterday

Monkey

51 - 200

💳 Fintech

☁️ SaaS

🤝 B2B

Analista de Governança e Segurança da Informação apoiando auditorias, riscos e controles na Monkey. Empresa de tecnologia financeira que simplifica transações entre grandes empresas e fornecedores.

🗣️🇧🇷🇵🇹 Portuguese Required

Cloud

🕒 Yesterday

Localiza&Co

10,000+ employees

🚘 Automotive

📦 Logistics

✈️ Travel

Product Owner Sênior liderando IAM, AI Security e Engenharia de Segurança na Localiza&Co, plataforma de mobilidade sustentável. Conectando negócio, tecnologia e cibersegurança para reduzir riscos e acelerar inovação.

🗣️🇧🇷🇵🇹 Portuguese Required

AWS

Azure

Cloud

Cyber Security

Google Cloud Platform

SDLC

🕒 Yesterday

GFT Technologies

10,000+ employees

💼 Consulting

🛡️ Insurance

🔒 Cybersecurity

Senior Cloud Security Engineer fortalecendo ambientes AWS regulados da GFT Technologies. Desenvolvendo controles Terraform, compliance, threat modeling e resiliência para clientes financeiros.

🗣️🇧🇷🇵🇹 Portuguese Required

AWS

Cloud

Terraform

VMware

🕒 Yesterday

Grupo Boticário

10,000+ employees

🏭 Manufacturing

🍽️ Food & Beverage

💄 Beauty

Analista de Governança de SI no Grupo Boticário, grupo brasileiro de beleza presente em mais de 40 países. Estruturando processos, indicadores e iniciativas de segurança da informação.

🗣️🇧🇷🇵🇹 Portuguese Required