Staff Security Engineer – AppSec

Job not on LinkedIn

🔥 15 hours ago

🇧🇷 Brazil – Remote

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 25%

infoinfo

🗣️🇧🇷🇵🇹 Portuguese Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Stone & Company

Stone & Company

1 - 10 employees

💼 Consulting

🤝 B2B

Consulting • B2B

Stone + Company is a management and strategy consulting firm that empowers corporate clients to achieve exceptional results by transforming disjointed strategies or crafting new ones into a unified plan designed for optimal performance and team synchronization. The firm focuses on delivering fast and effective outcomes for its clients.

📋 Description

• Define security architecture standards with Engineering and Product teams, including for applications with LLMs, agents, and RAG pipelines • Create architectural plans for new systems and technical migration roadmaps for legacy systems • Identify vulnerabilities, assess risks, and help prevent attacks • Participate in security incident analysis and response • Train and raise awareness among development teams about best practices and the safe use of AI assistants • Define and implement security strategies for applications using LLMs and generative AI • Integrate security practices from the beginning of the software development lifecycle • Conduct architecture, code, and design reviews • Define guardrails and standards for LLM risks, such as prompt injection, insecure output handling, data leakage, excessive agency, and denial-of-wallet • Establish guidelines for the safe use of AI-assisted development tools • Develop security standards and best practices • Provide technical security guidance and training • Use and understand automated validation tools in CI/CD, such as SAST, DAST, SCA, and Secret Scanning • Monitor threat trends, including threats to AI systems • Develop solutions to complex security challenges • Hunt for threats in corporate and production environments

🎯 Requirements

• Bachelor's degree, completed or in progress, in Information Security, Computer Science, Information Systems, Software Engineering, or a related field • Knowledge of common attack vectors • Experience conducting threat modeling • Experience with effective protection mechanisms for APIs and mobile applications • Knowledge of fundamental Cloud security services and concepts (AWS, Azure, or GCP) • Familiarity with security risks in applications that use LLMs and generative AI, including the OWASP Top 10 for LLM Applications and MITRE ATLAS • Ability to identify opportunities for improvement, new solutions, and alerts • Influencing and negotiation skills to guide teams • Ability to work autonomously • Concise, candid, and assertive communication, with the ability to translate complex problems into accessible language • Proactive in seeking or requesting information • Ability to work effectively on multidisciplinary teams using agile methodologies • Ability to read and communicate in English • Experience participating in incidents and identifying root causes (a plus) • Experience with projects subject to financial-sector requirements, such as Bacen, PCI, and SOX (a plus) • Strong programming skills (a plus) • Hands-on experience with threat modeling and controls for LLM applications in production (a plus) • Experience securing APIs that expose AI models (a plus) • Experience developing policies and controls for the enterprise use of generative AI tools (a plus) • Knowledge of the NIST AI RMF and ISO/IEC 42001 (a plus)

🏖️ Benefits

• Base salary • Variable compensation package (profit sharing, long-term incentive plan, or commission), depending on role eligibility • Health and dental insurance with co-payments • Hospital Virtual Verde: telemedicine team available 24 hours a day, 7 days a week • Medication allowance • Meal and/or food allowance – Pluxee • Childcare assistance for children up to 5 years and 11 months old • Assistance for employees with children with disabilities • Life insurance • Fuel allowance or commuting assistance • Home office allowance for hybrid or remote contracts • Welcome kit for new parents • SESC partnership • Education benefit: in-house self-development platform (Studa and Stone Library) • Acolhe360°: free emotional support • Quick massage and on-site clinic • Optional benefits: Wellhub, TotalPass, Pet Club, Flash, Férias&Co, transportation vouchers, Allya, and educational partnerships

Apply Now

Similar Jobs

🕒 July 28

iFood

5001 - 10000

🍽️ Food & Beverage

📦 Logistics

📣 Marketing

undefined

🗣️🇧🇷🇵🇹 Portuguese Required

AWS

Cloud

DNS

Kubernetes

Python

Terraform

Go

🕒 June 25

Spassu

1001 - 5000

💼 Consulting

📦 Logistics

📣 Marketing

Information Security Manager leading execution of security services for Spassu. Focused on team leadership, process improvement, and security compliance.

🗣️🇧🇷🇵🇹 Portuguese Required

🕒 June 8

Vidmob

201 - 500

💼 Consulting

📣 Marketing

Staff DevOps Security Engineer at Vidmob architecting and scaling multi-cloud infrastructure. Focusing on security execution and leveraging AI technologies in DevOps operations.

AWS

Cloud

Google Cloud Platform

Grafana

Prometheus

Terraform

🕒 April 29

Grupo Protege

10,000+ employees

🤖 Artificial Intelligence

🤝 B2B

☁️ SaaS

Head of Security overseeing security strategies, compliance, and operations for AI training data platform. Leading security initiatives and building trust with partners in a high-growth environment.

AWS

Azure

Cloud

Google Cloud Platform