Security Engineering Analyst — AppSec | Senior

full timeengineeringremote FROM 🇧🇷
Open to candidates in: Brazil
Jobgether
🏭 Not specified
📍 N/A
👤 Not specified

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Engineering Analyst — AppSec | Senior based in Brazil.

This senior role focuses on strengthening application security across the software development lifecycle.
You will define and evolve secure development practices, security requirements, and controls across applications and engineering workflows.
The position combines application security, cloud security, DevSecOps, threat modeling, and secure architecture.
You will partner closely with developers, architects, DevOps engineers, and other technical teams to identify and mitigate security risks.
A key focus will be embedding automated security controls into CI/CD pipelines through modern security testing and scanning practices.
You will also contribute to secure AWS architectures and help advance the organization’s overall culture of secure development.
This is a fully remote opportunity for an experienced security professional who enjoys working at the intersection of security, engineering, and technology.


Accountabilities:

  • Define and continuously improve the corporate Secure Software Development Life Cycle (SSDLC), including minimum security requirements for applications.
  • Establish and implement Security Gates across development processes and CI/CD pipelines, integrating security controls throughout the application lifecycle.
  • Support the evolution of secure development practices and promote a strong security-by-design culture across engineering teams.
  • Participate in projects from early conception and architecture stages, conducting security assessments and identifying risks, vulnerabilities, and appropriate mitigation measures.
  • Apply Threat Modeling and Security by Design principles while collaborating with architects, developers, DevOps engineers, and other technical teams.
  • Identify, analyze, and support the remediation of application vulnerabilities, including risks associated with code, dependencies, infrastructure, and configurations.
  • Support development teams in adopting Secure Coding practices and conduct security-focused code reviews.
  • Assess APIs, microservices, containers, and other software components from an application security perspective.
  • Integrate security tools into CI/CD pipelines, covering practices such as SAST, DAST, SCA, Secret Scanning, IaC Scanning, and Container Security.
  • Support the implementation and management of Software Bills of Materials (SBOM) and define policies and criteria for Security Gates.
  • Promote automation of security controls throughout development and deployment pipelines.
  • Support secure architecture initiatives in AWS environments, including the assessment of cloud security configurations and controls.
  • Work with services such as AWS API Gateway and AWS Security Hub to identify and address risks affecting cloud infrastructure and applications.
  • Requirements:

    • Proven experience working in medium- to large-scale corporate environments with complex technology ecosystems.
    • Experience working directly with software development teams and collaborating across technical functions.
    • Experience defining, implementing, or evolving security processes and controls.
    • Strong knowledge of SSDLC, Secure Software Development, and Security by Design principles.
    • Practical understanding of Threat Modeling, OWASP Top 10, and OWASP ASVS.
    • Knowledge of Secure Coding, API Security, application architecture, and microservices architecture.
    • Understanding of DevOps, CI/CD, DevSecOps, and application vulnerability management.
    • Experience with at least part of the following security technologies and practices: SAST, DAST, SCA, Secret Scanning, IaC Scanning, Container Security, SBOM, CI/CD, and DevSecOps.
    • Experience with AWS and knowledge of cloud security and architecture.
    • Familiarity with AWS API Gateway and AWS Security Hub is desirable.
    • Strong analytical and problem-solving skills, with the ability to translate security risks into practical mitigation measures.
    • Strong collaboration and communication skills, particularly when working with development, architecture, and infrastructure teams.
    • Benefits:

      • Fully remote work model.
      • Full-time employment.
      • Opportunity to work with modern technologies across application security, cloud, DevSecOps, and AI-driven environments.
      • Collaboration with multidisciplinary engineering and technology teams.
      • Opportunities for professional development and exposure to evolving security practices and technologies.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether?    Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.     #LI-CL1
Jobgether
🏭 Not specified
📍 N/A
👤 Not specified