Overview
What We're Looking For You'll be ARQ's first Security Engineer based in Brazil – it's the chance to lay the foundation for how we do security in the region and shape how that function grows from here. You'll work closely with our global security team but have real autonomy in deciding what "good" looks like locally, from day one. We're looking for someone who enjoys a multidisciplinary role. Security at ARQ spans Application Security, Security Operations, and Governance/Risk/Compliance, and we need someone comfortable moving across at least two of these three areas – because in a founding role, there's no one else to hand off the parts that don't fit your specialty. What you'll do Support application security work: threat modelling sessions, secure code review, API security testing, and CI/CD pipeline checks Help review and monitor AI/agentic workflows for prompt risks, unsafe automated
Full job description
Full Job Description
What We're Looking For
You'll be ARQ's first Security Engineer based in Brazil – it's the chance to lay the foundation for how we do security in the region and shape how that function grows from here. You'll work closely with our global security team but have real autonomy in deciding what "good" looks like locally, from day one.
We're looking for someone who enjoys a multidisciplinary role. Security at ARQ spans Application Security, Security Operations, and Governance/Risk/Compliance, and we need someone comfortable moving across at least two of these three areas – because in a founding role, there's no one else to hand off the parts that don't fit your specialty.
What you'll do
-
Support application security work: threat modelling sessions, secure code review, API security testing, and CI/CD pipeline checks
-
Help review and monitor AI/agentic workflows for prompt risks, unsafe automated actions, and data exposure
-
Build and maintain SIEM detection rules, alert pipelines, and response playbooks (Datadog SIEM, CrowdStrike, Cloudflare), owning detection coverage for a defined set of systems end-to-end
-
Support incident response: triage alerts, execute IR playbooks, and help run tabletop exercises
-
Conduct cloud security assessments across AWS and Kubernetes environments under the guidance of senior team members
-
Execute vendor security assessments using the established due diligence framework, owning the review process for a portion of the vendor pipeline
What you'll need
-
2–4 years in information security or a closely related technical role (security operations, cloud/infra engineering with a security focus, or similar)
-
Working experience with at least one cloud environment (AWS preferred) and familiarity with Kubernetes fundamentals
-
Basic familiarity with application security concepts: threat modelling, secure code review, or API security testing
-
Curiosity about AI/agentic tooling risks (LLM integrations, MCP servers, automated workflows) – prior hands-on experience is a plus, not required
-
Exposure to SIEM platforms and an interest in detection engineering – you've written or tuned at least a few detection rules
-
Strong written and verbal communication in English
Benefits
-
Competitive salary and benefits
-
Stock options, so you own part of what you build
-
Discretionary performance bonus
-
The latest tools and technology
-
A world-class team that will challenge and grow your skills
-
The opportunity to help build the best fintech app in Latin America
-
Office Policy: 3-4 days a week in-office
Tips for this job
Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
Discovered directly from the employer’s public Ashby Job Postings API. The complete public role content and compensation metadata were normalized into safe candidate-facing sections.
Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
A R Q Careers ↗Browse current Job and Scholarship listings from A R Q Careers →