Overview
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Engineering Analyst — AppSec | Senior bas
Full job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Engineering Analyst — AppSec | Senior based in Brazil. This senior role focuses on strengthening application security across the software development lifecycle. You will define and evolve secure development practices, security requirements, and controls across applications and engineering workflows. The position combines application security, cloud security, DevSecOps, threat modeling, and secure architecture. You will partner closely with developers, architects, DevOps engineers, and other technical teams to identify and mitigate security risks. A key focus will be embedding automated security controls into CI/CD pipelines through modern security testing and scanning practices. You will also contribute to secure AWS architectures and help advance the organization’s overall culture of secure development. This is a fully remote opportunity for an experienced security professional who enjoys working at the intersection of security, engineering, and technology.
Define and continuously improve the corporate Secure Software Development Life Cycle (SSDLC), including minimum security requirements for applications. Establish and implement Security Gates across development processes and CI/CD pipelines, integrating security controls throughout the application lifecycle. Support the evolution of secure development practices and promote a strong security-by-design culture across engineering teams. Participate in projects from early conception and architecture stages, conducting security assessments and identifying risks, vulnerabilities, and appropriate mitigation measures. Apply Threat Modeling and Security by Design principles while collaborating with architects, developers, DevOps engineers, and other technical teams. Identify, analyze, and support the remediation of application vulnerabilities, including risks associated with code, dependencies, infrastructure, and configurations. Support development teams in adopting Secure Coding practices and conduct security-focused code reviews. Assess APIs, microservices, containers, and other software components from an application security perspective. Integrate security tools into CI/CD pipelines, covering practices such as SAST, DAST, SCA, Secret Scanning, IaC Scanning, and Container Security. Support the implementation and management of Software Bills of Materials (SBOM) and define policies and criteria for Security Gates. Promote automation of security controls throughout development and deployment pipelines. Support secure architecture initiatives in AWS environments, including the assessment of cloud security configurations and controls. Work with services such as AWS API Gateway and AWS Security Hub to identify and address risks affecting cloud infrastructure and applications. Requirements: Proven experience working in medium- to large-scale corporate environments with complex technology ecosystems. Experience working directly with software development teams and collaborating across technical functions. Experience defining, implementing, or evolving security processes and controls. Strong knowledge of SSDLC, Secure Software Development, and Security by Design principles. Practical understanding of Threat Modeling, OWASP Top 10, and OWASP ASVS. Knowledge of Secure Coding, API Security, application architecture, and microservices architecture. Understanding of DevOps, CI/CD, DevSecOps, and application vulnerability management. Experience with at least part of the following security technologies and practices: SAST, DAST, SCA, Secret Scanning, IaC Scanning, Container Security, SBOM, CI/CD, and DevSecOps. Experience with AWS and knowledge of cloud security and architecture. Familiarity with AWS API Gateway and AWS Security Hub is desirable. Strong analytical and problem-solving skills, with the ability to translate security risks into practical mitigation measures. Strong collaboration and communication skills, particularly when working with development, architecture, and infrastructure teams. Benefits: Fully remote work model. Full-time employment. Opportunity to work with modern technologies across application security, cloud, DevSecOps, and AI-driven environments. Collaboration with multidisciplinary engineering and technology teams. Opportunities for professional development and exposure to evolving security practices and technologies.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
laptop-ats-crawler v3
JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from jobgether (lever) →