




Description: For this challenge, we need you to: * Proven experience in software development, with a focus on DevSecOps/AppSec. * Demonstrated experience in fixing code vulnerabilities and building secure architectures. * Proficiency in programming languages such as Python, Java, JavaScript, or Go, and development frameworks. * Expertise in AppSec best practices, including OWASP Top 10, secure coding guidelines, and zero trust principles. * Experience with CI/CD (Jenkins, GitLab CI, GitHub Actions) and security gates. * Advanced knowledge of cloud environments (AWS, Azure, OCI, and GCP). * Familiarity with tools such as SonarQube, Snyk, Veracode, Burp Suite. * Experience with IaC (Terraform, Ansible, CloudFormation) with a security focus. * Leadership, communication, and problem-solving skills. * Bachelor’s degree in Computer Science, Software Engineering, Information Security, or related fields. * Advanced English for technical reading and international collaboration. Additionally, it will be a differentiator if you have: * Cloud security certifications (AWS, Azure, OCI, and GCP). * DevSecOps certifications (e.g., Certified DevSecOps Professional) or security certifications (e.g., CISSP, CEH). As an Information Security Specialist \| DevSecOps, you will: * Integrate security practices (AppSec) throughout the software development lifecycle. * Fix vulnerabilities in source code and guide the creation of secure architectures. * Develop and evolve protection architectures for Web applications and APIs. * Automate security testing in CI/CD pipelines (SAST, DAST, dependency analysis, and compliance). * Design and implement security controls in cloud environments (AWS, Azure, GCP), including defining baselines and roadmaps for engineering and SRE teams. * Lead shift\-left security initiatives and promote DevSecOps best practices. * Conduct security audits on code and infrastructure, recommending and implementing fixes. * Mentor Security Champions and foster a culture of secure development. * Monitor emerging threats and update mitigation processes. * Participate in post\-incident analyses and implement preventive improvements. 2510260202221834042


