Faster chat, better deals — Get the App

AppSec Developer / Application Security Engineering

Indeed

Company

Job typeFull-time
Workplace typeHybrid
Experience levelMore than 10 years
Education levelNo degree limit

Description

We are seeking a professional with a focus on Application Security (AppSec), with strong expertise in secure development, code review, vulnerability analysis, and advancing security practices throughout the software development lifecycle. We seek someone with a "security professional who can develop" profile — capable of working directly in code, supporting development teams, and contributing to building the company's security culture and roadmap. **Key Responsibilities** Develop, maintain, and enhance applications within the e-Cidade ecosystem; Conduct security assessments of web applications and REST APIs; Perform vulnerability testing (application penetration testing), risk analysis, and technical validation of vulnerabilities; Apply static application security testing (SAST) and dynamic application security testing (DAST) techniques aligned with the Secure Software Development Lifecycle (SSDLC); Participate in investigation and response to real-world application-related security incidents; Analyze logs, trace suspicious behaviors, and identify potential attack vectors; Directly remediate vulnerabilities securely in source code; Provide technical support to development teams in adopting security best practices; Contribute to defining and implementing the company’s future DevSecOps pipeline; Help build the organization’s Application Security roadmap and AppSec maturity model; Conduct secure code reviews; Mitigate common vulnerabilities, especially those listed in the OWASP Top 10; Assess application authentication, authorization, session management, and access control; Perform analysis of vulnerable dependencies and third-party libraries (SCA – Software Composition Analysis); Support implementation of secure practices in CI/CD pipelines; Contribute to adaptations required by the LGPD (Brazilian General Data Protection Law) for public systems and processing of sensitive data. **Primary Technologies and Stack:** e-Cidade Stack - PHP - PostgreSQL - JavaScript - Laravel - Vue.js - Linux / Apache - Proprietary legacy codebase (initiated in 2002 using PHP and PostgreSQL) **Desirable Tools and Techniques** Kali Linux Metasploit Snort SonarQube SAST/DAST tools SCA tools GitLab CI Docker CI/CD **Desirable Technical Knowledge** Web application security (AppSec); OWASP Top 10; OWASP ASVS; SSDLC (Secure Software Development Lifecycle); REST API security; Application hardening; Vulnerability analysis and remediation; Secure code review; Authentication and authorization; Secure session management; Prevention of SQL Injection, XSS, CSRF, SSRF, RCE, and other web vulnerabilities; LGPD applied to public systems and applications; DevSecOps knowledge; Security integration into CI/CD pipelines; Containers and Docker environments; Git version control; Log analysis and incident investigation; Concepts of ISO 27001 and CIS Controls. **Desired Profile** Analytical and investigative mindset; Interest in offensive security applied to secure development; Ability to work effectively with legacy code; Strong communication skills with technical teams; Ability to identify risks and propose improvements; Interest in building security processes and culture; Proactivity and autonomy; Continuous interest in learning and staying updated in the field of security. **Advantages** Prior experience in AppSec; Experience with web application penetration testing; Participation in Bug Bounty programs; Knowledge of DevSecOps; Familiarity with public/government systems; Certifications or studies related to information security; Experience analyzing vulnerabilities in PHP/Laravel applications. **Work Model** CLT employment regime Remote work **About the Opportunity** The professional will directly contribute to advancing the e-Cidade’s security maturity, helping structure secure development practices, continuous vulnerability analysis, and the future establishment of the company’s security pipeline. The role focuses exclusively on application security (AppSec), with no responsibilities related to infrastructure or network/server administration. Benefits: * Medical insurance * Dental insurance * Food allowance * Meal voucher Work location: Hybrid remote work based in Niterói, RJ

Some content was automatically translated

Posted by

João Silva

Indeed · HR

Location

João Silva

Indeed · HR

Similar jobs

AppSec Developer / Application Security Engineering job by Indeed in 2026 | ok.com