




Job Summary: A security professional to work with agile teams, ensuring Security by Design, defining secure architectures, implementing DevSecOps, and supporting vulnerability remediation. Key Highlights: 1. Experience with security in agile environments and squads 2. Proficiency in DevSecOps, CI/CD, containers, and Kubernetes 3. Technical security reference for product and engineering teams Description: * Experience with security in agile development environments, working directly with squads. * Strong knowledge of web application architecture, APIs, microservices, and authentication/authorization (OAuth, JWT, etc.). * Experience with security tools throughout the development lifecycle: SAST, DAST, SCA, Secret Scanning, IaC Scanning. * Mastery of DevSecOps concepts and tools (CI/CD, security pipelines, containers, Kubernetes). * Ability to translate technical risks into accessible language for developers and product managers. * Knowledge of OWASP Top 10, ASVS, MITRE ATT\&CK. * Bachelor's degree in Computer Science, Engineering, Information Systems, or related fields. Advantages * Certifications such as OSWE, GWAPT, CSSLP, DevSecOps Professional, ISO27001, AWS Security. * Prior experience in regulated environments (LGPD, PCI\-DSS, BACEN, Anatel). * Experience in multi-cloud environments (AWS, Azure, GCP) with a security focus. * Participation in shift\-left initiatives and security culture transformation in development. * Ability to lead technical workshops, secure code reviews, and developer training. * Serve as the technical security reference for product and engineering teams. * Ensure application of Security by Design principles during architecture, development, and integration phases. * Collaborate on defining and reviewing secure architectures for applications, microservices, and APIs. * Actively participate in development cycles, advising on security risks and best practices. * Implement and promote DevSecOps practices: automated testing, secure pipelines, secret management, secure containers. * Support analysis and remediation of vulnerabilities identified by SAST, DAST, SCA tools, and manual reviews. * Conduct threat modeling and risk assessments for new products and features. * Act as a bridge between engineering and security to ensure compliance and privacy requirements are considered from the outset. 2511190202461603970


