Description
Job Summary:
As an Application Security Manager, you will design and scale innovative and secure systems, lead the security strategy and roadmap, and ensure the security of critical initiatives.
Key Highlights:
1. Design and scale innovative and secure systems in a dynamic environment.
2. Lead the application security strategy and roadmap.
3. Drive technical research and the secure adoption of generative AI.
As an **Application Security Manager** at Mercado Livre, you will design and scale innovative and secure systems that solve real-world, high-impact problems. You will work in a dynamic environment with cutting-edge technology, applying sound engineering practices, proprietary AI models, and continuous learning—all to democratize e-commerce and financial services across Latin America.
Imagine\-yourself leading challenging, dynamic, and innovative projects and being **responsible for:**
* Leading the application security strategy and roadmap for Mercado Pago, defining frameworks, processes, and team metrics—including threat modeling, penetration testing, vulnerability management, and forensic readiness.
* Ensuring the security of every critical initiative through early review of proposals and comprehensive coverage of the penetration testing program across web platforms, APIs, mobile applications, and generative AI agents.
* Driving technical research to identify high-impact vulnerabilities and leading the secure adoption of generative AI—including practices such as prompt hardening and assisted review.
* Managing vulnerabilities from multiple sources—including bug bounty programs, automated tools, and external reports—to maintain zero incidents due to exploitation.
* Managing coordinators and technical teams, overseeing goal tracking and driving operational excellence in security.
What we’re looking for in you:
* Proven experience in cybersecurity, with a focus on application security and direct management of technical teams and leaders in the field.
* Expertise in threat modeling, application maturity programs, and execution of security testing across web, API, mobile, cloud, and agent-based application ecosystems.
* Knowledge of microservices architectures, identity and authorization management, cloud infrastructure, containers, security in continuous integration pipelines, applied cryptography for payments, and regulatory frameworks such as PCI DSS and ISO 27001\.
* Understanding of systemic security risks and generative AI model risks—with advanced industry certifications and publications in the field being highly desirable.
**Are you excited to leave your mark on Latin America’s technology landscape?** Apply now and join our mission!
Work mode: Hybrid. Office in Osasco, SP