Description
**Job Description****:**
**Job Description**
The AppSec / SecOps Specialist will be responsible for ensuring that security is integrated into the development lifecycle from its earliest stages, defining standards, automating controls, and implementing quality gates in CI/CD pipelines. This is a technical and strategic role with a strong focus on vulnerability prevention, security governance, and enabling development teams.
This professional will define security policies, integrate tools, and continuously evolve DevSecOps practices, ensuring alignment with industry best practices, compliance requirements, and operational efficiency.
**Key Responsibilities:**
* Define and implement the corporate **quality gates** model within CI/CD pipelines, ensuring clear security criteria prior to promotion to production.
* Integrate **AppSec** tools—such as SonarQube and Checkmarx—into development pipelines, ensuring automated and standardized analysis.
* Establish policies and criteria for **vulnerability management**, including handling exceptions, false positives, and defining blocking rules.
* Define and evolve the **secrets management** strategy, eliminating hardcoded credentials and reducing exposure risks.
* Develop and implement **policy-as-code** practices to enable automated governance and consistent controls.
* Support engineering squads with secure development best practices, balancing security requirements and productivity.
* Create and maintain security documentation, standards, and guidelines to support technical teams.
* Collaborate with security, engineering, and compliance teams to advance **DevSecOps** and SecOps practices.
**Required Knowledge:**
* Solid experience in **AppSec, SecOps, or DevSecOps**, with hands-on application of security throughout the development lifecycle.
* Familiarity with tools such as **SonarQube, Checkmarx, GitHub Advanced Security**, or equivalents.
* Experience with **SAST**, quality gates, and vulnerability management in CI/CD pipelines.
* Practical experience with **secrets management**, application security, and protection of sensitive data.
* Knowledge of **policy-as-code**, control automation, and technical compliance.
* Experience with modern development environments, version control (Git), and automated pipelines.
* Analytical, meticulous, and collaborative mindset, capable of balancing **security and agility** across teams.
**Additional Information:**
* Contract Type: PJ (Individual Contractor)
**Location**
São Paulo, SP, BR