···
Log in / Register

Senior Security Engineer (AppSec, Cloud & Infrastructure) - Remote

Indeed
Full-time
Onsite
No experience limit
No degree limit
79Q22222+22
Favourites
Share
Some content was automatically translatedView Original

Description

Job Summary: We are seeking a security professional to work in AppSec, Cloud Security, and DevSecOps—protecting millions of students and advancing our security culture. Key Highlights: 1. Protect millions of students by building security into the code. 2. Work across the entire stack (app, cloud, and infrastructure) to strengthen security practices. 3. Automate processes and build solutions using Python, Bash, or Go. Description: What we're looking for: * Solid hands-on experience in AppSec, Cloud Security, and DevSecOps, with a broad view across the full development lifecycle. * Practical experience with WAFs (e.g., Cloudflare), including tuning, custom rule creation, and attack mitigation. * Proficiency in SAST, DAST, and SCA tools (e.g., Semgrep, Burp Suite, ZAP, Snyk, Dependabot) integrated into CI/CD pipelines. * Knowledge of container and cloud-native security (Docker, Kubernetes). * Ability to identify and remediate vulnerabilities in modern architectures (Web, Mobile, APIs, Microservices). * Incident response experience, with analytical insight and a prevention-focused mindset. * Familiarity with threat modeling methodologies (STRIDE, PASTA, MAESTRO, OWASP Threat Dragon). * Understanding of LGPD, PCI-DSS, and general compliance best practices. Bonus: * Programming and automation skills in Python, Bash, or Go. * Knowledge of AI/ML security and emerging risks in this domain. What you'll do here: * Be part of the journey protecting millions of students by building security into the code. * Work across the entire stack (app, cloud, and infrastructure), strengthening AppSec, CloudSec, and automation practices. * Integrate security into CI/CD pipelines, applying SAST, DAST, and SCA intelligently and efficiently. * Manage and tune WAFs (e.g., Cloudflare), mitigating attacks and protecting production applications. * Lead threat modeling, architecture reviews, and incident response. * Automate processes and build solutions using Python, Bash, or Go. * Ensure security in cloud environments (AWS) and support secure AI/ML initiatives. * Continuously evolve our security standards, policies, and culture. 2512170202551871252

Source:  indeed View original post
João Silva
Indeed · HR

Company

Indeed
Cookie
Cookie Settings
Our Apps
Download
Download on the
APP Store
Download
Get it on
Google Play
© 2025 Servanan International Pte. Ltd.