Description
### **About Jusbrasil**
Transforming the justice system with technology is not a trivial challenge. Therefore, Jusbrasil positions itself as an **AI-first** company that leverages **Generative AI, massive datasets, and cutting-edge engineering** to solve complex problems and create real, scalable impact.
We are at an inflection point: the GenAI revolution is redefining the market, and we hold a **rare opportunity to lead the technological transformation of Brazil’s legal system**.
We handle **petabytes of data**, **billions of documents**, and challenges around **scale, accuracy, and relevance** worthy of the world’s largest tech companies.
Our team operates with **high talent density**, autonomy, and purpose. Hundreds of exceptional people across more than **40 cities in Brazil and abroad** are united by the same mission: building solutions that improve access to justice and strengthen trust in social relationships.
Here, we value those who pursue **deep professional mastery**, act with **clarity of purpose**, and possess the energy to consistently tackle major challenges with excellence.
We are building something significant—and we seek people eager to be part of this story, **with intensity, focus, and excellence**.
### **Jusbrasil by the numbers:**
Over 1.2 billion public-interest legal documents
Over 1 PB of data in our technology infrastructure
Over 30 million users
Over 500 collaborators
Over 80% of registered Brazilian lawyers
**About the role**
The Security Partner (AppSec) will ensure Jusbrasil’s B2B products are built on a solid security foundation—operating integrally and embedded within the Jus Soluções engineering team. This is a hands-on role requiring a builder mindset: rather than merely reviewing completed work, we expect someone who engages from the earliest stages of the development lifecycle, anticipates risks, and implements tangible solutions.
**Key responsibilities**
* Serve as the security focal point within Jus Soluções, participating in planning sessions, refinement meetings, and RFCs with engineering and product teams.
* Lead the implementation of robust authentication and Single Sign-On (SSO), including domain separation and integration with external identity providers.
* Ensure applications, APIs, and integrations are developed following Secure-by-Design principles—from design through delivery.
* Conduct recurring threat modeling for products and critical workflows, identifying and prioritizing risks based on business impact.
* Perform continuous security reviews—including code, architecture, and external integrations—in collaboration with engineering teams.
* Build and maintain AppSec practices: secure coding guidelines, review checklists, and documentation of security-related technical decisions.
* Translate technical risks into business impact for product stakeholders, leadership, and customers—including actionable reports and recommendations.
**What we’re looking for**
* Solid software development experience
* Practical knowledge of Application Security: OWASP Top 10, API Security, authentication (OAuth 2.0, JWT, SSO, OIDC), and data protection.
* Experience with cloud platforms (GCP, AWS, or Azure) and modern architecture: microservices, REST/gRPC APIs, and external integrations.
* Ability to influence teams without direct authority—acting as a technical partner.
* Fluency in AI: Experience using Generative AI tools as part of the workflow.
* Proactive, solution-oriented profile, with autonomy to build solutions from scratch and comfort operating in ambiguous environments.
**Nice-to-have qualifications**
* Experience with LGPD and data protection requirements applied to digital products
* Familiarity with secure infrastructure and open-source-based project development.