4 days ago
São Paulo, BrazilMid Level / Senior
Responsibilities
- Drive application security initiatives including threat modeling, secure code review support, API testing, and security pipeline improvements.
- Assess and secure AI and agentic workflows by reviewing prompts, preventing destructive actions, and controlling data exposure.
- Build SIEM detection rules, alert pipelines, and automated response playbooks using Datadog SIEM, CrowdStrike, and Cloudflare.
- Improve incident response readiness through playbooks, tabletop exercises, and forensic procedures.
- Conduct cloud security assessments across AWS and Kubernetes environments.
- Establish and operate a scalable vendor security assessment and third-party due diligence process.
Requirements
- 4–7 years of information security experience, ideally building or significantly shaping security functions at startups or high-growth companies.
- Hands-on experience securing cloud infrastructure using AWS and Kubernetes.
- Familiarity with threat modeling, secure code review, CI/CD pipeline hardening, and API security testing.
- Ability to assess and secure LLM integrations, MCP servers, and automated AI workflows using practical guardrails.
- Working knowledge of SIEM platforms and detection engineering, including writing detection rules.
- Experience with endpoint security tooling, EDR/XDR, identity and access management, Google Workspace, Okta or Cloudflare Access, SSO, and SCIM.
- Experience conducting or contributing to vendor security assessments and third-party due diligence.
- Strong written and verbal communication skills in English.
Benefits
- Competitive salary and benefits.
- Stock options.
- Discretionary performance bonus.
- Latest tools and technology.
- Opportunity to help build a fintech app in Latin America.
- Hybrid office policy requiring 3–4 days per week in-office.