4 hours ago
São Paulo, BrazilSenior
Responsibilities
- Conduct security assessments and code reviews to identify vulnerabilities and support compliance with security standards.
- Develop and maintain product threat models and risk management strategies.
- Integrate security practices into the software development lifecycle and advise engineering teams on secure application and product design.
- Identify, assess, triage, and coordinate remediation of product vulnerabilities.
- Implement and maintain product security tools and automation systems.
- Participate in incident response activities related to products.
- Provide secure coding and product security training and guidance to development teams.
- Ensure products comply with applicable security standards and regulations.
- Collaborate with engineering, product management, IT, and other teams to incorporate security into product development and deployment.
- Develop and enforce security policies and procedures for product development and maintenance.
Requirements
- Bachelor’s degree in information security, information systems, or a similar field, or similar experience; the degree is preferred.
- Relevant information technology and information security experience.
- Experience with AWS and Terraform.
- Broad exposure to cloud infrastructure, systems analysis, application development, vulnerability scanning, security policies and procedures, and audits.
- Experience with cloud computing environments, infrastructure as code, containers, and functions.
- Strong knowledge of CWE Top 25, OWASP Top 10, and the MITRE ATT&CK matrix.
- Ability to read and understand source code in Ruby, PHP, Go, JavaScript, and Python.
- Experience with automated and manual web, mobile, and traditional application penetration testing.
- Experience building security automations with Python and tools such as Claude Code.
- Experience leveraging AI in security testing workflows and processes.
- Strong networking and information security knowledge.
- Understanding of MVC, JWT, and GraphQL.
- Experience with Burp Suite, SAST, DAST, container scanning, and dependency scanning tools.
- Security certifications such as OSWE, OSCP, CISSP, GPEN, CEH, or CCSP are desired.
- Strong verbal and written communication, analytical, organizational, time-management, problem-solving, and root-cause-analysis skills.
Benefits
- Company-wide bonuses based on monthly sales targets.
- Employee referral bonuses, adoption assistance, tuition reimbursement, certification reimbursement, and certification completion bonuses.
- Modern, high-tech, and fun work environment in the São Paulo, Brazil office.
- An applicant assessment and background check may be part of the hiring procedure.
About KnowBe4
KnowBe4 builds a SaaS platform for security awareness training, phishing/attack simulation, human risk management, collaboration security, and cloud email security for organizations. Its subscription products include AI-driven protection for humans and agents (AIDA) with a proprietary risk score, used by over 70,000 organizations. Founded in 2010 and headquartered in Clearwater, Florida, KnowBe4 is owned by Vista Equity Partners (formerly NASDAQ: KNBE).
