20 days ago
Remote, ColombiaMid Level / Senior
Responsibilities
- Serve as the security partner for Product and maintain visibility into applications, components, data, dependencies, attack surfaces, and priority risks.
- Apply threat modeling, architecture reviews, abuse-case analysis, secure code review, and security assessments to APIs, payment flows, authentication, authorization, business logic, and cloud configurations.
- Design, implement, operate, and evaluate AI- and LLM-assisted AppSec capabilities for code review, testing, finding prioritization, and remediation.
- Define guardrails for development assistants and agents, including approved tools and models, code and data handling, secret protection, permission scope, execution isolation, and action traceability.
- Extend the secure SDLC to formal and informal development such as prototypes, scripts, vibe coding, automations, and internal tools.
- Integrate and tune SAST, SCA, secret detection, IaC and container security, DAST, API testing, and manual analysis with risk-based gates.
- Strengthen software supply-chain security through component inventories, dependency and provenance controls, artifact management, versioning, and verified remediation.
- Define secure development standards based on OWASP, NIST SSDF, and PCI DSS guidance.
- Collaborate with Offensive Security and engineering squads to validate exploitability, prioritize real risk, plan remediation, and verify closure.
- Develop the Security Champions program, practical guidance, laboratories, and reusable secure-development patterns.
- Measure security coverage, risk, remediation time, recurrence, signal quality, and process friction, and communicate trends and investment needs.
- Participate in application and AI-generated software incidents and convert lessons learned into new controls.
Requirements
- At least 4 years of experience in Application Security, Product Security, secure code review, or security-focused software development.
- Demonstrated experience improving the security posture of a production product, not only reporting findings.
- Practical experience building or operating AI or LLM automations for code analysis, testing, triage, or remediation, including evaluating their quality, limitations, and risks.
- Strong knowledge of application and API vulnerabilities, including authorization, authentication, business logic flaws, injection, SSRF, secret handling, data integrity, and misconfiguration.
- Experience with threat modeling, architecture reviews, secure code review, and vulnerability management through verified remediation.
- Experience integrating and tuning SAST, SCA, secret detection, IaC or container analysis, DAST, and API testing into CI/CD.
- Ability to program and automate in at least one production-relevant language such as Python, Java, Go, JavaScript, TypeScript, Ruby, or Kotlin.
- Comfort reading unfamiliar code and delivering maintainable tooling.
- Practical knowledge of AI-assisted development risks, including prompt injection, excessive permissions, secret or code exposure, malicious or nonexistent dependencies, untrusted instructions, and unvalidated agent actions.
- Experience with cloud architectures, preferably AWS, as well as APIs, microservices, containers, serverless, and infrastructure as code.
- Critical thinking to distinguish exploitability and real risk from noise and select controls proportional to customer, data, and funds impact.
- Clear communication and ability to influence without formal authority across Engineering, Product, Platform, Data, AI, and Offensive Security.
- Preferred qualifications include fintech, payments, digital banking, or sensitive transaction-data experience; PCI DSS 4.0.1, OWASP ASVS 5.0, OWASP AISVS, OWASP Top 10 for Agentic Applications, or NIST SSDF knowledge; experience securing agents, LLM applications, MCP integrations, or machine-learning pipelines; Security Champions, bug bounty, pentesting, or secure-pattern experience; advanced English; and certifications such as OSWE, GWEB, CSSLP, or AWS Certified Security.
Benefits
- Indefinite-term employment contract.
- Fully remote, full-time work arrangement.
- Health insurance policy.
- Annual performance bonus paid in shares or money.
- Competitive salary.
- Financial support for education.
- World-class technologies and processes.
- Additional days off beyond vacation.
- Vision-health bonus.
- Emotional well-being support.
