XP Inc.

Analista Sênior de AppSec

XP Inc.
Apply
24 days ago
São Paulo, BrazilSenior

Responsibilities

  • Analyze applications, APIs, and microservices for vulnerabilities and recommend secure-development remediation.
  • Structure and operate the AppSec program, including SAST, DAST, SCA, alert triage, vulnerability management, and remediation tracking.
  • Conduct threat modeling and security reviews for software architectures, APIs, authentication, authorization, encryption, and sensitive-data protection.
  • Build and improve AppSec controls, including automation scripts, hardening scripts, security-as-code policies, security gates, and CI/CD integrations.
  • Develop integrations among security tools, SIEM systems, ticketing systems, dashboards, and scanners using APIs, webhooks, and SDKs.
  • Assess the security of AI and LLM solutions and propose controls for prompt injection, data poisoning, sensitive-data exposure, and hallucinations.
  • Collaborate with DevOps and engineering teams to integrate security into pipelines with a shift-left approach.
  • Guide developers through secure-coding guidelines, training, code reviews, and API security best practices.
  • Monitor emerging vulnerabilities, critical CVEs, attack techniques, and trends in software, API, and AI security.

Requirements

  • Solid experience in Application Security and application-security analysis throughout the SDLC.
  • Experience with SAST, DAST, SCA, and secret-scanning tools and processes, including CodeQL, Sonatype, Dependabot, Snyk, and Checkmarx.
  • Deep knowledge of OWASP Top 10 and OWASP ASVS.
  • Ability to interpret and prioritize vulnerabilities and translate security risks into clear technical recommendations.
  • Experience securing cloud-native environments involving containers, Kubernetes, and serverless, preferably in Azure.
  • Knowledge of DevOps with GitHub Actions, including workflows, custom actions, and security-tool integrations.
  • Hands-on experience building AppSec controls, automation scripts, guardrails, security-as-code policies, and pipeline integrations.
  • Solid knowledge of RESTful APIs and system integrations, including API authentication, authorization, rate limiting, payload validation, webhooks, SDKs, and OWASP API Security Top 10.
  • Knowledge of AI, LLMs, and applied AI security, including prompt injection, data leakage, jailbreaking, and OWASP Top 10 for LLM Applications.
  • Experience in financial-market AppSec and familiarity with BACEN, CVM, or PCI-DSS is preferred.
  • Experience configuring and operating security gates in GitHub Actions, Azure DevOps, or Jenkins is preferred.
  • Programming experience in Python, C#, Go, Java, or TypeScript for security automation, internal tools, and source-code vulnerability analysis is preferred.
  • Relevant certifications such as GWEB, GWAPT, CEH, AWS Security Specialty, or Azure Security Specialty are preferred.
  • Advanced English for communication with partners, suppliers, and global security communities is preferred.

Benefits

  • Health plan, dental plan, Wellhub, Zenklub, life insurance, flexible iFood Benefits meal and food allowance, transportation allowance, New Value benefits club, childcare assistance, and parental leave of six months for maternity and 20 days for paternity.
  • Exclusive investment funds, investment advisory services, an annual-fee-free XP Visa Infinite card, and credit products.
  • Flexible, predominantly in-office work model whose exact arrangement varies by function, with greater flexibility for some teams.
  • Recruitment process includes screening, general tests, recruitment interview, technical assessment, leadership interview, peer interview, and offer stages.

Tech Stack

Categories

XP Inc.

About XP Inc.

10,000+ employees
Contact me