4 hours ago
Remote, BrazilSenior
Responsibilities
- Lead vulnerability management across infrastructure, platforms, and applications, including scanning, dependency analysis, external findings, validation, remediation coordination, and verification.
- Build, operate, and mature SIEM/XDR capabilities through log ingestion, detection rule development, alert tuning, and investigation workflows.
- Investigate and respond to security incidents across cloud infrastructure and applications, perform root cause analysis, and drive long-term fixes.
- Design detection strategies for suspicious activity, including data exfiltration patterns using application and database telemetry.
- Lead threat modeling and security design reviews to identify risks and strengthen architecture.
- Secure and improve AWS and Kubernetes infrastructure at scale.
- Drive CI/CD hardening and container and software supply chain risk controls.
- Partner with engineering teams to remediate vulnerabilities and improve secure development and deployment practices.
- Implement security controls aligned with PCI DSS, SOC 2, and other compliance requirements.
- Develop security automation, including appropriate use of AI, to improve detection, response, and operational efficiency.
- Triage and validate external security findings, including bug bounty reports.
Requirements
- 6+ years of experience in security, software, or infrastructure engineering, including hands-on experience securing cloud-based production systems.
- Experience with threat modeling and security design reviews for modern systems.
- Strong hands-on vulnerability management experience covering scanning, triage, validation, remediation coordination, and verification.
- Experience with SIEM platforms such as Wazuh, Splunk, or ELK for detection engineering, monitoring, and incident response.
- Experience triaging findings from vulnerability scanners and bug bounty programs.
- Strong knowledge of AWS, Linux, and Kubernetes infrastructure, including security architecture, hardening, and operational practices.
- Experience with infrastructure security, CI/CD hardening, and software supply chain risk mitigation.
- Experience with container and dependency security tools such as Snyk, Trivy, or Grype.
- Ability to investigate issues using logs, cloud tooling, and system-level data.
- Knowledge of common security vulnerabilities and mitigation strategies, including OWASP and SANS guidance.
- Working knowledge of PCI DSS, SOC 2, and related compliance expectations.
- Demonstrated experience using Claude or an equivalent large language model tool is required.
- Preferred experience designing and tuning detection rules, reducing alert noise, improving investigation workflows, securing CI/CD workflows, and using automation and AI at scale.
Benefits
- Full-time remote work arrangement.
- Monthly gross compensation of $5,000-$9,500 USD, based on experience level.
- Opportunity to shape security capabilities across detection, supply chain security, data protection, automation, and incident response.
Tech Stack
Categories
About Sezzle
Sezzle builds a buy now, pay later platform that lets consumers split purchases into interest-free installments online and in stores, integrated with e-commerce and retail merchants. The company earns revenue from merchant fees and related consumer charges and provides underwriting and payment processing services. Founded in 2016 and headquartered in Minneapolis, Sezzle is a public company dual-listed on Nasdaq and the ASX.
