
Staff Security Engineer [AppSec]
Stone - Linkedin11 hours ago
Remote, BrazilStaff+
Responsibilities
- Define and implement application security strategies, including for applications integrating LLMs and generative AI.
- Collaborate with development teams to integrate security practices throughout the software development lifecycle.
- Conduct architecture, code, and design reviews to identify vulnerabilities and security issues.
- Define security guardrails and standards for LLM applications, agents, RAG pipelines, and AI-assisted development tools.
- Establish secure-use guidelines for AI coding assistants while protecting intellectual property and sensitive data.
- Develop and promote application security standards and best practices across engineering teams.
- Provide technical security guidance, training, and awareness to development teams.
- Use or understand automated security validation tools in CI/CD, including SAST, DAST, SCA, and Secret Scanning.
- Monitor evolving security threats, including emerging threats to AI systems, and update protection measures.
- Investigate threats in corporate and production environments and participate in security incident response.
Requirements
- Completed or ongoing higher education in Information Security, Computer Science, Information Systems, Software Engineering, or a related field.
- Knowledge of common attack vectors and experience with threat modeling.
- Experience with effective protection mechanisms for APIs and mobile applications.
- Knowledge of fundamental cloud security services and concepts in AWS, Azure, or GCP.
- Familiarity with security risks in LLM and generative AI applications, including OWASP Top 10 for LLM Applications and MITRE ATLAS.
- Ability to influence and negotiate with teams, work autonomously, communicate complex issues clearly, and collaborate across multidisciplinary teams.
- Ability to read and communicate in English.
- Preferred: incident participation and root-cause analysis experience.
- Preferred: experience with financial-sector requirements such as Bacen, PCI, and SOX.
- Preferred: strong programming skills and practical experience defining threat models and controls for production LLM applications.
- Preferred: experience protecting AI-model APIs against prompt injection, structured-output issues, authorization problems in function calling and tool use.
- Preferred: experience defining corporate policies and controls for generative AI tools.
- Preferred: knowledge of NIST AI RMF and ISO/IEC 42001.
Benefits
- Fixed salary and an eligible variable compensation package.
- Health and dental insurance, virtual medical care, medication subsidy, life insurance, and emotional support through Acolhe360º.
- Meal and/or food allowance, childcare assistance, assistance for dependents with disabilities, and fuel or commuting assistance.
- Home-office assistance for remote or hybrid contracts.
- Education and self-development benefits through Studa and Stone Library.
- Additional optional benefits include Wellhub, TotalPass, Pet Club, Flash, Férias&Co, VT, Allya, and educational partnerships.
- Remote work arrangement is indicated by the posting.
Tech Stack
Categories
About Stone - Linkedin
Stone is a Brazilian fintech that provides payment processing, POS terminals, online checkout, and financial services such as banking and credit for merchants of all sizes. It earns primarily through transaction fees and service subscriptions tied to its merchant-acquiring and software offerings. Founded in 2012 and headquartered in São Paulo, the company went public on Nasdaq in 2018, serving entrepreneurs across Brazil through a nationwide operation.