4 days ago
São Paulo, BrazilMid Level
Responsibilities
- Support application security through threat modeling, secure code review, API security testing, and CI/CD pipeline checks.
- Review and monitor AI and agentic workflows for prompt risks, unsafe automated actions, and data exposure.
- Build and maintain SIEM detection rules, alert pipelines, and response playbooks using Datadog SIEM, CrowdStrike, and Cloudflare.
- Own detection coverage for a defined set of systems and support incident response through alert triage, playbook execution, and tabletop exercises.
- Conduct cloud security assessments across AWS and Kubernetes environments.
- Execute vendor security assessments and own reviews for part of the vendor pipeline.
- Help establish and grow ARQ’s security function in Brazil in collaboration with the global security team.
Requirements
- 2–4 years of experience in information security or a closely related technical role.
- Experience with at least one cloud environment, preferably AWS, and familiarity with Kubernetes fundamentals.
- Basic familiarity with application security concepts such as threat modeling, secure code review, or API security testing.
- Curiosity about AI and agentic tooling risks, including LLM integrations, MCP servers, and automated workflows; hands-on experience is a plus but not required.
- Exposure to SIEM platforms and interest in detection engineering, including writing or tuning at least a few detection rules.
- Strong written and verbal communication skills in English.
Benefits
- Competitive salary and benefits.
- Stock options.
- Discretionary performance bonus.
- Latest tools and technology.
- Opportunity to work with a world-class team and build the security function for a fintech app in Latin America.
- Hybrid office policy requiring three to four days per week in the office.