
Cyber Security Spec IV (AppSec)
Banco Santander, S.A.2 hours ago
São Paulo, BrazilStaff+
Responsibilities
- Advise Cyber Security, Architecture, and Engineering teams on application security risks, controls, and vulnerability mitigation.
- Lead and improve DevSecOps practices across SAST, SCA, DAST, IaC, secrets management, and development pipelines.
- Conduct static, dynamic, and interactive security testing, secure code reviews, threat modeling, and technical security assessments.
- Define and review SDLC processes and security architecture guidelines for complex applications, APIs, microservices, mobile applications, cloud environments, and CI/CD pipelines.
- Support incident response through forensic analysis, evidence collection, root-cause investigation, containment, and remediation recommendations.
- Coordinate Red Team and Blue Team simulations and support Protect and Detect service maturity and effectiveness assessments.
- Support new technology adoption, container security, security automation, architecture reviews, proof-of-concepts, and technical validations.
- Collaborate with development, Cloud, Infrastructure, GRC, and IAM teams on holistic cyber security initiatives.
Requirements
- Solid knowledge of SDLC/SSDLC processes and secure development practices.
- Experience implementing DevSecOps pipelines using SAST, DAST, SCA, IaC, CI/CD, and GitHub Actions.
- Experience with security architecture, APIs, microservices, containers, multi-cloud environments, Blue Team operations, incident response, forensic investigation, threat modeling, STRIDE, OWASP Top 10, ASVS, MASVS, and security standards.
- Knowledge of cryptography, access control, authentication and authorization, hardening, data protection, malware analysis, and mobile application security.
- Experience with SAST, DAST, IAST, IaC, and container security tools.
- Ability to analyze security requirements and guide engineering teams on secure development practices.
- Advanced English for communication with the global team.
- Preferred: Red Team experience, vulnerability exploitation, MITRE ATT&CK, AI applied to security, Databricks, data pipelines, machine learning, secure data governance, reverse engineering, security process orchestration, LLMs for security, and internal security framework development.
Benefits
- Variable compensation including profit sharing and bonus.
- Medical and dental assistance.
- Meal and food allowances.
- Complementary pension plan and life insurance.
- Childcare or nanny assistance.
- Gympass or Totalpass.
- Transportation allowance.
- Programa Nascer, Be Healthy, and PAPE personal support programs.
- Brazil-based role with collaboration with a global team.
Tech Stack
DatabricksGitHub Actions