2 months ago
Remote, AmericasMid Level / Senior
Responsibilities
- Conduct secure code reviews for Go-based microservices and identify vulnerabilities.
- Perform security testing of APIs, web applications, and backend services.
- Establish secure coding standards, guardrails, and reusable engineering patterns.
- Lead threat modeling sessions with engineering and product teams.
- Define and enforce CI/CD security gates for SAST, DAST, SCA, and secrets scanning.
- Own the DAST process, including tool selection, scheduling, escalation, and remediation tracking.
- Integrate container image scanning and infrastructure-as-code security checks into deployment pipelines.
- Support hardening across Kubernetes, ingress, and workloads.
- Define and tune security alerts for authentication anomalies and suspicious API usage.
- Provide secure-development guidance, training, and hands-on support to engineering teams.
- Maintain security documentation, runbooks, and standards.
- Triage, prioritize, and track security findings and ensure high-severity findings are not open for more than 30 days.
- Coordinate external penetration tests and vendor remediation plans.
- Partner with product and business teams to assess product risk.
Requirements
- 3–5 years of experience in application security, product security, or a similar role.
- Hands-on experience with SAST/DAST tools such as Snyk, Checkmarx, OWASP ZAP, or Burp Suite.
- Knowledge of the OWASP Top 10 for web applications and APIs and real-world exploitability assessment.
- Experience reviewing Go code or code in similar compiled languages.
- Familiarity with Kubernetes, containers, and cloud-native architectures.
- Strong written and verbal communication skills for explaining security risks to technical and non-technical stakeholders.
- English proficiency in writing and speaking is required.
- Certifications such as OSCP, OSWE, CEH, or eWPT are preferred.
- Experience with Istio or service mesh security is preferred.
- Familiarity with ISO 27001, GDPR, or SOC 2 is preferred.
- Threat modeling experience with STRIDE, PASTA, or similar methods is preferred.
- Experience in fintech or regulated environments is preferred.
Benefits
- Opportunity to join a high-impact, mission-driven fintech with regional scale.
- Cross-functional collaboration with teams across Latin America.
- Equipment provided by R2.
- Training budget for professional development.
- Career growth within R2.
- Location options are São Paulo, Buenos Aires, or Santiago.
Tech Stack
Categories
About R2 Games
R2Games (Reality Squared Games) publishes and operates free-to-play browser and mobile games, partnering with developers to localize, launch, and run live-ops for global audiences. Its platform focuses on MMORPGs and other online titles monetized through in-game purchases, supported by community management and customer service. The company is headquartered in Hong Kong and concentrates on bringing China-developed online games to overseas markets.
