Flash logo
Flash

A plataforma que simplifica sua gestão: da admissão ao controle de benefícios e despesas.

Information Security Specialist – AppSec

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 501-1,000Since 2018H1B No SponsorCompany SiteLinkedIn

Location

Brazil

Posted

1 day ago

Salary

0

Seniority

Senior

Bachelor DegreeExperience acceptedPortugueseAWSCloudDockerJenkinsKubernetes

Job Description

Information Security Specialist – AppSec

Flash

• Work closely with development teams to promote secure development practices (Secure Coding). • Support the implementation and evolution of Application Security (AppSec) and DevSecOps initiatives. • Perform security assessments of web applications, APIs, and integrations. • Identify vulnerabilities and assist teams in remediation and risk mitigation. • Participate in security-focused code reviews. • Work with security tools such as SAST, DAST, SCA and vulnerability scanners. • Support the construction of secure pipelines in CI/CD environments. • Help define standards, policies and security best practices for applications. • Participate in initiatives related to security applied to Artificial Intelligence (AI), including data protection, ensuring safe model usage and risk analysis for AI-enabled applications. • Support risk assessments related to the use of generative AI and intelligent automations within the corporate environment. • Collaborate with Engineering, Architecture, Cloud and Information Security teams to strengthen solution security. • Promote security and safe-AI awareness for technical and product teams. • Monitor trends, threats and best practices related to AppSec, DevSecOps and AI security.

Job Requirements

  • Knowledge of Information Security with a focus on Application Security (AppSec).
  • Understanding of secure development and best practices based on the OWASP Top 10.
  • Experience or familiarity with application security testing tools:
  • SAST: SonarQube, Checkmarx, Semgrep.
  • DAST: OWASP ZAP, Burp Suite.
  • SCA: Snyk, Dependency-Check.
  • Knowledge of REST APIs, modern web applications and microservices.
  • Familiarity with CI/CD pipelines using tools such as GitHub Actions, GitLab CI/CD or Jenkins.
  • Basic knowledge of cloud computing and security in Amazon Web Services (AWS) or Google Cloud environments.
  • Experience with code versioning using Git.
  • Knowledge of containers and container security using Docker and Kubernetes.
  • Familiarity with cloud and container security tools such as Trivy, Wiz or Prisma Cloud.
  • Interest or experience in security applied to Artificial Intelligence (AI), including:
  • Security in the use of generative AI.
  • Protection of data used by AI models.
  • Risk assessment in AI-enabled applications.
  • Familiarity with frameworks and best practices such as the OWASP LLM Top 10.
  • Good communication skills to work closely with development, engineering and product teams.
  • Analytical, collaborative profile with a continuous interest in new technologies and offensive/defensive security.

Benefits

  • Flash Card (the beloved pink one!) with flexible benefits: meal, grocery, mobility, health, education, culture and wellness
  • Health insurance
  • Life insurance
  • Extended maternity and paternity leave + childcare assistance
  • Day off on your birthday 🎂
  • Hybrid and flexible work model + home office allowance + in-office experiences
  • Exclusive partner discounts via the Flash app
  • TotalPass
  • Pet care benefit with Guapeco

Related Categories

Related Job Pages

More Security Engineer Jobs

Apex Systems logo

IT Cyber Security Engineer

Apex Systems

Apex Systems, an IT staffing and workforce solutions firm, provides recruiting and staffing services to large and small companies alike. Founded in 1995 by thre

Title: IT Cyber Security Engineer Location: Akron United States Job Description: Job#: 3035357 Job Description: POSTION: IT Cyber Security Analyst LOCATION: 100% (Must reside near Akron, OH) DIRECT HIRE - We are unable to sponsor Visa at this time* Apex Systems is seeking a highly qualified IT Cyber Security Analyst for a full-time position location in Akron, OH. performed 100% remote with infrequent multi-day trips to the Akron, Ohio area as needed (a few times per year). The Cyber Security Analyst works across all divisions and business units to protect the cyber assets. We seek a knowledgeable individual well-versed in current cyber security and information security strategies with skills to effectively apply such strategies to a large, dynamic, heterogeneous landscape. Job Requirements: - 5+ years of experience in a real cyber security role doing practical cyber security at a midsized or large organization. - Ability to identify and assess the severity and potential impact of risks. Communicate risk assessment findings to risk owners outside the cybersecurity program in a way that consistently drives objective, fact-based decisions about risk that optimize the trade-off between risk mitigation and business performance. - Familiarity with common cyber security related tools such as vulnerability scanners (Tenable preferred), ServiceNow IRM and GRC, Microsoft Power Automate, Microsoft Power BI, and other similar toolchains. - Strong decision-making, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one - Able to participate in an on-call rotation (cycling daily; on-call once every ~4-6 days) responding to out-of-hours calls and alerts in support of security response. Job Duties: - Act as a subject matter expert (SME) between cybersecurity and the business units in the development of appropriate policies, standards, and frameworks - Continuously monitor trends to anticipate and plan for future impact of cyber risk on a specific business unit (BU) or function - Follow all risk remediation protocols to ensure issues are mitigated, risks are accounted for, and exceptions are tracked in accordance with frameworks, policies and standards set by the organization - Educate stakeholders on cybersecurity-related matters to increase awareness and improve culture - Performs focused information risk assessments of existing or new services and technologies, along with business counterparts. - Identifies and facilitates implementation of appropriate controls to effectively manage cyber and information risks as needed. - Understand software and system vulnerability processes, manage vulnerability patches through a process lifecycle, and perform vulnerability assessments on systems and services Additional Skill Desired: - An ability to work on several tasks simultaneously and pay attention to sources of information from inside and outside one's network within an organization. - An ability to effectively influence others by informing their opinions, plans or behaviors. - Ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily understood, authoritative and actionable manner Education: - Bachelor's Degree in Computer Science, Information Security, or similar discipline is preferred. A bachelor's degree in another field with relevant industry experience in cyber/information security will be considered. EEO Employer Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Employee Services Department at [email protected] or 844-463-6178. Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRated's Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico. Everforth Apex uses a virtual recruiter as part of the application process. Click here for more details. Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide. Employee Type: FullTime Location: Akron, OH, US Job Type: Pay Range: $89,000 - $115,000 Similar Jobs - Cyber Security Engineer - Cyber Security Specialist - Cyber Security Analyst - Cyber Security SME - Cyber Security / Qualys Engineer

Ohio
$89K - $115K / year
Full TimeRemoteTeam 201-500Since 2012H1B No Sponsor

• Lead and support end-to-end PAM implementations using Delinea solutions • Integrate Delinea platforms with Active Directory, LDAP, cloud environments, SIEM tools, and ticketing systems • Manage privileged account onboarding and lifecycle • Implement password rotation, session monitoring, and auditing capabilities • Configure Just-in-Time (JIT) access and least-privilege policies • Perform upgrades, migrations, and system optimizations • Troubleshoot and resolve technical incidents related to PAM environments • Collaborate with architects, infrastructure teams, and clients • Produce clear and structured technical documentation • Participate in audits and ensure compliance with cybersecurity frameworks

Spain
€38 - €48 / hour
Apex Systems logo

Senior Security Engineer

Apex Systems

Apex Systems, an IT staffing and workforce solutions firm, provides recruiting and staffing services to large and small companies alike. Founded in 1995 by thre

Senior Security Engineer Location: Appleton United States Job Description: Job#: 3035230 Job Description: Overview This Senior Security Engineer Role is a remote, one-year contract position focused heavily on DevSecOps, application security pipeline visibility, and security tooling integration. The core objective is not just deploying tools, but creating a unified security visibility model across the SDLC - connecting SAST findings, container vulnerabilities, cloud environments, CI/CD pipelines, and deployment stages into a single contextualized security workflow. This is a true security engineering role with strong development alignment. The ideal candidate will be highly technical, solution-oriented, collaborative, and capable of helping shape architecture and implementation strategy alongside senior engineers already leading the initiative internally. Key Responsibilities - Help evaluate, implement, configure, and operationalize a DAST/Web Application Scanning platform - Contribute to architecture and development of a unified security visibility pipeline across: - SAST findings - Container vulnerabilities - Cloud-hosted workloads - CI/CD pipelines - Deployment environments (dev/stage/prod) - Build or enhance custom integrations between security tools and internal systems - Develop API-based integrations and custom workflows to aggregate vulnerability data - Assist in designing a centralized vulnerability mapping and contextualization framework - Collaborate closely with AppSec engineers and development teams to improve security visibility and workflows - Help create automated onboarding/enforcement controls across repositories and pipelines - Contribute to custom security controls and automation where commercial tooling is insufficient - Support backend, middleware, infrastructure, and API integration efforts tied to security initiatives - Participate in technical solutioning and architectural discussions around DevSecOps maturity - Provide recommendations and alternative approaches based on prior real-world implementation experience - Communicate technical solutions clearly to engineering leadership and business stakeholders How to Apply: Please send resumes to [email protected] to apply. We are an equal opportunity employer and welcome applications from all qualified candidates regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status. Apex uses a virtual recruiter as part of the application process. Click here for more details. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Benefits Department at [email protected] or 804-523-8228. Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRated's Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico. Everforth Apex uses a virtual recruiter as part of the application process. Click here for more details. Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide. Employee Type: Contract Remote: Yes Location: Appleton, WI, US Job Type: Pay Range: $60 - $90 per hour Similar Jobs - Senior Security Engineer - Senior Security Engineer - Sr Security Engineer IAM - NXTG Senior Security Engineer - Senior Workday Security Administrator

Wisconsin
$60 - $90 / hour
GoDaddy logo

Junior Security Engineer - Cyber Threat Intelligence

GoDaddy

GoDaddy is a web services platform that helps individuals and businesses worldwide start, grow, and manage their online presence. GoDaddy employs team members across North America,

Role Description GoDaddy is looking for a Security Engineer - CTI with foundational cybersecurity knowledge and a strong interest in threat intelligence, adversary tracking, and security research. This is an outstanding opportunity to be part of a world-class team that is exceptionally dedicated to protecting our customers and improving our security posture! You will engage with Security Operations, Detection Engineering, Incident Response, and Insider Threat teams and learn from skilled CTI professionals in an environment centered on collaboration and growth! What you'll get to do... - Assist in collecting and analyzing threat intelligence from OSINT sources, threat feeds, and vendor advisories. - Monitor emerging vulnerabilities, exploits, threat campaigns, and threat actor activities. - Maintain threat actor profiles, IOC repositories, and intelligence databases. - Support administration and maintenance of CTI platforms such as Anomali, Recorded Future, and Intel471. - Assist with IOC feed management, STIX/TAXII integrations, enrichment pipelines, and basic troubleshooting. - Gain hands-on exposure to SIEM and EDR technologies including Splunk and SentinelOne. - Support Detection Engineering teams with IOC validation, alert triage, and threat hunting activities. - Prepare threat summaries, daily intelligence briefs, IOC reports, and internal security documentation. - Collaborate closely with Incident Response, Insider Threat, and other security groups that support Security Operations across functions. Qualifications - 1+ years of experience in Cybersecurity, Information Security, SOC Operations, IT Security, Vulnerability Management, or related security domains. - Basic understanding of cyber threats, attack vectors, and defensive security concepts. - Foundational networking knowledge including TCP/IP, DNS, HTTP/S, and firewalls. - Familiarity with SIEM tools, EDR platforms, or threat intelligence feeds. - Aware of the MITRE ATT&CK framework and cyber threat intelligence concepts. - Strong written communication and documentation skills. - Demonstrated interest in CTI through CTFs, security blogs, research, home labs, coursework, or open-source contributions. Requirements - Certifications such as CompTIA Security+, CySA+, BTL1, or equivalent. - Exposure to OSINT tools including Shodan, Maltego, VirusTotal, and Censys. - Basic scripting knowledge in Python, Bash, or PowerShell. - Experience with STIX/TAXII and cyber threat data frameworks. - Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related fields, or equivalent experience. - Enthusiastic about cybersecurity and threat intelligence with a strong desire to learn. - Self-motivated and comfortable working in a fully remote environment. - Strong analytical thinking, attention to detail, and problem-solving abilities. - Comfortable collaborating across teams and time zones. - Able to handle sensitive information with integrity and discretion. Benefits - Paid time off. - Retirement savings (e.g., 401k, pension schemes). - Bonus/incentive eligibility. - Equity grants. - Participation in our employee stock purchase plan. - Competitive health benefits. - Other family-friendly benefits including parental leave.

India