Senior Application Security Architect – AppSec

Location

Brazil

Posted

18 days ago

Salary

0

Seniority

Senior

Bachelor DegreePortugueseAWSAzureCloudGoogle Cloud Platform

Job Description

Senior Application Security Architect – AppSec

Stone & Company

• Define and implement security strategies for applications, including those that integrate LLMs and generative AI components • Collaborate with development teams to integrate security practices from the beginning of the software development lifecycle • Conduct architecture, code, and design reviews to identify potential vulnerabilities and security issues • Define guardrails and standards for LLM-based applications, addressing risks such as prompt injection, insecure output handling, data leakage through outputs, excessive agent autonomy, and cost-abuse (denial-of-wallet) • Establish guidelines for the safe use of AI-assisted development tools by engineering teams • Develop and promote security standards and best practices across the development organization • Provide technical guidance and security training • Be familiar with tools for automated quality validation in the CI/CD pipeline such as SAST, DAST, SCA and Secret Scanning • Stay up to date with security threats and evolving attack techniques and continuously update protective measures • Develop creative solutions to complex security problems • Use your security expertise and intuition to hunt for threats in corporate and production environments • Read and communicate in English

Job Requirements

  • Bachelor's degree (completed or in progress) in Information Security, Computer Science, Information Systems, Software Engineering, or a related field
  • Ability to identify opportunities for improvement, new solutions, and alerts that can benefit or streamline operations
  • Use influencing and negotiation skills to guide teams to remediate issues or adopt security-appropriate architectures
  • Concise, direct, and assertive communication
  • Initiative to seek or request information when needed
  • Passion for learning in a dynamic environment
  • Knowledge of common attack vectors
  • Experience performing threat modeling
  • Experience with effective mechanisms to protect APIs and mobile applications
  • Familiarity with core cloud services and security concepts (AWS, Azure, or GCP)
  • Ability to work within multidisciplinary teams using agile methodologies
  • Familiarity with security risks in applications that use LLMs and generative AI (references such as OWASP Top 10 for LLM Applications and MITRE ATLAS)

Benefits

  • 🩺 Health and Dental Insurance
  • 🏥 Green Virtual Hospital available 24/7 for fast, convenient care
  • 🥗 Meal Voucher and/or Food Voucher
  • 💻 Remote Work Allowance (exclusive to remote positions)
  • 🕗 Flexible working hours
  • ✏ Education Benefit - internal platform with access to books, podcasts, trainings and video lessons for self-development (Studa and StoneCo Library)
  • 💪 Wellhub
  • 💪 TotalPass
  • 👶 Childcare Assistance
  • 💰 Profit Sharing (PLR)
  • 💚 Life Insurance
  • 🚗 Transport Voucher (exclusive to on-site positions)

Related Categories

Related Job Pages

More Security Engineer Jobs

Zscaler logo

Escalation Engineer - AI Security

Zscaler

Zscaler helps leading organizations in 180+ countries securely transform their networks and applications for a mobile and cloud-first world. Founded in 2008, th

Full TimeHybridTeam 8,697Since 2007

Title: Escalation Engineer - AI Security Location: Bangalore, IND; Mohali, IND Role We are looking for an experienced Escalation Engineer to join our Customer Success team. This is a hybrid role based in Bangalore, you will report to the Escalation Manager. Our Customer Success Strategy & Operations team uses valuable data and market research to help our customers succeed and drive value. You'll be an integral part of solving challenges faced by our client-facing teams to help make Zscaler more efficient in meeting our customers' needs. What you’ll do (Role Expectations) - Own and resolve the highest-severity technical escalations through deep analysis, ensuring fast resolution and managing the on-call rotation for critical issues - Troubleshoot and resolve complex issues across Zscaler cloud security services, configuration, policy engines, APIs, and AI-assisted capabilities - Investigate and resolve scenarios related to the secure use of AI models, governance of AI agents, data protection, and inference security - Perform detailed log, telemetry, and packet-level analysis to identify the root cause, reproducing complex defects, providing engineering-ready bug reports, and validating fixes - Drive cross-functional collaboration with Engineering, Cloud Ops, and Product Management, while also creating advanced troubleshooting documentation and acting as a technical mentor to uplift support capability Who You Are (Success Profile) - You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful. - You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. True ownership involves leveraging dynamic range: the ability to navigate seamlessly between high-level strategy and hands-on execution. - You are a problem-solver. You love running towards the challenges because you are laser-focused on finding the solution, knowing that solving the hard problems delivers the biggest impact. - You are a high-trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback—knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust. - You are a learner. You have a true growth mindset and are obsessed with your own development, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose. What We’re Looking for (Minimum Qualifications) - 4–10 years of deep technical support, cloud support engineering, or escalation engineering experience - Strong understanding of AI model security, data governance, AI agent behavior, and safe enterprise deployment principles - Proficiency with APIs, JSON, logging frameworks, Linux CLI, debugging tools, and cloud-based distributed systems - Exposure to cloud platforms (AWS/GCP/Azure) and identity, policy, or proxy-based architectures - Ability to reproduce complex issues, correlate across layers (client → edge → cloud), and articulate clear RCAs What Will Make You Stand Out (Preferred Qualifications) - Demonstrated experience with Zscaler products (ZIA, ZPA, ZDX) or similar cloud security platforms, including knowledge of enterprise networking, TLS/SSL inspection, and authentication flows - Familiarity with LLM-based system behavior, data leakage prevention in AI, and establishing model access policy controls - Proficiency in scripting for automation, efficient troubleshooting, and reproducing complex customer environments #LI-RR #LI-Hybrid At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure. Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including: - Various health plans - Time off plans for vacation and sick time - Parental leave options - Retirement options - Education reimbursement - In-office perks, and more!

KA + 1 moreAll locations: KA | India
EY - Ernst & Young logo

Senior Network Security Architect

EY - Ernst & Young

Ernst & Young, or EY, is a global financial services company that provides a host of assurance, tax, transaction, and advisory services. A member of Ernst & Young Global Limited, E

Title: Cybersecurity Engineering - Network Security Architect - Senior Manager - Consulting - Location Open Location: Anywhere in Country The opportunity The Senior Network Security Architect is a strategic and hands‑on technical leader responsible for designing, implementing, and governing secure network architectures across the enterprise. This role ensures that network security controls align with business objectives, risk tolerance, and regulatory requirements while enabling scalability, performance, and resilience. The architect serves as the authority on network security design, providing thought leadership across on‑premises, cloud, and hybrid environments, and partnering closely with infrastructure, cloud, application, and security operations teams. Join our dynamic team as a Senior Manager in Cybersecurity Engineering, where you will play a pivotal role in developing, managing, and integrating cutting-edge cybersecurity solutions. Protect sensitive data against a myriad of threats while leading cross-departmental initiatives that align security measures with business goals and technical specifications. This is your chance to be part of a revenue-generating team that values innovation and quality in safeguarding our digital landscape. Your key responsibilities As a Senior Manager, you will be at the forefront of designing and managing security infrastructure systems, monitoring for intrusions, and ensuring data integrity. You'll collaborate across departments to meet security, business, and operational needs, leading complex project delivery with a focus on quality and risk management. Additionally, you will control budgets, establish client relations, identify sales opportunities, and manage resources for project success. Expect regular travel to meet client needs and daily interactions with external clients to foster and manage relationships. - Design and manage security infrastructure systems - Monitor and protect against intrusions and data breaches - Collaborate interdepartmentally to align security with business objectives Skills and attributes for success To thrive in this role, you must possess a deep understanding of cybersecurity and privacy concepts, coupled with the technical expertise in deploying and managing security solutions. Change management, system administration, and technical writing are part of your arsenal, along with threat hunting and vulnerability management. Your business competencies will include relationship-building, critical thinking, negotiation, and communication skills, enabling you to lead and manage teams effectively. - Deep technical experience in Zero Trust and Network security - Develop and maintain enterprise network security architecture encompassing LAN, WAN, cloud, data center, edge, and remote access environments - Design secure solutions using zero trust principles, defense‑in‑depth, and least privilege access - Define standards for firewalls, segmentation, VPNs, secure routing, IDS/IPS, DDoS protection, NAC, and secure network services - Review and approve network and security designs for new initiatives and changes - Expertise in broad cybersecurity concepts - Proficiency in change management and organizational impact - Strong skills in technical writing and people management - Exceptional relationship-building and critical thinking abilities - Effective communication and team leadership skills To qualify for the role, you must have - A bachelor's degree, with a master's degree preferred - A minimum of 5-7 years of relevant experience in the cybersecurity field { - Change Management skills - Expertise in Cybersecurity and Privacy Concepts, Principles, and Solutions - Experience with Digital Transformation - Script Writing/Coding abilities - Proficiency in Security Solution Deployment, Integration, Configuration, and Debugging - Experience with Cisco, Palo Alto Networks, Zscaler, Cloudflare, Netskope Ideally, you’ll also have - Knowledge of the complexity of deploying technology to branch-connected networks - Cloud network security expertise (AWS, Azure, GCP) - Experience with SASE / SSE platforms - Automation and Infrastructure‑as‑Code exposure (e.g., Terraform, ARM, CloudFormation) - Security architecture certifications such as: - CISSP - CCSP - CCIE Security - GIAC certifications - Experience in regulated industries or large global enterprises - Strong Business Skills including Building and Managing Relationships, Communicating with Impact, Complex Problem-Solving, Critical Thinking, and Negotiation and Influencing What we look for We seek top performers who demonstrate a keen understanding of the importance of cybersecurity in today's digital world. Candidates should exhibit a proactive approach to problem-solving, an eagerness to learn and adapt to new technologies, and the ability to lead with integrity and inspire trust among team members and clients. and risk management. What we offer you At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more. - We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $170,600 to $390,000. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $204,800 to $443,200. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. - Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year. - Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

United States
$170.6K - $390K / year
Stefanini LATAM logo

Ingeniero de Seguridad

Stefanini LATAM

Co-creating solutions for a better future

Full TimeRemoteTeam 10,001+Since 1987H1B No Sponsor

• Implementar controles de seguridad, respuesta a incidentes y revisión de cumplimiento normativo. • Desarrollar funcionalidades complejas y ejecutar proyectos de mayor envergadura. • Optimizar tiempo, mantener la productividad y asumir nuevas asignaciones.

Mexico
Excellus BlueCross BlueShield logo

Principal AI Security Engineer

Excellus BlueCross BlueShield

UPSTARS – продуктова IT-компанія, з якою злітають і люди, і бренди. Наш основний фокус – технологічні рішення та B2B-послуги для міжнародних клієнтів.

Full TimeRemoteTeam 2-10H1B No Sponsor

Role Description The Principal Artificial Intelligence (AI) Security Engineer serves as the technical lead for securing machine learning (ML), generative artificial intelligence (GenAI), and agentic systems in production, with emphasis on healthcare and other regulated environments. This role creates security architecture, threat modeling, control design, and detection strategy across the AI lifecycle. - Data ingestion - Feature engineering - Training and fine-tuning - Evaluation - Model serving - Retrieval-augmented generation (RAG) pipelines - Agent frameworks - Application programming interface (API) mediation - Post-deployment monitoring The Principal AI Security Engineer leads and partners throughout the organization to build enforceable guardrails for: - Protected health information and electronic protected health information handling - Identity and access control - Secrets isolation - Model and dataset provenance - Output safety - Evidence collection for audits and investigations Qualifications - Ten (10) years of hands-on security engineering experience spanning application security, cloud security, security architecture, detection and response, platform security, or infrastructure security. - Bachelor's degree in computer science, information technology, or relevant field. In lieu of degree, six (6) cumulative years of related experience required. - Demonstrated experience securing production AI/ML systems, including large language model (LLM) applications, model serving stacks, retrieval-augmented generation architecture, or agent frameworks. - CISA, CISM, CCSP, HCISPP, GIAC and or CISSP certifications preferred. - Demonstrated advanced expertise in AI threat modeling and adversarial testing. - Strong implementation knowledge of secure software development lifecycle (SDLC), continuous integration/continuous delivery (CI/CD) security, and cloud-native telemetry pipelines. - Experience designing or reviewing controls for secure machine learning operations (MLOps). - Experience instrumenting detections and response workflows using logs, traces, metrics. - Advanced working knowledge of RAG security and evaluation harnesses for safety, security, and regulated-data compliance. - Prior experience in healthcare, payer, provider or similarly regulated environments with PHI/ePHI safeguards preferred. - Advanced ability to write engineering standards, design docs, threat models, and control requirements. - Hands-on familiarity with model gateways and AI observability tooling. - Working knowledge of static/dynamic application security testing and dependency-risk management. - Experience with AI red teaming platforms and automated release gates for model or prompt changes. - Familiarity with Sarbanes Oxley, HIPAA, OCR, AI RFM, HCFA, PCI/DSS, NIST and other regulations impacting security preferred. Requirements - Ability to work prolonged periods sitting and/or standing at a workstation and working on a computer. - Ability to travel across the Health Plan service region for meetings and/or trainings as needed. - Ability to work in a home office for continuous periods of time for business continuity. Benefits - Participation in group health and/or dental insurance - Retirement plan - Wellness program - Paid time away from work - Paid holidays Compensation Range(s) Minimum: $123,304 - Maximum: $221,948 The salary range indicated in this posting represents the minimum and maximum of the salary range for this position. Actual salary will vary depending on factors including, but not limited to, budget available, prior experience, knowledge, skill and education as they relate to the position’s minimum qualifications, in addition to internal equity. The posted salary range reflects just one component of our total rewards package. Please note: There may be opportunity for remote work within all jobs posted by the Excellus Talent Acquisition team. This decision is made on a case-by-case basis. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

United States
$123.3K - $221.9K / year