Clicksign. O click que muda a sua vida.
AppSec Specialist, Application Security
Location
Brazil
Posted
10 days ago
Salary
0
Seniority
Mid Level
Job Description
AppSec Specialist, Application Security
Clicksign
• Assess technical vulnerabilities and propose solutions to improve the security of our platform, working in our stack (Ruby, Go, and PHP) and developing security fixes on AWS/Lambda. • Quickly assess development queue demands, reducing the AppSec bottleneck and unblocking Engineering deliveries. • Actively propose and implement fixes in code, going beyond merely reporting findings. • Conduct threat modeling and apply secure-by-design principles to product initiatives. • Create guardrails, tooling, and automations that make the secure path the default for Engineering teams. • Integrate and tune security tools in the CI/CD pipeline (SAST, SCA, and secret scanning), keeping noise and false positives low.
Job Requirements
- Experience in software engineering or security, writing and delivering production code (ideally Ruby and PHP), including automations on AWS/Lambda.
- Experience in Application Security/Product Security: threat modeling, secure-by-design, and creating guardrails and tooling.
- Strong knowledge of CI/CD pipeline security, with calibrated SAST, SCA, and secret scanning.
- Knowledge of AWS cloud security as applied to the product.
- Information security certifications are a plus.
- Strong ability to collaborate with Engineering teams, proposing and implementing fixes directly in code — not just reporting findings.
- Ability to communicate in English (written and spoken).
Benefits
- 100% remote work.
- Trust-based culture, results-oriented, with plenty of challenge and learning opportunities.
- Autonomy and ownership in a collaborative and empathetic environment.
- Feedback culture and regular 1:1s with human leadership and no micromanagement.
- Comprehensive benefits including meal/food allowance, childcare assistance, home office stipend, health coverage, education and cultural benefits, Gympass, birthday day-off, discounts on therapy and English courses, among other partnerships.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Support the end-to-end IT and security risk management lifecycle, including risk identification, assessment, treatment tracking, and reporting • Maintain and continuously improve the enterprise IT/security risk register, ensuring risks are accurately documented, rated, and assigned to appropriate owners • Perform risk assessments across technology domains (cloud infra, access management, application security) and third-party assessments using the appropriate methodology for each • Partner with control owners and business stakeholders to evaluate the effectiveness of risk mitigation controls and identify gaps • Integrate vendor and technology risk findings into the risk register to facilitate tracking and remediation across both IT/Security and Third-Party Risk Management. • Contribute to the development and maintenance of risk policies, standards, and procedures • Assist in preparing risk reporting and dashboards for senior leadership and committee-level audiences • Monitor the threat and vulnerability landscape and help translate emerging risks into actionable insights for the business • Support security and compliance initiatives, including PCI DSS, SOC 2, and NIST, from a risk lens, ensuring risk findings are integrated into broader compliance activities • Participate in risk-related work streams tied to new product launches, infrastructure changes, and strategic initiatives
Security Engineer
AssureSoft - CareersAssureSoft is a multinational software development and information technology company providing strategic consulting, technology services, and outsourcing business processes. We work to innovate and create quality software with motivated, passionate, and qualified teams that develop in an environment of professional, stable growth and continuous learning. Inclusive Opportunities for Every Talent. At AssureSoft, we believe that true innovation is born from diversity—of ideas, experiences, and perspectives. That’s why our hiring practices are inclusive and reflect a firm commitment to equity and equal opportunity. Here, every person—regardless of origin, gender, orientation, or beliefs—finds a space to grow, contribute, and be valued not only for their talent, but also for who they are.
Role Description - Develop and maintain secure applications using Angular and C#. - Support front-end and back-end development activities. - Work with SQL Server databases to support application functionality. - Develop and maintain solutions within Microsoft Azure environments. - Collaborate with engineering teams to implement secure and scalable software solutions. Qualifications - Mid-level professional experience. - Experience with Angular for front-end development. - Experience with C# for back-end development. - Experience working with SQL Server. - Experience with Microsoft Azure cloud services. - Advanced English. Benefits - Great Place To Work certification. - A company with more than 15 years of experience. - Work with world-class clients and long-term projects. - English scholarships for an external institute. - English classes with company teachers. - State-of-the-art tools and resources. - Certifications for your professional growth. - Recreation and leisure activities. - Compliance with the regulations and labor rights of your region. Company Description AssureSoft is a multinational software development and information technology company providing strategic consulting, technology services, and outsourcing business processes. We work to innovate and create quality software with motivated, passionate, and qualified teams that develop in an environment of professional, stable growth and continuous learning. Inclusive Opportunities for Every Talent. At AssureSoft, we believe that true innovation is born from diversity—of ideas, experiences, and perspectives. That’s why our hiring practices are inclusive and reflect a firm commitment to equity and equal opportunity. Here, every person—regardless of origin, gender, orientation, or beliefs—finds a space to grow, contribute, and be valued not only for their talent, but also for who they are.
• Work directly with federal and national-security customers to understand mission workflows, pain points, data environments, and operational constraints. • Build and deploy AI-enabled applications, agents, integrations, and workflow automation in secure customer environments. • Translate customer needs into technical requirements, implementation plans, and product feedback for the core engineering team. • Own delivery from prototype through production, including architecture, backend services, APIs, integrations, observability, testing, deployment, and customer acceptance. • Integrate with customer systems, data sources, identity providers, and cloud or on-prem infrastructure. • Partner with product, engineering, security, and customer teams to ensure solutions are secure, reliable, auditable, and operationally useful. • Debug issues in deployed environments and drive fast resolution across application, infrastructure, data, and integration layers. • Contribute reusable patterns, platform improvements, and documentation back to the broader engineering organization. • Operate with strong judgment in environments involving sensitive data, government stakeholders, and mission-critical workflows.
Senior Security Engineer
ECS Tech IncAll candidates must meet the following criteria: Must be a US Citizen, no dual Citizenships. Must be able to secure a Public trust clearance. Must be able to work across multiple programs across the Federal and DOD space. The core values that ECS looks for in an engagement manager include: Teamwork, Respect, Accountability, Integrity, and Leadership.
Role Description The Senior Security Engineer is responsible for supporting the engineering, implementation, and optimization of the security technologies, telemetry integrations, detection content, and automation capabilities that enable effective enterprise security monitoring and incident response operations. This role works closely with the Security Engineering Manager, SOC analysts, enterprise IT teams, and platform owners to ensure the reliability, scalability, and operational effectiveness of enterprise security monitoring capabilities. The Senior Security Engineer will contribute to the continuous improvement of SOC technologies, detection engineering, and automation initiatives that strengthen the organization’s cybersecurity posture. - Security Platform Administration: Support the operation, maintenance, and optimization of SOC security platforms including SIEM, EDR, and related monitoring technologies. - Security Telemetry Integration: Configure and maintain telemetry integrations to ensure enterprise visibility across infrastructure, cloud, identity, and endpoint platforms. - Detection Engineering: Develop, tune, and maintain detection rules, alerts, and correlation logic to improve threat detection capabilities and reduce false positives. - SIEM Data Management: Monitor SIEM performance, data ingestion pipelines, and log normalization processes to ensure reliable and accurate data collection. - Security Automation Support: Implement and maintain automation and orchestration workflows to improve SOC operational efficiency and investigation response times. - Investigation Support: Provide technical support and expertise to SOC analysts during security investigations, threat hunting, and incident response activities. - Platform Integration: Collaborate with enterprise IT, cloud, and infrastructure teams to onboard new systems and services into the SOC monitoring environment. - Operational Monitoring: Monitor the health, reliability, and performance of security monitoring infrastructure and telemetry pipelines. - Technical Documentation: Maintain documentation related to detection logic, engineering procedures, telemetry integrations, and SOC platform configurations. - Continuous Improvement: Identify opportunities to enhance monitoring coverage, improve detection quality, and optimize engineering workflows within the SOC. Qualifications - Experience: Minimum of 5–8 years of cybersecurity or security engineering experience supporting enterprise security operations environments. - Security Engineering Experience: Hands-on experience supporting enterprise security monitoring technologies including SIEM, EDR, and log management platforms. - Detection Engineering Knowledge: Experience creating, tuning, and maintaining detection content and alerting logic. - Security Telemetry Experience: Familiarity with log collection, normalization, and telemetry integration across enterprise environments. - Security Automation Experience: Experience implementing or supporting automation workflows within SOC or incident response operations. - Enterprise Security Knowledge: Strong understanding of enterprise infrastructure, cloud environments, identity systems, and network security monitoring. - Security Framework Knowledge: Familiarity with cybersecurity frameworks such as NIST Cybersecurity Framework, CIS Critical Security Controls, and ISO 27001. Requirements - Able and willing to obtain a US Security Clearance. - On-Call Support: Participates in on-call support to assist with security incident response, operational issues, and investigation activities to maintain continuous SOC coverage and response capability. Company Description Everforth ECS Federal is driven by a commitment to excellence and innovation in solving complex challenges. As a premier provider of advanced technology solutions and services, our mission is to secure and optimize the most critical commercial, government, defense, and intelligence projects across the country. Our team is composed of dynamic professionals who thrive in a collaborative and empowering environment, where our team members leverage the latest technologies and insights to make a real-world impact. Join us and be part of a forward-thinking organization that values your expertise and supports your professional growth.



