Apply

Senior Application Security Engineer

Posted 2024-10-20

View full description

📍 Location: Brazil

🔍 Industry: Corporate wellness

🏢 Company: Wellhub

🗣️ Languages: English, Portuguese

🪄 Skills: AWSPythonSoftware DevelopmentCybersecurityJavaStrategyGoCollaborationCI/CD

Requirements:
  • Experience designing and implementing security controls for CI/CD pipelines and micro-services infrastructure.
  • Experience with SAST, DAST, and Vulnerability Scanners.
  • Experience with Code Review.
  • Background as a Software Developer.
  • Experience with Public Cloud infrastructure (preferably AWS).
  • Knowledge in Linux, containers, and networking.
  • Proficiency in modern programming languages (Java, Go, Python, etc.).
  • Knowledge of cybersecurity frameworks like OWASP and Mitre’s ATT&CK.
  • Knowledge of Security Champions programs.
  • Experience with Infrastructure as Code.
  • Fluency in English and Portuguese.
Responsibilities:
  • Help define the DevSecOps strategy and security architecture eliminating vulnerabilities within applications from early development stages.
  • Ensure successful deliveries and promote long-term technical health of projects.
  • Provide security practices at all stages of the software development process.
  • Develop and implement tools and processes that facilitate collaboration between developers, security experts, and operations teams.
Apply

Related Jobs

Apply

📍 Australia, Austria, Bangladesh, Belgium, Brazil, Canada, Colombia, Costa Rica, Croatia, Czech Republic, Denmark, Egypt, Estonia, Finland, France, Germany, Ghana, Greece, India, Indonesia, Ireland, Israel, Italy, Kenya, Mexico, Netherlands, Nigeria, Peru, Poland, Singapore, South Africa, Spain, Sweden, Switzerland, Uganda, United Arab Emirates, United Kingdom, United States of America, Uruguay

🧭 Full-Time

💸 109047 - 169455 USD per year

🔍 Nonprofit, Technology, Open Source

  • Two or more years of application security experience, with knowledge of OWASP Top Ten and CWE Top 25
  • Strong understanding of modern, object-oriented PHP development
  • In-depth experience developing or auditing JavaScript
  • Demonstrated ability to exploit and mitigate application-level vulnerabilities
  • Experience conducting software security reviews using source code inspection, manual testing, and automated scanning
  • Ability to explain security issues to non-technical audiences
  • Sensitivity to security challenges in large, international projects
  • Strong understanding of cryptography in web application security
  • Experience using Linux for web application development and deployment tasks
  • Ability to maintain focus while working remotely

  • Triage and remediate reported security issues
  • Review and deploy features developed by the Foundation and community members
  • Work with other development teams to ensure safe architectural and implementation choices
  • Test and evaluate software to find bugs before attackers do
  • Provide application security concept reviews and promote application security best practices
  • Provide support for application security incidents and operations

PHPSoftware DevelopmentBashCybersecurityJavaJavascript*NixOAuthC (Programming language)Linux

Posted 2024-08-30
Apply