ABC Fitness

Application Security Engineer (Secure SDLC)

🌍 Remoto📍 Remoto
PUBLICIDADE

Descrição da Vaga

As an Application Security Engineer II, you will partner with software engineering teams to embed security throughout the software development lifecycle. You will help developers build secure applications by helping integrate security into CI/CD pipelines, improving code practices, implementing application security tooling, and supporting cloud-native security across AWS and Azure environments.
 

This role is ideal for someone with a background in software engineering, DevSecOps, cloud engineering or application security who enjoys solving security challenges through collaboration, automation, and engineering rather than offensive security testing.

WHAT YOU'LL DO

  • Partner with software engineering teams to identify, prioritize, and help remediate application security risks throughout the Secure Software Development Lifecycle (SSDLC).
  • Implement and maintain application security tooling including SAST, DAST, Software Composition Analysis (SCA), and secret scanning within CI/CD pipelines to enable secure software delivery.
  • Support secure code reviews, provide secure coding guidance, and help development teams remediate identified vulnerabilities.
  • Review penetration testing findings and work with engineering teams to prioritize, validate, and remediate identified issues.
  • Contributes to security automation, reusable security controls, and developer enablement resources to improve secure software delivery.
  • Collaborate with DevOps teams to integrate security into CI/CD pipelines and Infrastructure as Code (IaC) workflows.
  • Assist with application security reviews for applications deployed in AWS and Azure cloud environments, including cloud-native services, APIs, and containerized workloads.
  • Assist in evaluating emerging technologies, including AI-enabled applications and Large Language Models (LLMs), for potential security risks.
  • Contribute to application security governance activities by contributing to secure coding standards, technical guidance, and security documentation.
  • Assist in maintaining security monitoring, logging, and vulnerability reporting processes in collaboration with cloud operations and security teams.
  • Collaborate with Privacy, Compliance, Legal, and IT teams on initiatives related to data protection, regulatory compliance, and application security.
  • Stay informed on emerging application security threats, vulnerabilities, and industry best practices and contribute to continuous improvement initiatives.

WHAT YOU'LL NEED

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent work experience.
  • Professional proficiency in both Portuguese and English (written and verbal) is required.
  • 1–5 years of experience in Application Security, Software Engineering, DevSecOps, Platform Engineering or Cloud Engineering
  • Experience applying security throughout the Secure Software Development Lifecycle (SSDLC), including secure design, code review, automated security testing, and vulnerability remediation.
  • Familiarity with application security testing methodologies, including SAST, DAST, Software Composition Analysis (SCA), vulnerability assessments, and basic penetration testing concepts.
  • Familiarity of threat modelling methodologies such as OWASP ASVS and STRIDE.
  • Basic understanding of AWS and/or Azure cloud security concepts and cloud-native application security.
  • Familiarity with CI/CD pipelines and integrating security tools using platforms such as GitHub Actions, Azure DevOps, GitLab CI, Jenkins or similar.
  • Experience developing software or the ability to read, understand, and troubleshoot code in one or more modern programming languages (Java, C#, Python, JavaScript/TypeScript, Go, etc.).
  • Excellent analytical, problem-solving, and communication skills, with the ability to work collaboratively across cross-functional teams.
  • Relevant industry certifications such as Security+, SSCP, CSSLP Associate, Azure Security Engineer Associate, AWS Security Specialty, or similar certifications are considered an asset
  • We're looking for someone who is curious, collaborative, and eager to grow their application security expertise. If you don't meet every qualification but believe you'd be a great fit, we encourage you to apply.
PUBLICIDADE

With four decades of experience behind us, we’ve brought together a suite of best-in-class platforms and a diverse, global, united team. We are now the only fit tech company on the planet that provides software for any fitness business, of any size, anywhere in the world.[Ver Mais]

Informações Adicionais

Selecionamos as principais informações da posição. Para conferir o descritivo completo, clique em "acessar" 


PUBLICIDADE
Candidatar-se a esta vaga →

Você será redirecionado para o site da empresa

PUBLICIDADE