Talent.com
Application Security Engineer
Application Security EngineerVelozient • colombo, estado do paraná, Brazil
As candidaturas não são mais aceitas
Application Security Engineer

Application Security Engineer

Velozient • colombo, estado do paraná, Brazil
Há +30 dias
Descrição da vaga

We are seeking a remote, full-time Senior Application Security Engineer with 5+ years of experience to help strengthen the security posture of the software platforms. This role will be responsible for reviewing application code, identifying security vulnerabilities, and working closely with development teams to ensure secure coding practices are followed throughout the software development lifecycle.


The ideal candidate will have strong experience in application penetration testing, fraud detection and analysis, and secure software development practices. This individual will play a key role in proactively identifying risks in PHP, Python, and Angular applications, while also educating development teams on secure coding standards and best practices.


Our client provides integrated software and marketing solutions for the hospitality industry, specializing in short-term rental management. Their platform provides vacation rental companies with an enterprise-class property management system integrating booking, guest communications, and financial reporting systems - all built with partner organization integrations in mind.


Responsibilities:

  • Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software, including manual and automated code reviews for applications written in PHP, Python, and Angular
  • Analyze applications for common vulnerabilities such as those identified in the OWASP Top 10, including risks related to authentication, authorization, data validation, and session management
  • Conduct application penetration testing and vulnerability assessments on web applications and APIs, simulating real-world attack scenarios to uncover security weaknesses and documenting findings with recommended mitigation strategies
  • Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies
  • Track, analyze, and manage vulnerabilities in applications while providing guidance and support for remediation efforts
  • Analyze application behavior and transaction patterns to detect potential fraud or abuse scenarios and identify vulnerabilities that could enable account takeover, payment fraud, or data manipulation
  • Partner with engineering and product teams to design controls that reduce fraud risk.
  • Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including developing secure coding guidelines, delivering secure coding training, and providing guidance during design and architecture reviews
  • Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats, including integrating and maintaining security testing tools such as SAST, DAST, and dependency scanning within CI/CD pipelines
  • Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents
  • Track vulnerabilities and remediation progress through internal ticketing systems while collaborating with engineering, DevOps, and product teams to improve the overall application security posture and assist in developing internal security policies and procedures


Required Experience:

  • Excellent English communication skills
  • 5+ years of experience in application security, penetration testing, or secure software development
  • Strong understanding of web application security principles and the OWASP Top 10
  • Experience reviewing code in PHP, Python, and modern JavaScript frameworks such as Angular
  • Experience performing application penetration testing and vulnerability assessments
  • Knowledge of authentication, authorization, encryption, and secure session management
  • Experience identifying and mitigating fraud or abuse patterns in applications
  • Familiarity with common security testing tools (e.g., Burp Suite, OWASP ZAP, Snyk, SonarQube, etc.)
  • Strong communication skills and the ability to explain security issues to non-security engineers


Desired Experience:

  • University degree or relevant industry experience
  • Experience integrating security testing into CI/CD pipelines
  • Familiarity with cloud security principles
  • Experience with secure architecture reviews
  • Relevant certifications such as OSCP, CEH, GWAPT, or CSSLP
  • Experience working in agile development environments


Additional Information:

  • Knowing your ideas are heard and matter, think big!
  • You get to own your job and be recognized for your contributions
  • Work with smart and creative people
  • Making mistakes is human. Let's learn from them. Be transparent!
  • We recognize you as an individual, with no presumptions or judgment. Be the extraordinary you!
  • 15 days Paid Time Off (PTO), 1 floating day, 3 sick days, and designated national holidays
  • Start: ASAP


About Velozient:


We are a privately held, nearshore software development company providing outsourced development resources to North American companies. Our mission is to offer development talent that enjoy taking on challenging work, want to grow their skills and experiences building software, and excel in a fast-paced, dynamic team environment. We are focused on providing world-class remote resources to work as valued client team members. If this type of opportunity excites you, then consider joining our team!

Criar um alerta de emprego para esta pesquisa

Application Security Engineer • colombo, estado do paraná, Brazil

Vagas similares

Analista SAP Basis - Security

Softtekpinhais, estado do paraná, br

Analista SAP Basis Security - Sênior.Conhecimentos/Experiências que a pessoa precisa ter:.Segurança em SAP ECC / SAP S/4HANA (módulos BC, HR, PM, MM, FICO, etc.Segurança em CyberArk (gestão de aces...Mostre mais

 • Promovida

Consultor Security Cloud Azure SR (Projeto no México)

T-Systems do Brasilcolombo, estado do paraná, br

Se você busca uma oportunidade na área de Tecnologia da Informação, tem organização, boa comunicação e vontade de crescer, essa vaga 100% remoto e CLT, pode ser para você.Experiência sólida com Mic...Mostre mais

 • Promovida

Firewall Engineer

bid.pinhais, estado do paraná, br

We’re Hiring: Firewall Engineer (L3 Support – F5 Technologies).Latin America, with a strong focus on.This role involves operational support, configuration, troubleshooting, and optimization of F5 d...Mostre mais

 • Promovida

Arquitetura de Segurança Cloud AWS - 132141

GFT Technologiescolombo, estado do paraná, br

Profissional de nível Arquitetura que atue com.Arquiteto especializado em segurança para ambientes financeiros críticos, responsável por definir, validar e garantir controles de segurança fim a fim...Mostre mais

 • Promovida

Full Stack Engineer

ITMC Systems, Inccuritiba, estado do paraná, br

Job Description: Full Stack Developer (2 Openings).Location: Remote from Barzil & Mexico.Digital Signage & Clubs team, building and maintaining software that powers airport signage systems and Unit...Mostre mais

 • Promovida

Identity Engineer Expert

Tata Consultancy Servicespinhais, estado do paraná, br

Come to one of the biggest IT Services companies in the world!! Here you can transform your career!.Why to join TCS? Here at TCS we believe that people make the difference, that's why we live a cul...Mostre mais

 • Promovida

Mobile Application Developer

Ascendioncuritiba, estado do paraná, br

Ascendion is a full-service digital engineering solutions company.We make and manage software platforms and products that power growth and deliver captivating experiences to consumers and employees...Mostre mais

 • Promovida

Software Engineer

Luxoftpinhais, estado do paraná, br

We are building a team to work on the FreeBSD Performance Monitoring Counter (PMC) framework, including hwmon, libpmc, and pmcstat.The project includes development, testing, and cooperation with th...Mostre mais

 • Promovida

Senior AI Security Engineer - Brazil Location

Ledelseapinhais, estado do paraná, br

We’re Hiring: Senior AI Security Engineer - Brazil.Language: Fluent English is mandatory.Language: Resumes must be in English.Start Date: Immediate joiners preferred or candidates who can join with...Mostre mais

 • Promovida

Consultor de Segurança de Aplicações - Sênior

Runtalentpinhais, estado do paraná, br

Somos a @Runtalent, com DNA inovador, somos consolidados no mercado de tecnologia e especializados em soluções de TI há quase duas décadas.Acompanhamos todos os avanços tecnológicos dos últimos ano...Mostre mais

 • Promovida

Endpoint Engineer-Crowdstrike

HCLTechcuritiba, estado do paraná, br

We are HCLTech, one of the world’s largest and fastest growing technology and DSA companies with over 227,000 professionals across 60 countries, driving progress through industry-leading capabiliti...Mostre mais

 • Promovida

Security Observability Engineer

Aegis Staffing Inccuritiba, estado do paraná, br

We’re Hiring: Security Observability Engineer (Mid-Level).Security Observability Engineer.You’ll work across cloud, identity, endpoint, SaaS, and network layers—turning raw data into meaningful ins...Mostre mais

 • Promovida

Cloud Security Engineer Sênior

Platform Builderscolombo, estado do paraná, br

Somos um ecossistema de transformação digital que combina tecnologia e visão estratégica para.Respeitamos todas as diferenças e criamos um.Se você deseja estar em um ambiente colaborativo, desafiad...Mostre mais

 • Promovida

ABAP Developer (PI/CPI) - Advanced English

HCLTechpinhais, estado do paraná, br

HCLTech is a global technology company, spread across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of tech...Mostre mais

 • Promovida

Implementation Analyst

The Methodical Groupcuritiba, estado do paraná, br

The Methodical Group (methodicalgroup.IT Services, Consulting, and Specialized Staffing Solutions, operating with a systematic, high-quality approach for over 25 years.Petersburg, Florida, we use p...Mostre mais

 • Promovida

DevOps Engineer SR

Encora Inc.curitiba, estado do paraná, br

This is a highly sensitive and mission‑critical role with admin‑level access to the core platform.The ideal professional is exceptionally reliable, security‑minded, technically strong, and trustwor...Mostre mais

 • Promovida

Event Management Engineer (Spyglass)

GeorgiaTEK Systems Inc.pinhais, estado do paraná, br

Observability & Event Management Engineer (Spyglass).Spyglass Event Configuration Management Primary Focus.Design and implement Event Correlation Rules within Spyglass to aggregate disparate logs a...Mostre mais

 • Promovida

NOC Infrastructure Engineer (REMOTE)

ITTConnectcuritiba, estado do paraná, br

The Infrastructure Engineer is responsible for supporting and maintaining customer IT infrastructure within the Managed Services environment.This role focuses on resolving technical issues, support...Mostre mais