Logo for Compass.uol

Security Engineering Analyst — AppSec | Senior (Remote)

Role overview

Qualifications

  • Experience in corporate environments of medium or large complexity
  • Experience working directly with development teams
  • Experience in defining or evolving security processes and controls
  • Technical knowledge in SSDLC and Security by Design

Responsibilities

  • Define and evolve the corporate Secure Software Development Life Cycle (SSDLC) process
  • Establish minimum security requirements for applications
  • Integrate security controls and requirements into the application lifecycle
  • Identify, analyze, and address vulnerabilities in applications

Key facts

Hard skills

Other skills

  • Collaboration

About the company

Compass.uol logo

Compass.uol

Digital Transformation Consulting

Compasso UOL is a Brazilian technology company owned by the UOL Group, which offers technology services, and provides state-of-the-art solutions, contributing to the digital transformation of its customers so they can become leaders in its sectors of activity. Compasso UOL is a company that cultivates people's talent and use state-of-the-art technologies such as Agile Development, Multicloud, Data&Analytics, Cyber Security, Artificial Intelligence/Machine Learning, APIs/Microservices, IoT and others, providing technology and knowledge that help customers in building digital solutions that enable the transformation and evolution of their business.

Company details

Company typeXLarge
IndustryDigital Transformation Consulting
Company size5001 - 10000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

JOB DESCRIPTION


.


RESPONSIBILITIES AND ASSIGNMENTS


  • Definir e evoluir o processo corporativo de Secure Software Development Life Cycle (SSDLC);
  • Estabelecer requisitos mínimos de segurança para aplicações;
  • Definir e implementar Security Gates nos processos de desenvolvimento e CI/CD;
  • Integrar controles e requisitos de segurança ao ciclo de vida das aplicações;
  • Apoiar a evolução da cultura de desenvolvimento seguro na organização.
  • Participar de projetos desde as etapas iniciais de concepção e arquitetura;
  • Realizar avaliações de segurança das soluções e arquiteturas propostas;
  • Identificar riscos e vulnerabilidades e propor medidas de mitigação;
  • Aplicar Threat Modeling e práticas de Security by Design;
  • Atuar em conjunto com arquitetos, desenvolvedores, DevOps e demais equipes técnicas.
  • Identificar, analisar e tratar vulnerabilidades em aplicações;
  • Apoiar times de desenvolvimento na adoção de práticas de Secure Coding;
  • Realizar revisão de código sob a perspectiva de segurança;
  • Avaliar APIs, microsserviços, containers e componentes de software;
  • Trabalhar com vulnerabilidades e riscos relacionados a dependências, código, infraestrutura e configurações.
  • Integrar ferramentas de segurança às esteiras de CI/CD;
  • Trabalhar com soluções de SAST, DAST, SCA, Secret Scanning, IaC Scanning e Container Security;
  • Apoiar a implementação e gestão de SBOM;
  • Definir critérios e políticas para Security Gates;
  • Promover automação dos controles de segurança ao longo das pipelines.
  • Atuar em ambientes AWS, apoiando a implementação de arquiteturas seguras;
  • Avaliar configurações e controles de segurança em cloud;
  • Trabalhar com recursos como AWS API Gateway e AWS Security Hub;
  • Apoiar a identificação e tratamento de riscos relacionados à infraestrutura e aplicações em cloud.


REQUIREMENTS AND QUALIFICATIONS


  • Experiência em ambientes corporativos de média ou grande complexidade;
  • Experiência trabalhando diretamente com times de desenvolvimento;
  • Experiência em definição ou evolução de processos e controles de segurança.
  • Conhecimentos técnicos

  • SSDLC — Secure Software Development Life Cycle;
  • Security by Design;
  • Threat Modeling;
  • OWASP Top 10;
  • OWASP ASVS;
  • Secure Coding;
  • API Security;
  • Arquitetura de Aplicações;
  • Arquitetura de Microsserviços;
  • DevOps e CI/CD;
  • Gestão de vulnerabilidades em aplicações.
  • Experiência com pelo menos parte das seguintes tecnologias e práticas:

  • SAST;
  • DAST;
  • SCA;
  • Secret Scanning;
  • IaC Scanning;
  • Container Security;
  • SBOM;
  • CI/CD;
  • DevSecOps.
  • Experiência com AWS;
  • AWS API Gateway;
  • AWS Security Hub;
  • Conhecimentos de segurança e arquitetura em cloud.


Become a Compasser, be part of AI/R.


Compass UOL is a global firm and part of the AI Revolution Company, together transforming organizations using Artificial Intelligence, Generative AI, and other of today’s most advanced technologies.

We equip our team with proprietary and external AI-driven tools to design and build digital-native platforms, integrating cutting-edge technologies and enabling companies to innovate, transform their businesses, and drive success in their markets.

To achieve this, we attract and develop the best talent, creating opportunities that enhance people’s lives and highlight the positive impact of disruptive technologies.

We empower borderless talent and promote knowledge and opportunities in the latest market trends, driving significant personal and professional growth.

Join us and be part of the AI-driven revolution.


Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at Compass.uol

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.