CareerPlanSign in

Senior Product Security Engineer

BrazilRemoteFull-time2026-09-23 → 2026-10-02

Core

Partner with developers to secure the product across the SDLC through design reviews, threat modeling, penetration testing, and secure-coding partnership.

Role type

Senior IC product security engineer

Builds

Defensible web applications and APIs

Required skills

Penetration testing (web apps/APIs), SDLC security integration, Threat modeling, Secure code review, SAST/DAST/Supply-chain scanning triage, OAuth 2.0/OpenID Connect, OWASP Top 10

Preferred skills

Offensive Security Certified Professional (OSCP), Cloud security (AWS/Azure/GCP), Container/Kubernetes security, SOC 2/ISO 27001 compliance support

Technologies

OWASP ZAP, Burp Suite, Semgrep, Trivy, Grype, Nuclei

Responsibilities

Lead security design and architecture reviews; Perform hands-on penetration testing of web applications and APIs; Conduct secure code reviews and define secure-coding standards; Operate and tune SAST, DAST, and dependency scanning tools; Translate security findings into prioritized, fixable work; Contribute to compliance posture (SOC 2, ISO 27001)

Seniority

Senior, hands-on IC