Geekhunter Logo

Solutions

Recruitment Software

Post jobs, import profiles, add screening questions, and manage hiring all in one place with personalized questions and control the entire recruitment process.

Recruitment Service

Let our expert team handle the key stages of tech recruitment for you with our specialized team acting in the main stages of recruitment.

Talent Pool

Top-tier Brazilian tech professionals, pre-vetted and ready for action, all pre-selected and ready for new opportunities.

Our Plans

Discover the perfect plan for your needs.

Login

English

EN

Nava Technology for Business

Senior Application Security Engineer

Show original

Hybrid

São Paulo, SP, Brazil

Salary Range

Not informed

Experience Level

Senior

Requirements

5+ years of experience in the career

Tasks and Responsibilities

Show original

We are looking for a Senior Application Security Specialist to work in a high-tech environment with a strong culture of collaboration, innovation, and security.


What you will do

  • Work with AppSec, Secure Coding, and DevSecOps
  • Perform in-depth security analyses on APIs
  • Support code reviews in Java, Python, .NET, or other relevant languages
  • Conduct security assessments in cloud and cloud-native environments
  • Collaborate with development, engineering, and product teams
  • Translate technical risks into practical and actionable recommendations

Requirements and qualifications

  • Solid experience in Application Security
  • Mastery of OWASP Top 10, OWASP ASVS, OWASP MASV, and API Security Top 10
  • Hands-on experience with SAST, DAST, and SCA
  • Experience with tools such as Checkmarx, GitLab Security, Snyk, Veracode, Fortify, SonarQube, or Blackduck
  • Knowledge of AWS and Azure
  • Experience with threat modeling using STRIDE
  • Familiarity with security practices in CI/CD
  • Knowledge of TLS, secure hashing, secure storage, OAuth2, OIDC, JWT, and mTLS
  • Experience with secure architectures, such as Zero Trust and Defense in Depth

Desired differentials

  • Participation in pentests, vulnerability exploitation, or bug bounty programs
  • Experience with GraphQL and complex microservices
  • Knowledge of IaC scanners, such as Checkov, Tfsec, and Kics
  • Knowledge of container scanners, such as Trivy, Anchore, and Clair
  • Certifications such as OSWE, OSCP, GWAPT, GWEB, eWPT, eCPPT, CEH, CSSLP
  • Cloud certifications, such as Security Specialty or AZ-500

Expected soft skills

  • Critical thinking and analytical vision
  • Strong communication skills to translate technical topics into risks and solutions
  • Ability to influence and engage with different areas
  • Organizational skills to handle multiple demands
  • Collaborative mindset, focused on mentoring and building trust

Apply now

If you have experience in AppSec and want to join a team that values technical depth, collaboration, and true security, we want to meet you.


Interested? Apply for the position and take your technical interview with SophIA:

https://entrevista.starmindai.ai

Code: NAVA-APPSEC

See all jobs at Nava Technology for Business

Share job:

Share job: