Application Security Specialist improving security practices throughout development lifecycle at ClickBus. Collaborating with teams for vulnerability remediation and secure coding guidelines implementation.
Responsibilities
Implement and advance Application Security (AppSec) practices throughout the development lifecycle.
Conduct security reviews of architecture and code.
Execute and support SAST, DAST, SCA processes and security testing of applications.
Identify, analyze, and prioritize vulnerabilities in applications and APIs.
Collaborate with engineering teams to remediate vulnerabilities.
Support the implementation of DevSecOps practices in CI/CD pipelines.
Define and evolve secure development policies, standards, and guidelines.
Perform threat modeling for new projects or significant architectural changes.
Support bug bounty processes, penetration tests, and vulnerability management.
Promote a security culture through training and awareness programs for developers.
Requirements
Experience in Application Security.
Knowledge of OWASP Top 10 vulnerabilities.
Experience with security tools such as SAST, DAST, SCA, and secret scanning.
Knowledge of web application and API architecture.
Experience with programming languages (e.g., Java, Python, Node.js, Go, etc.).
Experience with cloud environments (preferably AWS).
Understanding of CI/CD pipelines and DevSecOps practices.
Ability to perform technical analyses and translate risks to non-technical stakeholders.
Benefits
Meal/Food allowance: R$ 1,000.00/month credited to the Flash card;
Home office allowance: R$ 149.00/month credited to the Flash card;
Flexible benefits: R$ 200.00/month credited to the Flash card;
Busonauta Traveler: Our exclusive benefit for Busonauta employees — R$ 2,000.00/year to use for bus ticket purchases in the app or on the site;
Transportation voucher;
Parking;
SulAmérica Health Insurance: no co-payment and no monthly fee;
Bradesco Dental Insurance;
Childcare assistance for parents;
6-month maternity leave and 30-day paternity leave;
Life insurance;
Wellhub and TotalPass;
Annual profit-sharing (PLR);
Birthday day off;
Partnership with Petlove;
Pharmacy assistance;
Support for employees with children with disabilities;
Partnerships with educational and leisure institutions;
Head of Security at Street Group managing organizational security and working with IT and Engineering teams. Leading security posture and compliance while mitigating emerging threat vectors.
Security Consultant providing technical leadership in electronic security systems engineering for complex built environments. Leading projects through all lifecycle stages while engaging with clients and contractors.
Assistente de Segurança da Informação supporting operational activities in information security at AuditSafe. Engaging in monitoring, documentation, and compliance efforts in cybersecurity.
Security Architect for Logicalis focusing on networking and security solutions for clients. Engaging with vendors and providing technical documentation and proposals collaboratively.
Técnico de Segurança do Trabalho ensuring safety protocols and risk management at KFC stores in Brazil. Focused on implementing regulatory standards and safety training initiatives.
DevSecOps engineer at Ford ensuring secure software development and compliance with security standards. Collaborating with teams to embed security practices and assess vulnerabilities in software delivery.
Security Officer responsible for ensuring safety and security at the Genesee Brewing Company. Monitoring premises, responding to emergencies, and providing visitor assistance during shifts.
Security Estimator creating estimates and proposals for security projects at LINX. Collaborating with engineering and sales teams for system design and client relationships.