Senior Security Engineer at PagBank focusing on application security and secure development practices. Responsibilities include testing, vulnerability management, and collaboration with development teams.
Responsibilities
Plan and execute security testing for all solutions developed internally or externally within the secure pipeline, using automated SAST and DAST tools and performing penetration tests in QA environments.
Record vulnerabilities and manage them within the teams.
Assist the Development team in identifying potential security risks, supported by guides and a security champions program.
Attend meetings with business and development stakeholders, providing guidance for secure implementation.
Conduct penetration tests and produce security reports and assessments.
Requirements
Bachelor's degree completed or in progress in Information Technology, Computer Science, Information Systems or related fields.
Experience with secure development methodologies (security shift-left and security by design).
Experience with SAST and DAST solutions in secure pipelines and DevSecOps.
Experience with Web and Mobile applications and REST APIs.
Experience with Threat Modeling.
Experience with application penetration testing.
Knowledge of SSDLC (Secure Software Development Life Cycle) and SSL.
Knowledge of application vulnerabilities and classification methodologies.
To stand out in this role, it would be a plus to also have:
Certifications such as CEH, eWPTx, OSWA, CBBH.
Knowledge of Go, Python, Java and Kotlin.
Benefits
Meal allowance and/or meal voucher.
Health and dental insurance.
Life insurance.
Partnerships with TotalPass and ZenKlub.
Extended maternity and paternity leave.
Childcare assistance.
Up to 50% discounts on postgraduate and MBA programs at major institutions such as FIA, FAAP and PUCRS.
No formal dress code: wear what makes you comfortable.
Microsoft Success Manager helping partners grow secure, scalable Microsoft practices across ANZ. Championing Microsoft security solutions and supporting partner success strategies in the region.
Assistant AVP overseeing a 5 - member team for Access Management services in Pune and Mumbai, ensuring high standards of service delivery and compliance.
Own global security systems infrastructure for QVC, managing access control and networked security systems across multiple regions. Collaborate with IT to ensure security and technology initiatives meet organizational needs.
Sales Account Manager growing ADAPTIT Cybersecurity business in Greece and Cyprus. Responsible for client relations, sales pipeline, and collaboration with the cybersecurity team.
Information Security Engineer focusing on Identity & Access Management and SSO at Westfield. Design, operate, and mature enterprise authentication and federation capabilities.
Cyber Security Engineer responsible for operational support and development activities with Ping Identity. Collaborate with global teams to strengthen cybersecurity and improve customer satisfaction.
Application Security Specialist focusing on security in software development lifecycle at Insight Investment in Manchester, driving DevSecOps practices across teams.
Cyber Security Engineer supporting mission - critical DoD contract at CACI. Involves reviewing infrastructure changes and implementing security measures in a cloud - based environment.
Security Incident Management Analyst coordinating information security incidents. Overseeing cyber incident response and providing guidance to senior management within a leading industrial software company.
Customer Security Engineer managing end - to - end pentesting services at Aikido Security. Ensuring customer value and addressing vulnerabilities for a developer - first security product.