Lead the definition and evolution of corporate security architecture and AppSec strategy.
Oversee threat modeling, architecture reviews and integrate AppSec into the SDLC (DevSecOps).
Responsibilities
Coordinate the definition and evolution of corporate security architecture, including applications, APIs, cloud, on-premises and hybrid environments;
Define principles, standards, controls and security architecture guidelines aligned with frameworks such as NIST, ISO 27001, Zero Trust and CSA;
Perform and oversee solution architecture reviews, assessing risks, security controls and compliance with defined standards;
Collaborate with enterprise architecture and infrastructure/cloud teams to define secure and resilient architectures;
Support strategic decisions regarding technologies, platforms and new products from a security perspective;
Define and coordinate the application security (AppSec) strategy, integrated into the development lifecycle (SDLC / DevSecOps);
Oversee threat modeling, risk analysis and vulnerability assessment activities for applications and APIs;
Ensure adoption of Secure Coding and DevSecOps practices and tools (SAST, DAST, IAST, SCA, ASPM);
Provide technical support and guidance to development teams on vulnerability remediation and risk mitigation;
Define policies, standards and minimum security requirements for internal and third-party applications;
Requirements
Strong experience in Security Architecture and/or Application Security (AppSec);
Hands-on experience in software development (Java, .NET, Node.js, Python or similar) with a solid understanding of the SDLC;
Advanced knowledge of OWASP Top 10, CWE, NIST, ISO 27001, CIS and security best practices;
Experience in threat modeling, risk analysis and architecture review;
Practical knowledge of SAST, DAST, IAST, SCA and ASPM tools and processes;
Experience with cloud environments and modern architectures (microservices, APIs, containers);
Clear communication skills and the ability to act as a technical leader and strategic advisor.
** Differentials
Technical certifications in cybersecurity and architecture;
Previous experience coordinating or providing technical leadership for security teams;
Experience in regulated or large-scale environments.
Benefits
Medical and dental coverage (employee and dependents)
Dr. C&A - Telemedicine and teletherapy services
Annual bonus
Parking or transportation voucher (Work location: Alphaville – Barueri/SP)
Birthday off: one paid day off during your birthday month
Sales Account Manager for Cyber Security and Awareness role at HvS - Consulting GmbH. Providing holistic consulting on Cyber Security services and managing client relationships.
Security Engineer at PRC - Saltillo safeguarding IT infrastructure from cyber threats. Collaborating with IT teams to design and maintain security controls in a hybrid work environment.
Information Security Manager leading cyber security initiatives at NVISO, enhancing clients’ security posture and managing a team of consultants in Germany.
Cybersecurity Assessment Expert at IT - Strat managing A&A of information systems for U.S. federal clients. Ensuring compliance with DOD cybersecurity policies and standards in complex IT environments.
Senior Security Engineer responsible for deploying and maintaining endpoint security solutions. Collaborating across teams to enhance security posture and supporting incident response activities.
Administrative support role within MAHLE's Thermal and Fluid Systems unit, assisting the team with various operational tasks and employee interactions.
Senior Security Engineer at PagBank focusing on application security and secure development practices. Responsibilities include testing, vulnerability management, and collaboration with development teams.
Security Software Engineer at a tool - building company automating coding. Focused on shipping secure products covering enterprise security, cloud, and embedded protections.
Senior Product Cyber Security Systems Engineer at Sonova focusing on product security and cyber threats. Collaborating with teams to maintain robust security practices and compliance.