Application Security Specialist improving security practices throughout development lifecycle at ClickBus. Collaborating with teams for vulnerability remediation and secure coding guidelines implementation.
Responsibilities
Implement and advance Application Security (AppSec) practices throughout the development lifecycle.
Conduct security reviews of architecture and code.
Execute and support SAST, DAST, SCA processes and security testing of applications.
Identify, analyze, and prioritize vulnerabilities in applications and APIs.
Collaborate with engineering teams to remediate vulnerabilities.
Support the implementation of DevSecOps practices in CI/CD pipelines.
Define and evolve secure development policies, standards, and guidelines.
Perform threat modeling for new projects or significant architectural changes.
Support bug bounty processes, penetration tests, and vulnerability management.
Promote a security culture through training and awareness programs for developers.
Requirements
Experience in Application Security.
Knowledge of OWASP Top 10 vulnerabilities.
Experience with security tools such as SAST, DAST, SCA, and secret scanning.
Knowledge of web application and API architecture.
Experience with programming languages (e.g., Java, Python, Node.js, Go, etc.).
Experience with cloud environments (preferably AWS).
Understanding of CI/CD pipelines and DevSecOps practices.
Ability to perform technical analyses and translate risks to non-technical stakeholders.
Benefits
Meal/Food allowance: R$ 1,000.00/month credited to the Flash card;
Home office allowance: R$ 149.00/month credited to the Flash card;
Flexible benefits: R$ 200.00/month credited to the Flash card;
Busonauta Traveler: Our exclusive benefit for Busonauta employees — R$ 2,000.00/year to use for bus ticket purchases in the app or on the site;
Transportation voucher;
Parking;
SulAmérica Health Insurance: no co-payment and no monthly fee;
Bradesco Dental Insurance;
Childcare assistance for parents;
6-month maternity leave and 30-day paternity leave;
Life insurance;
Wellhub and TotalPass;
Annual profit-sharing (PLR);
Birthday day off;
Partnership with Petlove;
Pharmacy assistance;
Support for employees with children with disabilities;
Partnerships with educational and leisure institutions;
Information Security Specialist responsible for protecting systems and data at Ituran. Collaborating with teams and ensuring compliance with security measures and regulations.
Senior Cloud & Information Security Engineer responsible for EC Markets' technical security posture. Designing and operating secure systems while ensuring regulatory compliance and cloud infrastructure security.
Product Security Engineer focusing on ensuring software resilience against attacks during development phases. Collaborating with DevOps and Engineering teams to enhance security protocols.
IT audit specialist responsible for executing technology and cybersecurity audits at an international bank in Zurich. Collaborating with top management to enhance internal controls and efficiencies.
IT Systemadministrator focusing on Sophos Security at bauXpert GmbH. Responsible for IT infrastructure management and support tasks in a hybrid environment.
Cyber Security Specialist designing and implementing security controls for Squarcle clients. Supporting compliance with regulations and best practices in a digital environment.
Head of Security at Street Group managing organizational security and working with IT and Engineering teams. Leading security posture and compliance while mitigating emerging threat vectors.
Security Consultant providing technical leadership in electronic security systems engineering for complex built environments. Leading projects through all lifecycle stages while engaging with clients and contractors.