Skip to content

Open nowPosted 68 days ago

Security Engineer (DevSecOps / AppSec)

Gupy (Portal de Vagas)74,621 open roles

Where
Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineer (DevSecOps / AppSec)Gupy (Portal de Vagas) · Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Gupy (Portal de Vagas)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 68 days ago

The posting

Estamos em busca de uma nova pessoa para integrar nosso time de Tech atuando como Security Engineer (DevSecOps / AppSec)! 🐿️Já imaginou fazer parte de uma das maiores empresas de tecnologia para restaurantes do Brasil? Atendemos mais de 20 mil clientes em todo o país e somos líderes em software de gestão na nuvem para o setor gastronômico! Além disso, somos uma das Super Integradoras do iFood, entregando uma solução completa — do Ponto de Venda à Retaguarda. Incrível, né?E tem mais: o iFood é nosso investidor!Isso significa que estamos em crescimento exponencial e acelerado — por isso, queremos pessoas que compartilhem da nossa energia, da nossa vontade de inovar e de revolucionar o mercado de food service, para crescer junto com a gente! 💙🧡Responsabilidades e atribuiçõesO que vai fazer parte do seu dia a dia 💼Implementar e manter ferramentas de SAST, DAST e SCA no pipeline de CI/CD (Bitbucket/GitHub/Gitlab)Implementar, manter, operar e evoluir o Secrets Manager e VaultExecutar secret scanning contínuo nos repositórios e conduzir a remediação dos achados com os times de devRealizar code reviews com foco em segurança em features críticas — autenticação, autorização, integrações externas, tratamento de dados sensíveisFazer hardening da infraestrutura: Terraform state, IAM policies, configurações AWS, Security Groups Apoiar a remediação de findings técnicos coletados de ferramentas de análise de segurança, pentests externos e varreduras internasConstruir e liderar o programa de Security Champions — identificar pontos focais nos squads de dev e estruturar capacitação contínuaConduzir threat modeling em novas features e integrações críticas junto aos times de produto e engenhariaDefinir e documentar requisitos de segurança no SDLC — do design ao deployAvaliar a segurança de APIs internas e externas, integrações com parceiros e fluxos de autenticaçãoRequisitos e qualificaçõesO que esperamos de você 👌Experiência prática com pipelines de CI/CD e integração de ferramentas de segurança (SAST, SCA, secret scanning) no fluxo de desenvolvimento.Conhecimento sólido de AWS: IAM, S3, Lambda, Security Groups, VPC, KMS e boas práticas de cloud security.Experiência com infraestrutura como código (Terraform) - sabe identificar e corrigir problemas de segurança em IaC.Conhecimento de OWASP Top 10 e OWASP API Security Top 10 com capacidade de aplicar em revisões de código e arquitetura.Capacidade de escrever scripts e automações para análise e remediação (Python ou Bash).Leitura e interpretação de código em pelo menos uma linguagem utilizada no produto.Senso Crítico e Análise de Risco.Proatividade: Iniciativa e Antecipação.Comunicação Interpessoal com Times de Desenvolvimento.Independência Técnica.Colaboração e Trabalho em Equipe.Didática e Transferência de Conhecimento.Acabativa: Entrega e Resultado.O que vai te destacar por aqui 💡Experiência com BitbucketGestão de segredos: HashiCorp Vault e/ou AWS Secrets Manager na prática.Familiaridade com ferramentas de DAST (OWASP ZAP, Burp Suite) integradas a pipelines.Conhecimento de segurança em containers Docker e repositórios de imagens.Experiência com CIS Benchmarks aplicados a workloads AWS.Noções de segurança mobile ou análise de binários - diferencial para o contexto de instaladores e app.Familiaridade com ferramentas de cloud posture management (Wiz, Prisma Cloud, AWS Security Hub, Guarduty).Experiência com revisão de segurança em arquiteturas serverless (Lambda, API Gateway)Certificações - DesejáveisAWS Certified Solutions Architect – AssociateAWS Certified Solutions Architect – ProfessionalAWS Certified Security – SpecialtyCertified DevSecOps Professional (CDP) - Practical DevSecOpsHashiCorp Vault AssociateInformações adicionais ✨ Curtiu? Calma que tem mais! Aqui você ainda terá:

🌴Contratação PJ com 30 dias de descanso remunerado 🏥 Plano de saúde e odontológico com mensalidade 100% paga pela Saipos (Coparticipação em consultas e exames) 💰 Seguro de vida 🎂 Day off no mês do aniversário 🥊 Wellhub 💻 Kit completo de equipamentos 🚗 Auxílio deslocamento diário (Em caso de vinda presencial) — R$ 22 💵 Auxílio home office - R$180,00 (Para profissionais que atuem pelo menos 3x por semana remoto) 🍼 Licença maternidade estendida e paternidade estendida

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Gupy (Portal de Vagas)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Gupy (Portal de Vagas)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Gupy (Portal de Vagas)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.