What You’ll Be Doing
-
Application Security, Secure SDLC & DevSecOps
- Lead Application Security initiatives across web, mobile, API, microservices, and cloud-native products.
- Conduct architecture reviews, threat modeling, secure design and code reviews, and hands-on security assessments.
- Identify weaknesses in authentication, authorization, tenant isolation, business logic, data protection, and API security.
- Define practical security standards, requirements, guardrails, and reusable secure engineering patterns.
- Improve security testing across CI/CD pipelines using SAST, DAST, SCA, secret scanning, container scanning, and Infrastructure as Code scanning.
- Drive risk-based vulnerability triage and remediation in partnership with engineering teams.
- Develop security automation and promote secure coding through developer guidance, documentation, and training.
-
AI Security Assessment & Adversarial Testing
- Lead security reviews of LLM applications, AI agents, RAG architectures, machine learning services, and third-party AI integrations.
- Assess AI architectures, including model APIs, data pipelines, vector stores, prompts, fine-tuning workflows, plugins, and agent tool chains.
- Conduct adversarial testing for prompt injection, jailbreaking, sensitive-data disclosure, system-prompt leakage, output manipulation, insecure tool use, excessive agency, and model abuse.
- Evaluate applicable risks involving data poisoning, model inversion, training-data extraction, adversarial evasion, and model exfiltration.
- Test security controls such as guardrails, input/output filtering, access controls, human approvals, logging, monitoring, and abuse detection.
- Develop repeatable AI security testing methodologies, playbooks, automation, and test cases using tools such as Garak, PyRIT, or similar frameworks.
- Assess security and supply-chain risks associated with third-party models, AI platforms, and AI-enabled SaaS products.
-
Reporting, Collaboration & Leadership
- Produce clear security reports containing evidence, risk ratings, business impact, and actionable remediation guidance.
- Communicate security risks effectively to developers, architects, product leaders, and executive stakeholders.
- Partner with external consultants, researchers, and bug bounty programs for specialized assessments where required.
- Mentor engineers and help establish a security-conscious engineering culture.
- Stay current with developments in Application Security, AI Security, and adversarial testing.
What You’ll Bring
- 8+ years of cybersecurity experience, with deep hands-on expertise in Application Security, product security, penetration testing, or security engineering.
- Experience conducting threat modeling, architecture reviews, secure code reviews, penetration testing, and vulnerability validation.
- 1-3 years of AI Security experience, with AI/ML security, adversarial testing of AI systems, or applied AI research with a security focus.
- Strong knowledge of web, mobile, API, and cloud-native security, including OWASP guidance and business-logic risks.
- Strong understanding of authentication and authorization technologies, including OAuth 2.0, OIDC, JWT, SAML, and modern access-control models.
- Hands-on DevSecOps experience with CI/CD security automation, SAST, DAST, SCA, secret scanning, containers, and Infrastructure as Code.
- Practical knowledge of Docker, Kubernetes, microservices, and cloud security.
- Demonstrated experience assessing or securing LLM applications, RAG systems, AI agents, machine learning models, or AI-enabled products.
- Understanding of AI threats such as prompt injection, jailbreaking, data leakage, insecure tool use, excessive agency, model misuse, and AI supply-chain risks.
- Familiarity with OWASP guidance for LLM applications, MITRE ATLAS, NIST AI RMF, and related AI security practices.
- Programming or scripting proficiency in Python, Go, JavaScript, Bash, or a similar language.
- Strong written and verbal communication skills, with the ability to influence technical and non-technical stakeholders.
Preferred Qualifications
- Experience building or scaling Application Security practices within a SaaS or product-led technology organization.
- Hands-on experience red teaming LLM applications, RAG systems, AI agents, or AI-enabled products.
- Experience developing security automation, internal testing tools, or reusable security guardrails.
- Contributions to security research, open-source projects, bug bounty programs, or responsible vulnerability disclosure.
- Relevant certifications such as OSCP, OSWE, GWAPT, GIAC, CISSP, or an AI Security credential.
🇧🇷 Essa vaga exige inglês. Você está pronto?
A DevSpeak Academy prepara desenvolvedores brasileiros para conquistar vagas internacionais. Domine o inglês técnico com professores que entendem o mundo dev.
Conheça a DevSpeak Academy