JJobsSonar

Product Security Analyst

jobgether · Brazil

Accountabilities: Identify technical vulnerabilities and recommend security improvements across the product ecosystem, including applications built with Ruby, Go, and PHP. Develop and implement security fixes directly in code, going beyond vulnerability reporting to actively resolve identified risks. Analyze development requests and support engineering teams by reducing Application Security bottlenecks and enabling faster, safer delivery. Conduct threat modeling activities and apply secure-by-design principles across product initiatives. Create security guardrails, tooling, and automation solutions that make secure development practices the default approach for engineering teams. Integrate, configure, and optimize security tools within CI/CD pipelines, including SAST, SCA, and secret scanning solutions. Help maintain strong application security standards through collaboration, knowledge sharing, and continuous improvement initiatives. Support cloud security practices within AWS environments, ensuring secure product development and deployment. Requirements: Experience in software engineering or security engineering roles with hands-on experience writing and delivering production-level code. Strong knowledge of Application Security and Product Security practices, including threat modeling, secure-by-design methodologies, and security tooling. Experience developing security automations and solutions using technologies such as Ruby, PHP, or AWS Lambda is highly desirable. Solid understanding of CI/CD security practices, including SAST, SCA, and secret scanning configuration and optimization. Knowledge of cloud security principles, particularly within AWS environments applied to product development. Ability to collaborate effectively with engineering teams by proposing and implementing security improvements directly in applications. Strong analytical, problem-solving, and communication skills. Professional written and spoken English communication skills. Security certifications or additional training in information security are considered a plus. Benefits: 100% remote work environment with flexibility and autonomy. Trust-based culture focused on results, collaboration, and continuous learning. Opportunity to take ownership of impactful security initiatives and influence product security practices. Supportive environment with strong collaboration, empathy, and open communication. Regular feedback culture and one-on-one meetings with leadership. Comprehensive benefits package including meal/food allowance, childcare support, home office assistance, health benefits, education and culture support, wellness programs, birthday day-off, therapy discounts, English courses, and additional partnerships. Opportunity to work on challenging security problems while contributing to safer digital experiences.
Ready to apply?Apply now

Similar jobs

Browse all

Cloud Platform Engineer

ASE (Analysis Simulation Engineering) AG · Zurich, Zurich, Switzerland

On-siteEasy apply2w ago

DevOps Engineer

Sundayy · United States

RemoteEasy apply401(k), Medical2w ago