Cyber Security Specialist | AppSec
EBANX Ver todas as vagas
- Curitiba - PR
- Permanente
- Período integral
Let's build what's next - together.At EBANX's IT team you don't just manage systems and infrastructure. You ensure that our technology, which connects millions of people to global companies, runs flawlessly every day. Here, every solution you create has a direct impact on the revolution of digital payments, making our work truly Out Of The Ordinary.What your day-to-day will look like
- Lead the AppSec strategy and technical mentorship, guiding Junior, Mid-level, and Senior analysts in performing deep-dive security assessments and complex remediation;
- Architect and oversee Threat Modeling sessions across diverse product squads to identify architectural flaws and security requirements early in the design phase;
- Drive global security projects and communicate risk effectively in English to international stakeholders, ensuring that security initiatives align with business velocity;
- Manage the lifecycle of security vulnerabilities discovered through SAST, DAST, and SCA, providing actionable insights and polyglot code-fix guidance to engineering teams.
- Deep expertise in the AppSec Tooling ecosystem, including hands-on experience configuring and tuning SAST (Static Analysis), DAST (Dynamic Analysis), and SCA (Software Composition Analysis) within CI/CD pipelines;
- Strong command of API Security and Secret Management, with a proven track record of securing REST/GraphQL APIs and implementing robust policies for tokens, certificates, and secrets (e.g., HashiCorp Vault, AWS Secrets Manager);
- Multi-language coding proficiency, capable of reviewing and securing code across various stacks (such as Java, Python, Go, Node.js, or .NET) to support diverse development teams;
- Advanced to Fluent English communication, enabling you to lead technical discussions, document global standards, and collaborate with distributed teams worldwide.
- Advanced Security Certifications such as OSWE, CASE, CSSLP, or CISSP, demonstrating a high level of professional dedication;
- Experience automating custom security "guardrails" or building internal tools to automate the triaging of secrets and vulnerabilities at scale;
- Active participation in the security community, whether through Bug Bounty programs, open-source security projects, or speaking at conferences like OWASP Global AppSec.
- Performance Bonus: Annual bonus program based on company results.
- Meal Allowance: Monthly allowance to support your meals.
- EBANX Education: Financial assistance for undergraduate, graduate, and MBA programs to support your professional growth.
- EBANX Skills: Dedicated budget for courses, certifications, and workshops to encourage continuous learning.
- Language Classes: Language classes to support your personal and professional development.
- Health & Well-being: Medical and dental plans with extensive coverage, including support for dependents and wellness programs.