Skip to main content
Infios

Security Analyst

RemoteBrazil only
Published
Role
Security
Experience
Senior
Employment
Full-time
Salary not disclosed
Check eligibility

Open to BR only. Set where you work from to check your eligibility.

No BS summary

Experienced Application/Product Security engineer (5+ years) to own TVM/AppSec for web, API, cloud-native and LLM-powered features. Remote hire limited to Brazil. Hands-on with DAST/SAST/SCA, cloud platforms (AWS/Azure/OCI) and OWASP Top 10/LLM security.

Core skills

DASTSASTAI/LLM security

Required skills

Application SecurityVulnerability ManagementSoftware Composition AnalysisWeb Application SecurityAPI SecurityOWASP Top 10Secure SDLCAWSAzureOCICSPM (WIZ)DocumentationCommunicationREST APIsMicroservicesPythonBash

Optional skills

Burp SuiteZAPSnykSemgrepCheckmarxVeracodeAI-augmented security toolingSOC 2

What you'll do

  • Scan vulnerabilities using industry-leading tools in applications and infrastructure.
  • Conduct and manage DAST, SAST, and software composition analysis (SCA) activities.
  • Analyze vulnerability scan results, validate findings, reduce false positives, and prioritize risk.
  • Collaborate directly with development teams to assess identified vulnerabilities and deliver precise, actionable remediation recommendations.
  • Track vulnerabilities through remediation and verify fixes.
  • Act as a trusted AppSec advisor to engineering and product teams.
  • Use expertise in OWASP Top 10 and common web application and API attack methods.
  • Support secure development practices, threat modeling, and design reviews.
  • Contribute to secure coding guidance, patterns, and best practices.
  • Leverage AI-powered tools to improve vulnerability analysis, accelerate triage and reporting, and enhance testing efficiency.
  • Identify opportunities to automate repetitive security tasks and workflows.
  • Contribute to continuous improvement of TVM and AppSec tooling and processes.
  • Lead and support security testing of AI and LLM-powered features across the organization.
  • Assess and test for risks outlined in the OWASP Top 10 for LLM Applications.
  • Help define and operationalize AI security testing strategies within the SDLC.

What they require

  • 5+ years of experience in Application Security, Product Security, or Vulnerability Management
  • Experience with cloud platforms like AWS, Azure, and OCI and CSPM tools (WIZ).
  • Strong hands-on experience with DAST and SAST tools, Web Application and API Security Testing.
  • Deep understanding of OWASP Top 10 and Secure SDLC principles.
  • Excellent documentation and communication skills (both verbal and written).
  • Analytical problem-solving skills and knowledge of application security architecture.
  • Experience working directly with software development teams on remediation.
  • Solid understanding of modern application architectures (REST APIs, microservices, cloud).
  • Familiarity with OWASP Top 10 for LLMs.

Benefits

  • Equal-opportunity employer and committed to inclusion in the workplace.
  • Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this role.
  • Applications must be submitted via our career site.

We develop future technologies to relentlessly make supply chains better. We are a leader in supply chain software solutions, helping organizations streamline operations, reduce costs, and improve efficiency.

Supply Chain Softwareinfios.com/
Salary not disclosed