Senior Security Engineer | AppSec
GympassRemotely
Listed on 2 job boards, which is a stronger signal than one board alone.
awsiamappsecsastdast
Also available on
Job Description
📋 Description
- Protect our subscription platform across product verticals with a focus on application security.
- Own a control domain end-to-end, partnering with engineering to embed security into product
- Lead post-incident responses and post-mortems; drive guardrails, automation and policy improvements.
- Drive security-by-design standards; write RFCs, threat models, and design docs for high-risk
- Coordinate vulnerability remediation SLAs and security metrics with engineering teams.
- Support seamless security-critical migrations and platform updates while maintaining data integrity.
🎯 Requirements
- Experienced security engineer with a track record delivering tooling, detection logic, or secure
- Willingness to expand beyond AppSec to Cloud Security, GRC, or Detection as priorities evolve.
- Strong collaboration skills with cloud architectures and container ecosystems (AWS/EKS, GCP/GKE
- Fluent in English and Portuguese; able to translate complex security risks for engineers and
- Pragmatic problem-solver balancing security and product velocity with data-informed decisions.
- Developer-at-heart with deep knowledge of secure coding practices and security automation.
🎁 Benefits
- Flexible benefits program; hybrid and remote options available.
- Home office stipend to set up your workspace.
- Healthcare, dental, and life insurance; paid time off and parental leave.
- Career growth: internal opportunities and personalized development roadmap.
- Culture founded on wellbeing, collaboration, and belonging.
- Access to wellbeing programs and resources (Wellhub/Wellz) and wellness perks.
Back to all jobs