FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Information Security Analyst – AppSec
Banco ABC BrasilResponsible for leading Application Security initiatives at Banco ABC Brasil. Focus on Secure SDLC evolution and best security practices implementation.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Application Security (AppSec) with a focus on Secure SDLC, vulnerability analysis, and threat modeling. Proficient in utilizing security tools and frameworks to enhance security practices within development pipelines.
Highest-signal resume keywords
Application Security (AppSec)Secure SDLCVulnerability AnalysisThreat ModelingAzure DevOps
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
SAST ToolsSCA ToolsOWASP Top 10OWASP API Security Top 10OWASP ASVS v2Secure Code AnalysisREST APIsOAuth2OIDCJWT
Soft Skills
Good Communication Skills
Tools & Technologies
SnykCheckmarxVeracodeGitHubCI/CDKeycloakRASPDASTIASTAPI Gateway Solutions
Industry Keywords
NIST SSDFOWASP SAMMLGPDFinancial EnvironmentsSupply Chain Security
Tech Stack
Tools & technologiesAWSAzureKubernetesSaltStackSDLC
About the role
Key responsibilities & impact- Act as the technical lead for the Application Security program, driving continuous evolution of the Secure SDLC and ensuring security is integrated from solution design through production deployment.
- Define secure development standards, Security Gates, Security by Design, Security by Default, Threat Modeling, minimum security requirements, and Security Champions; support Security Architecture in adopting best practices.
- Promote a secure development culture through training, workshops, and technical support to development squads.
- Technically lead the Application Security (AppSec) program, ensuring continuous improvement of the Secure SDLC and enhancing security controls in development pipelines (Azure DevOps and GitHub).
- Validate vulnerabilities identified by tools, prioritizing based on CVSS, business context, and exploitability.
- Technically analyze vulnerabilities found in source code.
- Reproduce vulnerabilities when necessary to provide technical proof.
Requirements
What you’ll need- Strong experience in Application Security (AppSec).
- Practical experience with Secure SDLC.
- Solid knowledge of web and API vulnerability exploitation.
- Experience with SAST and SCA tools.
- Experience with Snyk, Checkmarx, Veracode, or equivalent tools.
- Strong knowledge of OWASP Top 10.
- Strong knowledge of OWASP API Security Top 10.
- Knowledge of OWASP ASVS v2.
- Experience in Threat Modeling (STRIDE, PASTA and/or DREAD).
- Experience with Azure DevOps and/or GitHub.
- Experience with CI/CD.
- Knowledge of Git.
- Knowledge of REST APIs.
- Knowledge of OAuth2.
- Knowledge of OIDC.
- Knowledge of JWT.
- Knowledge of Keycloak or equivalent solutions.
- Experience in secure code analysis.
- Good communication skills with development teams.
- Advanced English.
- Nice to have / Differentials:
- Experience with RASP.
- Experience with DAST.
- Experience with IAST.
- Experience with API Gateway solutions (Apigee, Kong, AWS API Gateway, Azure API Management).
- Experience with Salt Security.
- Experience with Kubernetes.
- Experience with containers.
- Experience with supply chain security.
- Knowledge of SBOM.
- Knowledge of Sigstore/Cosign.
- Experience in financial environments.
- Knowledge of NIST SSDF.
- Knowledge of OWASP SAMM.
- Knowledge of LGPD (Brazilian Data Protection Law).
Benefits
Comp & perks- Medical insurance;
- Dental insurance;
- Life insurance;
- Profit sharing (PLR);
- Performance-based bonus (PPR);
- Physical, social and mental wellness programs;
- Meal voucher;
- Food voucher;
- Extended parental leave: 20 days paternity and 6 months maternity;
- Childcare / nanny assistance;
- Annual day off;
- Home office allowance;
- Home office infrastructure support;
- TotalPass;