Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Certisign

Senior AppSec Analyst

Certisign

Analista AppSec SR responsible for application security throughout the corporate development lifecycle. Collaborating with teams to ensure compliance with security standards like OWASP and ISO.

Posted 5/26/2026full-timeSão Paulo • 🇧🇷 BrazilSeniorWebsite

Tech Stack

Tools & technologies
AnsibleAWSAzureCloudDockerGoogle Cloud PlatformKubernetesTerraform

About the role

Key responsibilities & impact
  • Define and implement application security policies and practices;
  • Perform vulnerability assessments and application security testing (SAST, DAST, application pentests);
  • Support development teams in remediation and prevention of vulnerabilities;
  • Integrate security tools into DevOps pipelines (DevSecOps);
  • Monitor and analyze security alerts, vulnerability reports, and application logs;
  • Ensure compliance with security standards and regulations (ISO, LGPD, PCI, OWASP);
  • Develop secure coding guidelines and deliver internal training on software security;
  • Collaborate with product and engineering teams to build secure architectures;
  • Conduct risk analyses and code reviews to identify critical issues;
  • Implement monitoring tools and application-related incident response;
  • Prepare technical and executive reports on system security posture;
  • Support internal and external audits by providing evidence and recommendations;
  • Participate in defining security strategies for new platforms and integrations;
  • Promote continuous improvement of application security processes.

Requirements

What you’ll need
  • Bachelor's degree in Information Technology, Systems Analysis, Engineering, or related fields;
  • Deep knowledge of OWASP Top 10, SAST, DAST, RASP and AppSec concepts;
  • Experience in analyzing and mitigating code vulnerabilities (DevSecOps);
  • Familiarity with secure architectures, authentication, authorization, and cryptography;
  • Proficiency with application security tools (Burp Suite, Fortify, SonarQube, Checkmarx, etc.);
  • Experience with secure CI/CD, integrating security into pipelines, and test automation;
  • Understanding of standards and frameworks: ISO 27001, NIST, PCI DSS, LGPD;
  • Knowledge of secure APIs, tokens, OAuth2, OpenID Connect, and JWT;
  • Ability to identify, report, and mitigate security risks in cloud environments (AWS, Azure, GCP);
  • Familiarity with infrastructure as code (Terraform, Ansible) and security practices for containers (Docker, Kubernetes);
  • Knowledge of microservices security and distributed applications.

Benefits

Comp & perks
  • Meal allowance on Flash card 🍽️
  • Grocery allowance on Flash card 🛒
  • SulAmérica medical insurance 🏥
  • MetLife dental insurance 😁
  • TotalPass and Wellhub benefits 💪
  • Birthday day off 🎉
  • Childcare assistance 👶
  • Corporate university - UniSign 📚
  • Life insurance 🔒
  • Educational partnerships 🎓
  • SESC membership benefits 🏖️
  • Better Maternity program 🤱
  • Extended maternity and paternity leave 👪
  • Pharmacy card 💊
  • Profit-sharing (PLR) 💼

ATS Keywords

✓ Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
application securityvulnerability assessmentsSASTDASTDevSecOpssecure codingrisk analysiscode reviewstest automationmicroservices security
Soft Skills
collaborationcommunicationtrainingreportingcontinuous improvement
Certifications
Bachelor's degree in Information TechnologyBachelor's degree in Systems AnalysisBachelor's degree in Engineering