FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Application Security throughout the software development lifecycle, with a strong focus on threat modeling, vulnerability management, and compliance with security standards such as OWASP ASVS. Proficient in integrating security tools into CI/CD pipelines and translating technical risks into business impacts.
Highest-signal resume keywords
Application SecurityThreat ModelingSAST, DAST, SCAOWASP ASVSCloud Security
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Application SecurityThreat ModelingSASTDASTSCAOWASP ASVSMicroservicesContainersAutomationCI/CD
Soft Skills
CommunicationCollaborationProblem-Solving
Tools & Technologies
DockerKubernetesAWSGCPAzure
Industry Keywords
Security Champions ProgramVulnerability RemediationArchitectural RisksDefect DensityRemediation SLAs
Tech Stack
Tools & technologiesAWSAzureDockerGoogle Cloud PlatformKubernetesSDLC
About the role
Key responsibilities & impact- Implement security controls across the development lifecycle, from design to deployment, as part of the AppSec program.
- Conduct Threat Modeling sessions with product squads to identify architectural risks before implementation.
- Manage and optimize SAST, DAST and SCA tools, prioritizing findings based on real business risk rather than only isolated technical severity.
- Maintain the Security Champions program, empowering developers to be the first line of defense.
- Validate the architecture of new projects and API integrations, ensuring compliance with OWASP ASVS and internal standards.
- Manage the vulnerability remediation workflow with engineering, addressing root causes rather than just symptoms.
- Translate technical risks into business impact for Product Owners and stakeholders. Automate security validations in CI/CD pipelines and maintain metrics such as remediation SLAs and defect density.
Requirements
What you’ll need- Hands-on experience in Application Security across the full SDLC.
- Experience with threat modeling and architecture review of applications and APIs. Proficiency with SAST, DAST and SCA, and integrating these tools into CI/CD pipelines.
- Knowledge of OWASP ASVS, OWASP Top 10 and SAMM.
- Familiarity with microservices, containers (Docker, Kubernetes) and cloud security (AWS, GCP or Azure).
- Strong development or automation background, with the ability to propose scalable solutions as code.
- Availability for hybrid work: must attend our office in the Morumbi area of São Paulo once a month for four consecutive days, usually during the last or first week of the month (Creditas in Person).
Benefits
Comp & perks- Health plan (Alice)
- Dental plan (SulAmérica)
- Wellz: 100% free therapy sessions
- Wellhub: access to gyms and studios
- Creditas Endurance: high-impact sports incentive program
- Pharmacy partnership (Univers)
- Life Insurance (Porto Seguro)
- Birthday day off
- Extended parental leave: 6 months for birthing parents and 35 days for non-birthing parents
- Family Care: support program for maternity and paternity
- Childcare allowance
- Support allowance for dependents with disabilities (PWDs)
- SESC: access to facilities for you and your dependents
- Meal Allowance (VR): flexible benefits card (Creditas Card)
- Payroll-deductible loans (Creditas Benefits)
- Salary advance (Creditas Benefits)
- Discounts on insurance (Minuto Seguros)
- Access to exclusive financial education content in the Creditas app
- PPR: profit-sharing program
- Educational and professional development incentives
- Flexible work model
- Free bike parking at the office
- Partnered parking at the office (subject to internal availability)
