All roles

SR Application Security Engineer - Argentina, Brazil, Uruguay & Spain

Remote · USA Full-time New today

Why should you join dLocal? dLocal enables the biggest companies in the world to collect payments in 40 countries in emerging markets. Global brands rely on us to increase conversion rates and simplify payment expansion effortlessly. As both a payments processor and a merchant of record where we operate, we make it possible for our merchants to make inroads into the world’s fastest-growing, emerging markets. By joining us you will be a part of an amazing global team that makes it all happen, in a flexible, remote-first dynamic culture with travel, health and learning benefits, among others. Being a part of dLocal means working with 1000+ teammates from 30+ different nationalities and developing an international career that impacts millions of people’s daily lives. We are builders, we never run from a challenge, we are customer-centric, and if this sounds like you, we know you will thrive in our team. What will I be doing?

  • Implement a software assurance model designed to address security defects early in the delivery pipeline
  • Perform security design reviews for new features and product releases
  • Perform code reviews and advise developers on remediation techniques
  • Design controls to detect and respond to common attacks on our platform
  • Tech talks in high technical level to engineers
  • Triage and respond to external inquiries around security vulnerabilities
  • Facilitate internal training on various security topics to raise awareness and interest

What skills will I need to have?

  • Strong proficiency in at least one programming language like Java, goLang, Python and/or NodeJS/TypeScript and also knowledge in any scripting languages
  • 5+ years of hands-on experience working with developers in building a software assurance model
  • Demonstrate the ability to manually fix/mitigate security flaws on web applications and APIs code-level
  • Experience designing secure web services, APIs and microservice architectures
  • Familiarity with threat modeling frameworks in cloud-base environments (OWASP, STRIDE, MITRE, etc)
  • Familiarity with OWASP verification guidelines (ASVS), OWASP Top 10s (web, API, LLM) and NIST special publications
  • Experience with application/development security tools, including but not limited to: Burp Suite, Qualys/WAS (Tenable or similar), Apiiro (Wiz, GHAS, or similar), Github (Gitlab, Bitbucket or similar), ECS/EKS, Github Actions, etc
  • Familiarity with the implementation and maintenance of SAST/DAST/IAST/SCA security sensors in a development pipeline
  • In-depth knowledge of OWASP10, SANS25 and other world-known application security frameworks
  • Understanding of a complete SDLC and how to make it secured (S-SDLC)
  • Familiarity with Cloud platforms (AWS preferably)
  • Ability to lead people to problem resolution when it comes to Security (Integrate teams, especially the Engineering Team)
  • Experience on how to secure LLMs and generative AI applications

Will be considered a plus:

  • Certified in any related security development certifications like CSSLP, CASE or others
  • Exposure to PCI-DSS, ISO27001 and/or SOC2 framework or any other relevant security standard will be valued
  • Extensive knowledge of security architectures, both monoliths and microservices, including how they are developed and operate at scale
  • Have had developed a personal or enterprise software/script with focus on security (exploitation of vulnerabilities, hardening automation, API integration for security

Apply tot his job Apply To this Job

Related roles

J.P. Morgan Wealth Management – Private Client Advisor - Apple Valley, CA (area)

Remote · USA Full-time

Application Architect - Quality Engineering job at Computer Task Group - CTG in US National

Remote · USA Full-time

Enterprise Architect - Application & Cloud

Remote · USA Full-time

Senior Application Security Engineer [Remote]

Remote · USA Full-time

[Remote] Certified Residential Appraiser (Remote)

Remote · USA Full-time

Penetration Tester

Remote · USA Full-time

Continuous Opening: Senior Application Security Pentester REMOTE

Remote · USA Full-time

Data Architecture Consultant

Remote · USA Full-time

Class Action & Arbitration Attorney | Remote

Remote · USA Full-time

Arbitration & Mediation Case Filing Specialist

Remote · USA Full-time

Associate, Finance and Strategy - Product, Insurance Tech

Remote · USA Full-time

Meat/Produce Team Associate

Remote · USA Full-time

Experienced Entry Level Remote Chat Support Specialist – Digital Marketing Campaigns

Remote · USA Full-time

Customer Service Specialist - Financial Services Expert at arenaflex

Remote · USA Full-time

Part-time Remote Customer Service Representative – Deliver Exceptional Customer Experiences with arenaflex

Remote · USA Full-time

Data Visualization Consultant

Remote · USA Full-time

Store Manager in National City, CA

Remote · USA Full-time

Experienced Virtual Data Entry and Research Associate – Remote Work Opportunity for Motivated Individuals

Remote · USA Full-time

Join Today: Immediately Need Behavior Technician- Work With Kids

Remote · USA Full-time

Experienced Customer Support Representative – Remote (11 AM – 8 PM EST) at arenaflex

Remote · USA Full-time