Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Compass

Senior Security Engineering Analyst – AppSec

Compass

. Define and evolve the corporate Secure Software Development Life Cycle (SSDLC) process .

Posted 9/23/2026full-timeRemote • BrazilSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Secure Software Development Life Cycle (SSDLC) and integrates security practices throughout the application lifecycle, including Threat Modeling and Secure Coding. Proficient in assessing and remediating application vulnerabilities while promoting a secure development culture within teams.

Highest-signal resume keywords
Secure Software Development Life Cycle (SSDLC)Threat ModelingApplication Vulnerability ManagementAWS Security HubDevSecOps

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Secure CodingApplication ArchitectureMicroservices ArchitectureAPI SecuritySecurity by DesignOWASP Top 10OWASP ASVSSASTDASTCI/CD
Soft Skills
CollaborationCommunicationProblem-Solving
Tools & Technologies
AWS API GatewayContainer SecuritySBOMIaC ScanningSecret Scanning
Industry Keywords
Cloud SecuritySecurity GatesDevelopment ProcessesSecurity AssessmentsRisk Mitigation

Tech Stack

Tools & technologies
AWSCloudSDLC

About the role

Key responsibilities & impact
  • Define and evolve the corporate Secure Software Development Life Cycle (SSDLC) process
  • Establish minimum security requirements for applications
  • Define and implement Security Gates in development and CI/CD processes
  • Integrate security controls and requirements into the application lifecycle
  • Support the advancement of a secure development culture across the organization
  • Participate in projects from the initial conception and architecture stages
  • Conduct security assessments of proposed solutions and architectures
  • Identify risks and vulnerabilities and propose mitigation measures
  • Apply Threat Modeling and Security by Design practices
  • Work closely with architects, developers, DevOps, and other technical teams
  • Identify, analyze, and remediate application vulnerabilities
  • Support development teams in adopting Secure Coding practices
  • Conduct code reviews from a security perspective
  • Assess APIs, microservices, containers, and software components
  • Address vulnerabilities and risks related to dependencies, code, infrastructure, and configurations
  • Integrate security tools into CI/CD pipelines
  • Work with SAST, DAST, SCA, Secret Scanning, IaC Scanning, and Container Security solutions
  • Support the implementation and management of SBOMs
  • Define criteria and policies for Security Gates
  • Promote automation of security controls throughout pipelines
  • Work in AWS environments, supporting the implementation of secure architectures
  • Assess cloud security configurations and controls
  • Work with resources such as AWS API Gateway and AWS Security Hub
  • Support the identification and remediation of risks related to cloud infrastructure and applications

Requirements

What you’ll need
  • Experience in medium- to large-scale corporate environments
  • Experience working directly with development teams
  • Experience defining or evolving security processes and controls
  • Knowledge of SSDLC — Secure Software Development Life Cycle
  • Knowledge of Security by Design
  • Knowledge of Threat Modeling
  • Knowledge of the OWASP Top 10
  • Knowledge of OWASP ASVS
  • Knowledge of Secure Coding
  • Knowledge of API Security
  • Knowledge of Application Architecture
  • Knowledge of Microservices Architecture
  • Knowledge of DevOps and CI/CD
  • Knowledge of application vulnerability management
  • Experience with SAST, DAST, SCA, Secret Scanning, IaC Scanning, Container Security, SBOM, CI/CD, and DevSecOps
  • Experience with AWS
  • Knowledge of AWS API Gateway
  • Knowledge of AWS Security Hub
  • Knowledge of cloud security and architecture

Benefits

Comp & perks
  • Open to applicants with disabilities (PwD)
  • Remote work