FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Security Engineer – DevSecOps, AppSec
Saipos | Sistema para Restaurante. Implement and maintain SAST, DAST, and SCA tools in the CI/CD pipeline (Bitbucket/GitHub/GitLab) .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in implementing and maintaining security tools within CI/CD pipelines, with a strong focus on AWS security best practices and infrastructure as code using Terraform. Capable of conducting security reviews, threat modeling, and leading security initiatives across development teams.
Highest-signal resume keywords
CI/CD Pipeline Security IntegrationAWS Security Best PracticesInfrastructure as Code (Terraform)Security Code ReviewSecrets Management (HashiCorp Vault, AWS Secrets Manager)
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
SASTDASTSCATerraformPythonBashAWS IAMAWS LambdaOWASP Top 10Docker Security
Soft Skills
Critical ThinkingProactivityInterpersonal CommunicationCollaborationOwnership
Tools & Technologies
BitbucketGitHubGitLabOWASP ZAPBurp SuiteAWS Security HubGuardDutyWizPrisma CloudHashiCorp Vault
Certifications & Qualifications
AWS Certified Solutions Architect – AssociateAWS Certified Solutions Architect – ProfessionalAWS Certified Security – SpecialtyCertified DevSecOps Professional (CDP)HashiCorp Vault Associate
Industry Keywords
Cloud SecuritySecurity Champions ProgramThreat ModelingAPI SecurityCIS Benchmarks
Tech Stack
Tools & technologiesAWSCloudDockerPythonSDLCTerraformVault
About the role
Key responsibilities & impact- Implement and maintain SAST, DAST, and SCA tools in the CI/CD pipeline (Bitbucket/GitHub/GitLab)
- Implement, maintain, operate, and enhance Secrets Manager and Vault
- Perform continuous secret scanning across repositories and lead remediation of findings with development teams
- Conduct security-focused code reviews for critical features, including authentication, authorization, external integrations, and sensitive data handling
- Harden infrastructure, including Terraform state, IAM policies, AWS configurations, and Security Groups
- Support the remediation of technical findings identified by security analysis tools, external penetration tests, and internal scans
- Build and lead the Security Champions program by identifying points of contact within development squads and structuring ongoing training
- Conduct threat modeling for new features and critical integrations in partnership with product and engineering teams
- Define and document security requirements throughout the SDLC, from design through deployment
- Assess the security of internal and external APIs, partner integrations, and authentication flows
Requirements
What you’ll need- Hands-on experience with CI/CD pipelines and integrating security tools (SAST, SCA, and secret scanning) into the development workflow.
- Solid knowledge of AWS, including IAM, S3, Lambda, Security Groups, VPC, KMS, and cloud security best practices.
- Experience with infrastructure as code (Terraform), including the ability to identify and remediate security issues in IaC.
- Knowledge of the OWASP Top 10 and OWASP API Security Top 10, with the ability to apply them to code and architecture reviews.
- Ability to write scripts and automations for analysis and remediation using Python or Bash.
- Ability to read and interpret code in at least one programming language used by the product.
- Critical thinking and risk analysis.
- Proactivity, initiative, and the ability to anticipate needs.
- Strong interpersonal communication skills when working with development teams.
- Technical independence.
- Collaboration and teamwork.
- Ability to explain concepts clearly and transfer knowledge.
- Strong ownership and results orientation.
- Experience with Bitbucket (a plus).
- Practical experience managing secrets with HashiCorp Vault and/or AWS Secrets Manager (a plus).
- Familiarity with DAST tools (OWASP ZAP, Burp Suite) integrated into pipelines (a plus).
- Knowledge of security for Docker containers and image repositories (a plus).
- Experience applying CIS Benchmarks to AWS workloads (a plus).
- Basic knowledge of mobile security or binary analysis (a plus).
- Familiarity with cloud posture management tools (Wiz, Prisma Cloud, AWS Security Hub, GuardDuty) (a plus).
- Experience conducting security reviews of serverless architectures (Lambda, API Gateway) (a plus).
- Preferred certifications: AWS Certified Solutions Architect – Associate; AWS Certified Solutions Architect – Professional; AWS Certified Security – Specialty; Certified DevSecOps Professional (CDP) – Practical DevSecOps; HashiCorp Vault Associate.
Benefits
Comp & perks- Contractor arrangement (PJ) with 30 days of paid time off
- Health and dental insurance with premiums 100% covered by Saipos (copayments apply to consultations and exams)
- Life insurance
- Birthday month day off
- Wellhub
- Complete equipment package
- Daily transportation allowance of BRL 22 for on-site work
- Home office allowance of BRL 180.00 for professionals working remotely at least three days per week
- Extended maternity and paternity leave