Responsibilities
- Support application security work: threat modelling sessions, secure code review, API security testing, and CI/CD pipeline checks
- Help review and monitor AI/agentic workflows for prompt risks, unsafe automated actions, and data exposure
- Build and maintain SIEM detection rules, alert pipelines, and response playbooks (Datadog SIEM, CrowdStrike, Cloudflare), owning detection coverage for a defined set of systems end-to-end
- Support incident response: triage alerts, execute IR playbooks, and help run tabletop exercises
- Conduct cloud security assessments across AWS and Kubernetes environments under the guidance of senior team members
- Execute vendor security assessments using the established due diligence framework, owning the review process for a portion of the vendor pipeline
Requirements
- 2–4 years in information security or a closely related technical role (security operations, cloud/infra engineering with a security focus, or similar)
- 2+ years at a regulated fintech/bank/payment company
- Working experience with at least one cloud environment (AWS preferred) and familiarity with Kubernetes fundamentals
- Basic familiarity with application security concepts: threat modelling, secure code review, or API security testing
- Exposure to SIEM platforms and an interest in detection engineering – you've written or tuned at least a few detection rules
- Strong written and verbal communication in English
Nice to Have
- Curiosity about AI/agentic tooling risks (LLM integrations, MCP servers, automated workflows) – prior hands-on experience is a plus, not required
Benefits
- Competitive salary and benefits
- Stock options, so you own part of what you build
- Discretionary performance bonus
- The latest tools and technology
- A world-class team that will challenge and grow your skills
- The opportunity to help build the best fintech app in Latin America
- Office Policy: 3-4 days a week in-office
Work Arrangement
On-site — Brazil
Additional Information
- Office Policy: 3-4 days a week in-office