
Application Security Engineer
4 semanas atrás
We are seeking an experienced Application Security Engineer to serve as a trusted partner to our software development teams. This role focuses on making our product secure by design—embedding security into how software is architected, written, deployed, and maintained. Unlike infrastructure security roles, this position centers on application-layer and code-level security, working closely with developers to enable fast, confident delivery by providing meaningful, actionable security tooling and feedback. This includes leveraging modern AI-assisted techniques to accelerate vulnerability analysis, exploit chaining, and demonstration of actual risk. You will ensure engineering teams move faster—not slower—while minimizing noise. This role is part of the IT & Security team and prioritizes embedding guardrails into developer workflows rather than enforcement gates.
About Nerdy: At Nerdy (NYSE: NRDY) - the company behind Varsity Tutors - we are redrawing the blueprint of learning. Our Live + AI platform fuses real-time human expertise with proprietary generative-AI systems, setting a new bar for measurable academic impact at global scale. We recruit technologists and operators who turn ambiguous problems into shipping code, iterate quickly, and use data to improve outcomes.
About the Company Values- AI-Native at every level From the CEO to day-one hires, everyone builds and ships with generative AI.
- Entrepreneurial velocity Move at founder speed and measure in real user outcomes.
- Full-stack ownership You design, build, and run what you ship; accountability is a feature.
- Reward for contribution Outstanding results are recognized and rewarded.
- Relentless exploration Push the frontier of generative AI in live learning.
Required:
- Experience as an Application Security Engineer, Security Consultant, or security-focused Software Engineer.
- Strong understanding of secure coding practices and common vulnerability patterns.
- Ability to apply common web application attack techniques and create proof-of-concept exploits to validate vulnerabilities.
- Proven ability to analyze exploit chains and demonstrate actual risk, leveraging AI to accelerate discovery and validation.
- Hands-on experience integrating security tooling into CI/CD pipelines.
- Familiarity with Ruby, Go, JavaScript/React, and related frameworks.
- Deep familiarity with OWASP guidance (Top 10, ASVS, Secure Coding Guidelines).
- Partner with DevOps to embed application security into CI/CD pipeline design and practices.
- Ability to assess and communicate application risk in architectural and business context.
- Comfortable demonstrating real-world exploits to technical and non-technical stakeholders.
- Excellent written and verbal communication skills in an async-first, remote environment.
- Preferred:
- Experience leveraging open-source tools and frameworks for application security testing and validation.
- Experience with API security testing and continuous monitoring, using AI for fuzzing and automated discovery.
- Experience building or maintaining secure development training programs.
- Security certifications (OSWE, OSCP, GIAC) are a plus but not required.
- Enable engineering teams to move quickly while embedding security into development workflows—security and speed go hand-in-hand.
- Partner with engineering on secure use of AI services, evaluating controls such as AI gateways, prompt inspection, and policy enforcement.
- Identify, prioritize, and implement security tooling in developer environments and CI/CD pipelines, with AI-assisted triage to reduce noise and highlight exploitable risks.
- Collaborate with developers to identify vulnerabilities in code, APIs, and dependencies; improve secure coding awareness; and participate in design reviews and threat modeling.
- Demonstrate practical exploit techniques to raise security awareness and drive remediation, including chaining multiple weaknesses across services to illustrate end-to-end risk.
- Analyze vulnerabilities across code, dependencies, APIs, and logic, with AI-assisted techniques to identify and prioritize exploit chains.
- Build or adapt automation scripts and tools for continuous security validation, using AI copilots to accelerate script generation and validation.
- Provide coaching, documentation, and embedded training to help developers understand and apply security guidance within their workflows.
- Continuously evaluate emerging AI and application security threats and detection techniques.
- Lead incident response activities as part of the incident commander rotation.
- Drive continuous improvement of incident response runbooks and playbooks.
Join our worldwide team—work from home, get great pay, and help shape the future of learning. Here's what you get:
- Competitive USD Compensation: Market-leading rate paid in U.S. dollars.
- 100% Remote (Home Country Only): Work from anywhere in your home country.
- Flexible Time Off: Flexible PTO to recharge when you need it.
- Local Holiday Pay: Paid holidays in your nation.
- Continuous Learning: Free learning membership for you and your household.
- Supercharge with AI: Access to AI tools to boost productivity.
- Feedback-Rich, Collaborative Culture: Regular training and peer reviews.
- Make a Global Impact: Work on a platform used by learners worldwide.
The Bottom Line: If you're driven by impact, ownership, and shaping what's next, you'll thrive here. We move fast, think big, and reward those who deliver.
Seniority level: Mid-Senior level
Employment type: Contract
Job function: Information Technology
Industries: Technology, Information and Internet
Referrals increase your chances of interviewing at Varsity Tutors, a Nerdy Company by 2x
#J-18808-Ljbffr-
Senior Application Security Engineer
4 semanas atrás
São Paulo, São Paulo, Brasil Agoda Tempo inteiroSenior Application Security Engineer (Bangkok based, relocation provided)Join to apply for the Senior Application Security Engineer (Bangkok based, relocation provided) role at AgodaSenior Application Security Engineer (Bangkok based, relocation provided)1 week ago Be among the first 25 applicantsJoin to apply for the Senior Application Security Engineer...
-
Application Security Engineer
3 semanas atrás
São Paulo, São Paulo, Brasil Awin Global Tempo inteiroOverview Purpose of Position Your role is to establish and lead an AppSec program within the Product and Technology department, acting as an evangelist for AppSec, trusted by engineers and managers alike. As a member of the core security team, you will engage in assessing application design proposals, to identify improvements to enable our engineers to...
-
Application Security Engineer
1 semana atrás
São Paulo, São Paulo, Brasil Monks Tempo inteiro R$120.000 - R$240.000 por anoPlease note that we will never request payment or bank account information at any stage of the recruitment process. As we continue to grow our teams, we urge you to be cautious of fraudulent job postings or recruitment activities that misuse our company name and information. Please protect your personal information during any recruitment process. While Monks...
-
Senior Application Security Engineer
3 semanas atrás
São Paulo, São Paulo, Brasil Rain Tempo inteiroOverview Join to apply for the Senior Application Security Engineer role at Rain . Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. We have raised nearly $400M in funding—including the largest Series A in fintech history—and just closed our Series B...
-
Senior Application Security Engineer
3 semanas atrás
São Paulo, São Paulo, Brasil Rain Tempo inteiroOverview Join to apply for the Senior Application Security Engineer role at Rain Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. We\'ve raised nearly $400M in funding—including the largest Series A in fintech history—and just closed our Series B...
-
Senior Application Security Engineer
3 semanas atrás
São Paulo, São Paulo, Brasil Rain Tempo inteiro3 weeks ago Be among the first 25 applicants Get AI-powered advice on this job and more exclusive features. Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. We've raised nearly $400M in funding—including the largest Series A in fintech history—and just...
-
Senior Application Security Engineer
3 semanas atrás
São Carlos, São Paulo, Brasil Rain Tempo inteiroOverview Join to apply for the Senior Application Security Engineer role at Rain Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. We've raised nearly $400M in funding—including the largest Series A in fintech history—and just closed our Series B to...
-
Senior/Staff Application Security Engineer
4 semanas atrás
São Paulo, São Paulo, Brasil Agoda Tempo inteiroOverview Senior/Staff Application Security Engineer (Bangkok based, relocation provided) role at Agoda. Agoda is an online travel booking platform for accommodations, flights, and more. We build and deploy cutting-edge technology that connects travelers with a global network of hotels, flights, activities, and more. Based in Asia and part of Booking...
-
Security Engineer
4 semanas atrás
São Paulo, São Paulo, Brasil CloudWalk, Inc. Tempo inteiroOverview Join to apply for the Security Engineer role at CloudWalk, Inc. Get AI-powered advice on this job and more exclusive features. About CloudWalk We are not just another fintech unicorn. We are a pack of dreamers, makers, and tech enthusiasts building the future of payments. With millions of happy customers and a hunger for innovation, we're now...
-
Principal Offensive Security Engineer
Há 3 dias
São Paulo, São Paulo, Brasil Questrade Financial Group Tempo inteiro R$90.000 - R$120.000 por anoCompany DescriptionQuestrade is an award-winning low-cost digital alternative to traditional banks that is transforming the Canadian financial services industry. We empower Canadians with innovative products and cutting-edge technology, offering easier ways to invest in securities and foreign currency. Our diverse and collaborative team is committed to...