Staff Application Security Engineer

Há 21 horas


Barretos, Brasil LEDN Tempo inteiro

Ledn is a global financial services company built for digital assets, helping to improve the everyday lives of Bitcoin holders while building generational wealth for the future. Responsibilities Lead secure design and code reviews across engineering teams. Define and enforce secure coding practices for JavaScript/TypeScript services. Automate vulnerability detection (SAST, SCA, DAST) within CI/CD. Conduct threat modeling and risk assessments for new features. Partner with engineers to remediate vulnerabilities and improve secure development practices. Own the roadmap for authentication and identity across customer and internal applications. Enhance existing Cognito-based identity architecture with stronger, phishing‑resistant MFA solutions (e.g., WebAuthn, passkeys, hardware tokens). Define secure approaches to session management, device trust, and account recovery. Design enclave‑based architectures to isolate and protect sensitive workloads. Integrate Nitro Enclaves with KMS and secure APIs. Migrate high‑value operations (e.g., cryptographic and financial processes) into enclave environments. Ensure compliance, auditability, and resilience of enclave workloads. Harden AWS services (Lambda, API Gateway, SQS, SNS) with least‑privilege IAM and secure key management. Improve Kubernetes security posture (RBAC, pod security, image scanning, runtime monitoring). Deploy and operate a SIEM framework; develop detection rules, dashboards, and incident playbooks. Support compliance initiatives (SOC 2, ISO 27001) with security controls and documentation. Qualifications 10+ years of proven experience in Application Security, with a focus on web and cloud‑native applications. Strong knowledge of JavaScript/TypeScript/Golang/Python and modern web vulnerabilities (OWASP Top 10, auth bypasses, business logic flaws). Expertise with AWS security best practices, particularly in serverless architectures. Hands‑on experience with AWS Nitro Enclaves for confidential computing. Deep understanding of authentication and authorization standards (OAuth2, OIDC, WebAuthn, FIDO2). Practical experience with Cognito / Auth0 (MFA, custom flows, secure session handling). Background in SIEM design and log correlation across cloud and application layers. Familiarity with Kubernetes security (RBAC, pod security, admission controls, image scanning). Experience with Secure Code Review. Understanding of software supply chain and Linux internals. Strong communication and collaboration skills, able to influence engineering and product teams. Remote experience is required. Nice to Haves Familiarity with Bitcoin custody and key management practices. Knowledge of Infrastructure as Code security (Terraform, AWS CDK). Prior work on user‑facing security features such as passwordless authentication, recovery flows, or device trust. Culture Fit Adapts to an ambiguous, high‑growth, fast‑paced environment. Has a builder's mindset, excited to create, iterate, and scale IS practices. Collaborates across functions and cultures with empathy and clarity. Demonstrates integrity and accountability, especially in managing confidential information across diverse legal and cultural contexts. Has remote work experience. Benefits Competitive PTO package. Ownership and shared equity opportunities. Remote work available up to 180 days worldwide (with restrictions). Comprehensive, best‑in‑class total rewards package starting on day one. Opportunity to work in a remote‑first environment spanning North America, Latin America, South Africa, and Europe. Equal Opportunity We are an equal opportunity employment organization and pride ourselves on inclusivity, diversity, and the success that comes from diversity. We provide accommodation requests throughout all stages of the recruitment process and will address them confidentially. #J-18808-Ljbffr



  • Barretos, Brasil Bebeesoftware Tempo inteiro

    Transforming legacy systems into an AI-driven future requires a skilled professional.In this role, you will play a foundational part in building the core platform for power utilities to shift from outdated technology.We seek a senior software engineer with 5+ years of experience in software development.Proficiency in React.js and either Golang, Node.js, or...


  • Barretos, Brasil Bebeedevops Tempo inteiro

    We are seeking an experienced DevOps Engineer to manage cloud infrastructure and lead migrations.Key Responsibilities:Design, build, and maintain cloud-based infrastructure across AWS and other providers.Lead migrations from EC2 to Kubernetes-native environments.SUPPORT LARGE-SCALE LIVE AND PRODUCT EVENTS WITH RELIABLE, SCALABLE DEVOPS PRACTICES.Implement...


  • Barretos, Brasil Bebeeautomacao Tempo inteiro

    Buscamos um especialista em automação para realizar planejamentos avançados.Requisitos:Graduação em tecnologia da informação;Experiência com Ansible, GitHub Actions, Jenkins, Python, Jinja2, Groovy, PowerShell, Bash e outras ferramentas de automação.Certificações em Red Hat Certified Specialist in Ansible Automation ou Red Hat Certified Engineer...


  • Barretos, Brasil Bebeebackend Tempo inteiro

    We're looking for a skilled Fullstack Developer to join our team.As a Staff Engineer, you will play a key role in the design, implementation, and deployment of our product.You will be responsible for building and maintaining backend systems and applications while collaborating closely with cross-functional teams.We practice engineering best practices like...

  • Ios Developer

    1 semana atrás


    Barretos, Brasil Flatiron Software Tempo inteiro

    AboutFlatiron is a global remote software development company with engineers located around the world.We unite experts from diverse backgrounds and experiences in a collaborative culture to deliver exceptional products and services for our clients.As a forward-thinking software engineering company, we provide industry-leading solutions to complex problems in...