
Application Security Engineer
Há 2 dias
We are seeking an experienced Application Security Engineer to serve as a trusted partner to our software development teams. This role focuses on making our product secure by design—embedding security into how software is architected, written, deployed, and maintained. Unlike infrastructure security roles, this position centers on application-layer and code-level security, working closely with developers to enable fast, confident delivery by providing meaningful, actionable security tooling and feedback. This includes leveraging modern AI-assisted techniques to accelerate vulnerability analysis, exploit chaining, and demonstration of actual risk. You will ensure engineering teams move faster—not slower—while minimizing noise. This role is part of the IT & Security team and prioritizes embedding guardrails into developer workflows rather than enforcement gates.
About NerdyAt Nerdy (NYSE: NRDY) - the company behind Varsity Tutors - we're redrawing the blueprint of learning. Our Live + AI platform fuses real-time human expertise with proprietary generative-AI systems, setting a new bar for measurable academic impact at global scale. We recruit the kind of technologists and operators you'd bet on as solo founders - people who turn ambiguous problems into shipping code, iterate faster than markets move, and compound their advantage with every data point. In an era where great employees can deliver 10-times the leverage of the merely good, we back those who play to win.
How we compete- AI-Native at every level From the CEO to day-one hires, everyone builds and ships with generative AI. If you're not wielding AI, you're not done.
- Entrepreneurial velocity Move at founder speed, prototype in hours, and measure in real user outcomes. Slow teams die.
- Free-market rigor Ideas rise or fall on merit and results - no committees, no politics, no cap on upside.
- Full-stack ownership You design, build, and run what you ship; accountability is a feature, not a bug.
- Reward for contribution Pay rises with impact, not years. Outstanding results earn outsized rewards. We evaluate both what you achieve and how you achieve it: living our leadership principles and using AI effectively are formally measured and rewarded.
- Relentless exploration Push the frontier of generative AI in live learning and - because only the paranoid survive - questioning every legacy assumption along the way.
- Is Apolitical You stay focused on mission-aligned outcomes, not distractions or unrelated causes.
Required:
- Experience as an Application Security Engineer, Security Consultant, or Security-focused Software Engineer.
- Strong understanding of secure coding practices and common vulnerability patterns.
- Ability to apply common web application attack techniques and create proof-of-concept exploits to validate whether vulnerabilities are exploitable in our environment.
- Proven ability to analyze exploit chains and demonstrate actual risk, leveraging AI to accelerate discovery and validation.
- Hands-on experience integrating security tooling into CI/CD pipelines.
- Familiarity with Ruby, Go, JavaScript/React, and related frameworks.
- Deep familiarity with OWASP guidance, including the OWASP Top 10, Application Security Verification Standard (ASVS), and Secure Coding Guidelines.
- Partner with DevOps to embed application security into CI/CD pipeline design and practices.
- Ability to assess and communicate application risk in architectural and business context.
- Comfortable demonstrating real-world exploits to technical and non-technical stakeholders.
- Excellent written and verbal communication skills in an async-first, remote environment.
Preferred:
- Experience leveraging and adapting open-source tools and frameworks for application security testing and validation.
- Experience with API security testing and continuous monitoring, leveraging AI for fuzzing, intelligent input generation, and automated discovery.
- Experience building or maintaining secure development training programs.
- Security certifications (OSWE, OSCP, GIAC) are a plus but not required.
- Enable engineering teams to move quickly while embedding security into development workflows—security and speed go hand-in-hand.
- Partner with engineering on secure use of AI services, evaluating controls such as AI gateways, prompt inspection, and policy enforcement.
- Identify, prioritize, and implement security tooling in developer environments and CI/CD pipelines, with AI-assisted triage to reduce noise and highlight exploitable risks.
- Collaborate with developers to identify vulnerabilities in code, APIs, and dependencies; improve secure coding awareness; and participate in design reviews and threat modeling.
- Demonstrate practical exploit techniques to raise security awareness and drive remediation, including chaining multiple weaknesses across services to illustrate end-to-end risk.
- Analyze vulnerabilities across code, dependencies, APIs, and logic, with AI-assisted techniques to identify and prioritize exploit chains.
- Build or adapt automation scripts and tools for continuous security validation, using AI copilots to accelerate script generation and validation.
- Provide coaching, documentation, and embedded training to help developers understand and apply security guidance within their workflows.
- Continuously evaluate emerging AI and application security threats and detection techniques.
- Lead incident response activities as part of the incident commander rotation.
- Drive continuous improvement of incident response runbooks and playbooks.
Join our worldwide team—work from home, get great pay, and help shape the future of learning. Here's what you get:
- Competitive USD Compensation: Enjoy a market-leading rate paid in U.S. dollars.
- 100% Remote (Home Country Only): Work from anywhere in your home country—no relocation required, no borders crossed.
- Flexible Time Off: Our flexible PTO lets you recharge on your own terms and when you need it the most.
- Local Holiday Pay: We honor your nation's official holidays with paid time off—celebrate what matters to you.
- Continuous Learning: Get a free, all-inclusive learning membership for you and your household—including 1-on-1 tutoring hours, unlimited on-demand classes, and access to our full suite of learning products and services.
- Supercharge with AI: Gain exclusive access to cutting-edge AI tools that boost your productivity, making you feel almost super-human (cape not included).
- Feedback-Rich, Collaborative Culture: Tap into regular training, peer reviews, and a team that treats every team member as a vital collaborator and owner in our success.
- Make a Global Impact: Your expertise fuels an innovative platform used by learners around the world—be part of something transformative.
If you're driven by impact, energized by ownership, and excited to help shape what's next, you'll thrive here. We move fast, think big, and reward those who deliver. This isn't a traditional corporate environment - it's a place to do the most meaningful work of your career.
Seniority level- Mid-Senior level
- Contract
- Information Technology
- Technology, Information and Internet
-
Security Engineer
Há 4 dias
Itapecerica da Serra, São Paulo, Brasil Varsity Tutors, A Nerdy Company Tempo inteiroSecurity Engineer - Detection & ResponseJoin to apply for the Security Engineer - Detection & Response role at Varsity Tutors, a Nerdy CompanySecurity Engineer - Detection & Response4 days ago Be among the first 25 applicantsJoin to apply for the Security Engineer - Detection & Response role at Varsity Tutors, a Nerdy CompanyGet AI-powered advice on this job...
-
Security Engineer
Há 9 horas
Itapecerica da Serra, São Paulo, Brasil Varsity Tutors, a Nerdy Company Tempo inteiroSecurity Engineer - Detection & Response Join to apply for the Security Engineer - Detection & Response role at Varsity Tutors, a Nerdy Company Security Engineer - Detection & Response 4 days ago Be among the first 25 applicants Join to apply for the Security Engineer - Detection & Response role at Varsity Tutors, a Nerdy Company Get AI-powered advice on...
-
Chief Cybersecurity Architect
Há 2 dias
Itapecerica da Serra, São Paulo, Brasil beBeeApplication Tempo inteiro US$90.000 - US$110.000Job OverviewWe are seeking an experienced cybersecurity professional to partner with our software development teams. This role focuses on making our product secure by design, embedding security into how software is architected, written, deployed, and maintained.This is a unique opportunity to work on high-impact projects and collaborate with talented...
-
QA Associate Manager
4 semanas atrás
Itapecerica da Serra, São Paulo, Brasil Trustly Tempo inteiro**WHO WE ARE**- Founded in 2008, Trustly is the global leader in Open Banking Payments, and the U.S. is Trustly's fastest-growing market. Today we serve 10,000 merchants, connecting them with over 650 million consumers and 7,600 banks in over 30 countries. In 2021, we processed over $20 billion in transaction volume in our global network.Our digital...
-
Operations Manager
Há 4 dias
Itapecerica da Serra, São Paulo, Brasil Sbm Offshore Tempo inteiro**Req Id**:9883**Job Family**:Operations - Onshore Operations**Location**:Vitória, BR, **Energy is a fundamental basic need of our society.Fossil fuels, including oil, are an essential source of energy and will remain so until renewable energies have the capacity to meet the growing demand for energy.****Nearly 5,000 SBMers globally are proud to design,...
-
AR Clerk
Há 3 dias
Itapecerica da Serra, São Paulo, Brasil Gates Corporation Tempo inteiroOverview Join to apply for the AR Clerk role at Gates Corporation . Are you inspired by challenging the status quo? Do you thrive in collaborative environments that drive results? If so, Gates could be for you. Gates is a leading manufacturer of application-specific fluid power and power transmission solutions. We push the boundaries of material science...
-
Cyber Security Specialist
Há 3 dias
Serra, Brasil Hydro Tempo inteiroHydro is a fully integrated aluminium company with 34,000 employees in 40 countries on all continents, combining local expertise, worldwide reach and unmatched capabilities in R&D. In addition to production of primary aluminium, rolled and extruded products and recycling, Hydro also extracts bauxite, refines alumina and generates energy to be the only 360°...
-
Senior Security Engineer
2 semanas atrás
São José da Laje, Brasil Redis Tempo inteiro US$80.000 - US$150.000 por anoWho we areWe're Redis. We built the product that runs the fast apps our world runs on. (If you checked the weather, used your credit card, or looked at your flight status online today, you're welcome.) At Redis, you'll work with the fastest, simplest technology in the business—whether you're building it, telling its story, or selling it to our 10,000+...
-
Full Stack Product Engineer Senior
Há 20 horas
Serra, Espírito Santo, Brasil Staffed Tempo inteiroJoin to apply for the Full Stack Product Engineer Senior role at Staffed.We are looking for a Senior Fullstack Engineer with expertise in React (frontend) and Python (backend) to build scalable applications in multi-cloud or flexible architectures.ResponsibilitiesDevelop and maintain fullstack applications (React + Python).Implement data ingestion and...
-
Quality Assurance Engineer II, INTech LATAM
2 semanas atrás
Vargem Grande da Serra, Brasil Amazon Tempo inteiroQuality Assurance Engineer II, INTech LATAM Join to apply for the Quality Assurance Engineer II, INTech LATAM role at Amazon Quality Assurance Engineer II, INTech LATAM Join to apply for the Quality Assurance Engineer II, INTech LATAM role at Amazon Get AI-powered advice on this job and more exclusive features. DescriptionThe Amazon International...
-
Senior Non-Destructive Testing Engineer
Há 3 dias
Vitória da Conquista, Bahia, Brasil Aramco Tempo inteiroSenior Non-Destructive Testing Engineer - Relocate to Saudi Arabia, Permanent Expat Relocation PackageJoin to apply for the Senior Non-Destructive Testing Engineer - Relocate to Saudi Arabia, Permanent Expat Relocation Package role at aramcoSenior Non-Destructive Testing Engineer - Relocate to Saudi Arabia, Permanent Expat Relocation Package3 weeks ago Be...
-
Infrastructure Architect
Há 7 dias
Serra, Brasil Top Technologies Tempo inteiroAn Infrastructure Architect with experience in leading and implementing cloud, IaaS, and SaaS architectures for our SAP Migration customers with a focus on Security and Infrastructure best practices. This position requires someone with strong business acumen along with technical depth to assist with architecture, implementation, and domain migrations for...
-
Senior Non-Destructive Testing Engineer
Há 5 dias
Vitória da Conquista, Bahia, Brasil aramco Tempo inteiroSenior Non-Destructive Testing Engineer - Relocate to Saudi Arabia, Permanent Expat Relocation PackageJoin to apply for the Senior Non-Destructive Testing Engineer - Relocate to Saudi Arabia, Permanent Expat Relocation Package role at aramco Senior Non-Destructive Testing Engineer - Relocate to Saudi Arabia, Permanent Expat Relocation Package3 weeks ago Be...
-
Senior Non-Destructive Testing Engineer
Há 8 horas
Vitória da Conquista, Bahia, Brasil aramco Tempo inteiroSenior Non-Destructive Testing Engineer - Relocate to Saudi Arabia, Permanent Expat Relocation Package Join to apply for the Senior Non-Destructive Testing Engineer - Relocate to Saudi Arabia, Permanent Expat Relocation Package role at aramco Senior Non-Destructive Testing Engineer - Relocate to Saudi Arabia, Permanent Expat Relocation Package 3 weeks ago...
-
Infrastructure Automation Specialist
Há 4 dias
Vitória da Conquista, Bahia, Brasil beBeeAutomation Tempo inteiro R$600.000 - R$1.000.000Job TitleAs a seasoned Infrastructure Automation Specialist, you will be instrumental in empowering our development teams to build solutions with stability and performance.The team acts as a protector of production, always making sure that everything is working as it should with self-healing, observability, and automation whenever possible.Key...
-
Senior Full Stack Software Engineer
2 semanas atrás
São José da Laje, Brasil Polygon Labs Tempo inteiro US$120.000 - US$200.000 por anoAbout Polygon LabsPolygon Labs is a software development company building and developing a network of aggregated blockchains via the Agglayer, secured by Ethereum. As public infrastructure, the Agglayer will bring together user bases and liquidity for any connected chain, and leverage Ethereum as a settlement layer. Polygon Labs has also contributed to the...