Application Security Engineer

1 semana atrás


Florianópolis, Santa Catarina, Brasil Varsity Tutors, a Nerdy Company Tempo inteiro
Overview

We are seeking an experienced Application Security Engineer to serve as a trusted partner to our software development teams. This role focuses on making our product secure by design—embedding security into how software is architected, written, deployed, and maintained. Unlike infrastructure security roles, this position centers on application-layer and code-level security, working closely with developers to enable fast, confident delivery by providing meaningful, actionable security tooling and feedback. This includes leveraging modern AI-assisted techniques to accelerate vulnerability analysis, exploit chaining, and demonstration of actual risk. You will ensure engineering teams move faster—not slower—while minimizing noise. This role is part of the IT & Security team and prioritizes embedding guardrails into developer workflows rather than enforcement gates.

About Nerdy: At Nerdy (NYSE: NRDY) - the company behind Varsity Tutors - we fuse real-time human expertise with proprietary generative-AI systems to measurably impact learning at global scale, and we back technologists who ship quickly and think strategically.

Responsibilities
  • Enable engineering teams to move quickly while embedding security into development workflows—security and speed go hand-in-hand.
  • Partner with engineering on secure use of AI services, evaluating controls such as AI gateways, prompt inspection, and policy enforcement.
  • Identify, prioritize, and implement security tooling in developer environments and CI/CD pipelines, with AI-assisted triage to reduce noise and highlight exploitable risks.
  • Collaborate with developers to identify vulnerabilities in code, APIs, and dependencies; improve secure coding awareness; and participate in design reviews and threat modeling.
  • Demonstrate practical exploit techniques to raise security awareness and drive remediation, including chaining multiple weaknesses across services to illustrate end-to-end risk.
  • Analyze vulnerabilities across code, dependencies, APIs, and logic, with AI-assisted techniques to identify and prioritize exploit chains.
  • Build or adapt automation scripts and tools for continuous security validation, using AI copilots to accelerate script generation and validation.
  • Provide coaching, documentation, and embedded training to help developers understand and apply security guidance within their workflows.
  • Continuously evaluate emerging AI and application security threats and detection techniques.
  • Lead incident response activities as part of the incident commander rotation and drive continuous improvement of incident response runbooks and playbooks.
Qualifications

Required:

  • Experience as an Application Security Engineer, Security Consultant, or Security-focused Software Engineer.
  • Strong understanding of secure coding practices and common vulnerability patterns.
  • Ability to apply common web application attack techniques and create proof-of-concept exploits to validate whether vulnerabilities are exploitable in our environment.
  • Proven ability to analyze exploit chains and demonstrate actual risk, leveraging AI to accelerate discovery and validation.
  • Hands-on experience integrating security tooling into CI/CD pipelines.
  • Familiarity with Ruby, Go, JavaScript/React, and related frameworks.
  • Deep familiarity with OWASP guidance, including the OWASP Top 10, ASVS, and Secure Coding Guidelines.
  • Partner with DevOps to embed application security into CI/CD pipeline design and practices.
  • Ability to assess and communicate application risk in architectural and business context.
  • Comfortable demonstrating real-world exploits to technical and non-technical stakeholders.
  • Excellent written and verbal communication skills in an async-first, remote environment.

Preferred:

  • Experience leveraging and adapting open-source tools and frameworks for application security testing and validation.
  • Experience with API security testing and continuous monitoring, leveraging AI for fuzzing, intelligent input generation, and automated discovery.
  • Experience building or maintaining secure development training programs.
  • Security certifications (OSWE, OSCP, GIAC) are a plus but not required.
Benefits and Perks
  • Competitive USD Compensation: Market-leading rate paid in U.S. dollars.
  • 100% Remote (Home Country Only): Work from anywhere in your home country—no relocation required.
  • Flexible Time Off: Flexible PTO for personal needs.
  • Local Holiday Pay: Paid time off for official holidays in your country.
  • Continuous Learning: Access to learning memberships and tutoring hours.
  • Supercharge with AI: Exclusive access to AI tools to boost productivity.
  • Feedback-Rich, Collaborative Culture: Regular training and peer reviews in a collaborative environment.
  • Make a Global Impact: Contribute to a platform used by learners worldwide.

The Bottom Line: If you're driven by impact and ownership, you'll thrive here. We move fast, think big, and reward those who deliver in a non-traditional corporate environment.

Seniority level: Mid-Senior level

Employment type: Contract

Job function: Information Technology

Industries: Technology, Information and Internet

#J-18808-Ljbffr

  • Florianópolis, Santa Catarina, Brasil beBeeapplication Tempo inteiro US$140.000 - US$170.000

    Secure Software Development EngineerWe're seeking a skilled Application Security Engineer to partner with our development teams. This role focuses on making our product secure by design, embedding security into how software is architected, written, deployed, and maintained.


  • Florianópolis, Santa Catarina, Brasil Canonical Tempo inteiro

    Join or sign in to find your next job Join to apply for the Ubuntu Security Engineer role at Canonical 1 week ago Be among the first 25 applicants Join to apply for the Ubuntu Security Engineer role at Canonical Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform,...


  • Florianópolis, Santa Catarina, Brasil Canonical Tempo inteiro

    Linux Cryptography and Security EngineerJoin or sign in to find your next job Join to apply for the Linux Cryptography and Security Engineer role at Canonical Linux Cryptography and Security Engineer3 days ago Be among the first 25 applicants Join to apply for the Linux Cryptography and Security Engineer role at Canonical Get AI-powered advice on this...


  • Florianópolis, Santa Catarina, Brasil Canonical Tempo inteiro

    Linux Cryptography and Security EngineerJoin or sign in to find your next jobJoin to apply for the Linux Cryptography and Security Engineer role at CanonicalLinux Cryptography and Security Engineer3 days ago Be among the first 25 applicantsJoin to apply for the Linux Cryptography and Security Engineer role at CanonicalGet AI-powered advice on this job and...


  • Florianópolis, Santa Catarina, Brasil Canonical Tempo inteiro

    Join or sign in to apply for the Security Software Engineer role at Canonical Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform, Ubuntu, is widely used in breakthrough enterprise initiatives such as public cloud, data science, AI, engineering innovation, and IoT. Our...

  • Security Engineer

    1 semana atrás


    Florianópolis, Santa Catarina, Brasil Varsity Tutors, a Nerdy Company Tempo inteiro

    Overview You are an AI-powered Security Engineer responsible for identifying and responding to malicious or suspicious activity across our environment with speed and confidence. This role leads the engineering work behind these capabilities—designing scalable systems to detect threats and trigger automated responses. You will integrate AI into detection...


  • Florianópolis, Santa Catarina, Brasil GE Vernova Tempo inteiro

    Cyber Security Consulting Engineer – Transmission & Distribution SystemsJoin to apply for the Cyber Security Consulting Engineer – Transmission & Distribution Systems role at GE Vernova Continue with Google Continue with Google Cyber Security Consulting Engineer – Transmission & Distribution Systems3 days ago Be among the first 25 applicants Join to...


  • Florianópolis, Santa Catarina, Brasil beBeeInfrastructure Tempo inteiro US$120.000 - US$140.000

    Job DescriptionOur organization is seeking an experienced professional to spearhead the planning and execution of operating system upgrades, ensuring system stability and minimizing disruption. This role requires a strong focus on security, risk evaluation, and compliance.Key ResponsibilitiesOperating System UpgradesDevelop and implement upgrade plans for...


  • Florianópolis, Santa Catarina, Brasil beBeeSoftware Tempo inteiro US$100.000 - US$130.000

    Job OverviewThe Security Engineering Manager is a pivotal role in leading and developing a team of engineers to address emerging threats and ensure the security of millions of users worldwide. This position directly impacts the safety and security of the open-source ecosystem.Key ResponsibilitiesLead and develop a team of engineers, ranging from graduate to...

  • DevOps Engineer ID38563

    2 semanas atrás


    Florianópolis, Santa Catarina, Brasil AgileEngine Tempo inteiro

    Join to apply for the DevOps Engineer ID38563 ($3,000 signing bonus) role at AgileEngine 3 weeks ago Be among the first 25 applicants Join to apply for the DevOps Engineer ID38563 ($3,000 signing bonus) role at AgileEngine Get AI-powered advice on this job and more exclusive features. AgileEngine is an Inc. 5000 company that creates award-winning...