Application Security Engineer

3 semanas atrás


Fortaleza, Ceará, Brasil Varsity Tutors, a Nerdy Company Tempo inteiro
Overview

We are seeking an experienced Application Security Engineer to serve as a trusted partner to our software development teams. This role focuses on making our product secure by design—embedding security into how software is architected, written, deployed, and maintained. Unlike infrastructure security roles, this position centers on application-layer and code-level security, working closely with developers to enable fast, confident delivery by providing meaningful, actionable security tooling and feedback. This includes leveraging modern AI-assisted techniques to accelerate vulnerability analysis, exploit chaining, and demonstration of actual risk. You will ensure engineering teams move faster—not slower—while minimizing noise. This role is part of the IT & Security team and prioritizes embedding guardrails into developer workflows rather than enforcement gates.

About Nerdy – the company behind Varsity Tutors – we built Live + AI platforms that fuse real-time human expertise with proprietary generative-AI systems to deliver measurable academic impact at global scale.

Qualifications

Required:

  • Experience as an Application Security Engineer, Security Consultant, or Security-focused Software Engineer.
  • Strong understanding of secure coding practices and common vulnerability patterns.
  • Ability to apply common web application attack techniques and create proof-of-concept exploits to validate whether vulnerabilities are exploitable in our environment.
  • Proven ability to analyze exploit chains and demonstrate actual risk, leveraging AI to accelerate discovery and validation.
  • Hands-on experience integrating security tooling into CI/CD pipelines.
  • Familiarity with Ruby, Go, JavaScript/React, and related frameworks.
  • Deep familiarity with OWASP guidance, including the OWASP Top 10, ASVS, and Secure Coding Guidelines.
  • Partner with DevOps to embed application security into CI/CD pipeline design and practices.
  • Ability to assess and communicate application risk in architectural and business context.
  • Comfortable demonstrating real-world exploits to technical and non-technical stakeholders.
  • Excellent written and verbal communication skills in an async-first, remote environment.

Preferred:

  • Experience leveraging and adapting open-source tools and frameworks for application security testing and validation.
  • Experience with API security testing and continuous monitoring, leveraging AI for fuzzing, intelligent input generation, and automated discovery.
  • Experience building or maintaining secure development training programs.
  • Security certifications (OSWE, OSCP, GIAC) are a plus but not required.
Responsibilities
  • Enable engineering teams to move quickly while embedding security into development workflows—security and speed go hand-in-hand.
  • Partner with engineering on secure use of AI services, evaluating controls such as AI gateways, prompt inspection, and policy enforcement.
  • Identify, prioritize, and implement security tooling in developer environments and CI/CD pipelines, with AI-assisted triage to reduce noise and highlight exploitable risks.
  • Collaborate with developers to identify vulnerabilities in code, APIs, and dependencies; improve secure coding awareness; and participate in design reviews and threat modeling.
  • Demonstrate practical exploit techniques to raise security awareness and drive remediation, including chaining multiple weaknesses across services to illustrate end-to-end risk.
  • Analyze vulnerabilities across code, dependencies, APIs, and logic, with AI-assisted techniques to identify and prioritize exploit chains.
  • Build or adapt automation scripts and tools for continuous security validation, using AI copilots to accelerate script generation and validation.
  • Provide coaching, documentation, and embedded training to help developers understand and apply security guidance within their workflows.
  • Continuously evaluate emerging AI and application security threats and detection techniques.
  • Lead incident response activities as part of the incident commander rotation.
  • Drive continuous improvement of incident response runbooks and playbooks.
Unlock Your Full Potential at Nerdy

Join our worldwide team—work from home, get great pay, and help shape the future of learning. Here's what you get:

  • Competitive USD Compensation: Enjoy a market-leading rate paid in U.S. dollars.
  • 100% Remote (Home Country Only): Work from anywhere in your home country—no relocation required, no borders crossed.
  • Flexible Time Off: Our flexible PTO lets you recharge on your own terms and when you need it the most.
  • Local Holiday Pay: We honor your nation's official holidays with paid time off—celebrate what matters to you.
  • Continuous Learning: Get a free, all-inclusive learning membership for you and your household—including 1-on-1 tutoring hours, unlimited on-demand classes, and access to our full suite of learning products and services.
  • Supercharge with AI: Gain exclusive access to cutting-edge AI tools that boost your productivity, making you feel almost super-human (cape not included).
  • Feedback-Rich, Collaborative Culture: Regular training, peer reviews, and a team that treats every member as a vital collaborator and owner in our success.
  • Make a Global Impact: Your expertise fuels an innovative platform used by learners around the world.
Bottom Line

If you\'re driven by impact, energized by ownership, and excited to help shape what\'s next, you\'ll thrive here. We move fast, think big, and reward those who deliver.

Seniority level
  • Mid-Senior level
Employment type
  • Contract
Job function
  • Information Technology
Industries
  • Technology, Information and Internet
#J-18808-Ljbffr
  • consultor devsecops

    Há 8 horas


    Fortaleza, Ceará, Brasil G4F Tempo inteiro R$70.000 - R$120.000 por ano

    Consultor (a) DEVSECOPSAG4Fé uma empresa com uma trajetória sólida de 15 anos, dedicada a conectar pessoas, ideias e tecnologia para oferecer soluções inovadoras. Somos mais de 8.000#greatersatuando em todo o Brasil.Atribuições Ao CargoDefinição de indicadores (KPI) para as tarefas e ações de segurança realizadas em todo o processo de...

  • AWS DevOps Engineer

    4 semanas atrás


    Fortaleza, Ceará, Brasil Applaudo Tempo inteiro

    Job DescriptionAbout youYou are someone who wants to influence your own development. You're looking for a company where you have the opportunity to pursue your interests and be able to grow professionally.You bring to Applaudo the following competencies:Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent work...


  • Fortaleza, Ceará, Brasil Canonical Tempo inteiro

    Join or sign in to find your next job Join to apply for the Linux Devices Software Engineer role at Canonical Continue with Google Continue with Google 1 month ago Be among the first 25 applicants Join to apply for the Linux Devices Software Engineer role at Canonical This role is one of our general tracks. Apply here for all engineering teams at...


  • Fortaleza, Ceará, Brasil G4F Tempo inteiro R$4.000 - R$8.000 por ano

    Estamos buscando um talento para a posição deAnalista de Segurança da Informação e Cibernética (Operações Defensivas).A G4F é uma empresa com uma trajetória sólida de 15 anos, dedicada a conectar pessoas, ideias e tecnologia para oferecer soluções inovadoras. Somos mais de 8.000 #greaters atuando em todo o Brasil.Atribuições Ao...

  • Lead Systems Engineer

    3 semanas atrás


    Fortaleza, Ceará, Brasil EPAM Systems Tempo inteiro

    Overview We are looking for a Lead Systems Engineer to lead modernization and migration initiatives while delivering scalable, secure cloud-based solutions. This role is critical in managing AWS infrastructure, enhancing operational standards, and promoting team collaboration for seamless system and process integration. Responsibilities Deploy AWS...

  • Full Stack Software Engineer

    3 semanas atrás


    Fortaleza, Ceará, Brasil Metacto Tempo inteiro

    Overview As a Full Stack Software Engineer at MetaCTO, you will develop both client and server-side applications, working closely with cross-functional teams to create innovative, high-quality solutions. You'll have the opportunity to contribute to a variety of projects, from MVPs to fully-fledged systems, while helping shape our development practices....


  • Fortaleza, Ceará, Brasil FullStack Labs Tempo inteiro

    Senior AI/ML Full Stack Engineer - Remote - Latin AmericaJoin our talent network and connect with U.S. clients for flexible, project-based development work as a Senior AI/ML Full Stack Engineer.OverviewFullStack is the most transparent IT talent network, connecting highly skilled individuals with top global companies and Silicon Valley startups for remote,...

  • Mobile Engineer ID36666

    4 semanas atrás


    Fortaleza, Ceará, Brasil AgileEngine Tempo inteiro

    OverviewMobile Engineer ID36666 ($2,500 signing bonus)1 day ago Be among the first 25 applicantsAgileEngine is an Inc. 5000 company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has earned us...


  • Fortaleza, Ceará, Brasil HOSTWEB DATA CENTER Tempo inteiro

    Responsabilidades/Atribuições:- Realizar análise de segurança (varreduras de vulnerabilidades e pentest em infraestrutura e aplicações);- Implantar soluções voltadas para a segurança da informação;- Monitorar serviços e ambientes;- Planejar e executar manutenções preventivas e corretivas;- Realizar pesquisa e implantação de melhorias e/ou...

  • Innovative Platform Engineer

    3 semanas atrás


    Fortaleza, Ceará, Brasil beBeeDevops Tempo inteiro

    As a seasoned professional, you will be responsible for implementing and supporting critical enterprise solutions. Our mission is to design and deploy innovative tools and infrastructure enhancements that enable efficient delivery and operation of scalable applications. Key Responsibilities Deploy and integrate legacy applications and microservices utilizing...