
Application Security Engineer
Há 3 dias
We are seeking an experienced Application Security Engineer to serve as a trusted partner to our software development teams. This role focuses on making our product secure by design—embedding security into how software is architected, written, deployed, and maintained. Unlike infrastructure security roles, this position centers on application-layer and code-level security, working closely with developers to enable fast, confident delivery by providing meaningful, actionable security tooling and feedback. This includes leveraging modern AI-assisted techniques to accelerate vulnerability analysis, exploit chaining, and demonstration of actual risk. You will ensure engineering teams move faster—not slower—while minimizing noise. This role is part of the IT & Security team and prioritizes embedding guardrails into developer workflows rather than enforcement gates.
About Nerdy – the company behind Varsity Tutors – we built Live + AI platforms that fuse real-time human expertise with proprietary generative-AI systems to deliver measurable academic impact at global scale.
QualificationsRequired:
- Experience as an Application Security Engineer, Security Consultant, or Security-focused Software Engineer.
- Strong understanding of secure coding practices and common vulnerability patterns.
- Ability to apply common web application attack techniques and create proof-of-concept exploits to validate whether vulnerabilities are exploitable in our environment.
- Proven ability to analyze exploit chains and demonstrate actual risk, leveraging AI to accelerate discovery and validation.
- Hands-on experience integrating security tooling into CI/CD pipelines.
- Familiarity with Ruby, Go, JavaScript/React, and related frameworks.
- Deep familiarity with OWASP guidance, including the OWASP Top 10, ASVS, and Secure Coding Guidelines.
- Partner with DevOps to embed application security into CI/CD pipeline design and practices.
- Ability to assess and communicate application risk in architectural and business context.
- Comfortable demonstrating real-world exploits to technical and non-technical stakeholders.
- Excellent written and verbal communication skills in an async-first, remote environment.
Preferred:
- Experience leveraging and adapting open-source tools and frameworks for application security testing and validation.
- Experience with API security testing and continuous monitoring, leveraging AI for fuzzing, intelligent input generation, and automated discovery.
- Experience building or maintaining secure development training programs.
- Security certifications (OSWE, OSCP, GIAC) are a plus but not required.
- Enable engineering teams to move quickly while embedding security into development workflows—security and speed go hand-in-hand.
- Partner with engineering on secure use of AI services, evaluating controls such as AI gateways, prompt inspection, and policy enforcement.
- Identify, prioritize, and implement security tooling in developer environments and CI/CD pipelines, with AI-assisted triage to reduce noise and highlight exploitable risks.
- Collaborate with developers to identify vulnerabilities in code, APIs, and dependencies; improve secure coding awareness; and participate in design reviews and threat modeling.
- Demonstrate practical exploit techniques to raise security awareness and drive remediation, including chaining multiple weaknesses across services to illustrate end-to-end risk.
- Analyze vulnerabilities across code, dependencies, APIs, and logic, with AI-assisted techniques to identify and prioritize exploit chains.
- Build or adapt automation scripts and tools for continuous security validation, using AI copilots to accelerate script generation and validation.
- Provide coaching, documentation, and embedded training to help developers understand and apply security guidance within their workflows.
- Continuously evaluate emerging AI and application security threats and detection techniques.
- Lead incident response activities as part of the incident commander rotation.
- Drive continuous improvement of incident response runbooks and playbooks.
Join our worldwide team—work from home, get great pay, and help shape the future of learning. Here's what you get:
- Competitive USD Compensation: Enjoy a market-leading rate paid in U.S. dollars.
- 100% Remote (Home Country Only): Work from anywhere in your home country—no relocation required, no borders crossed.
- Flexible Time Off: Our flexible PTO lets you recharge on your own terms and when you need it the most.
- Local Holiday Pay: We honor your nation's official holidays with paid time off—celebrate what matters to you.
- Continuous Learning: Get a free, all-inclusive learning membership for you and your household—including 1-on-1 tutoring hours, unlimited on-demand classes, and access to our full suite of learning products and services.
- Supercharge with AI: Gain exclusive access to cutting-edge AI tools that boost your productivity, making you feel almost super-human (cape not included).
- Feedback-Rich, Collaborative Culture: Regular training, peer reviews, and a team that treats every member as a vital collaborator and owner in our success.
- Make a Global Impact: Your expertise fuels an innovative platform used by learners around the world.
If you\'re driven by impact, energized by ownership, and excited to help shape what\'s next, you\'ll thrive here. We move fast, think big, and reward those who deliver.
Seniority level- Mid-Senior level
- Contract
- Information Technology
- Technology, Information and Internet
-
Application Security Architectural Expert
2 semanas atrás
Fortaleza, Ceará, Brasil beBeeAppSec Tempo inteiro US$120.000 - US$140.000Senior Application Security EngineerRain is the fastest-growing fintech in the U.S., serving millions of employees and backed by top investors. We've raised significant funding to fuel our next stage of hypergrowth.Our company seeks a skilled Senior Application Security Engineer to join its growing Security team. This role demands a proactive approach to...
-
IT Security Engineer
2 semanas atrás
Fortaleza, Ceará, Brasil Rocket Tempo inteiroOverview Join to apply for the IT Security Engineer role at Rocket.Chat . You will report to our Head of Security and join the Security team. On TheOrg you can view the complete structure of our organisation, including information about every team member, hiring managers and the size of each department. What You\'ll Do Support compliance and audit...
-
Cloud Security Specialist
Há 4 dias
Fortaleza, Ceará, Brasil beBeeSecurity Tempo inteiro US$100.000 - US$120.000Job TitleA security consultant plays a key role in developing and implementing all security aspects for complex global applications based on Microsoft Azure technology.This position is responsible for supporting multiple project teams, including detailed participation in implementation, certification of security controls across various...
-
System Security Specialist
2 semanas atrás
Fortaleza, Ceará, Brasil beBeeSecurity Tempo inteiro US$100.000 - US$145.000Site Reliability Engineer Role OverviewWe're seeking an accomplished Site Reliability Engineer to drive security enhancements in our production environment.This role requires a strong focus on Governance, Risk, and Compliance (GRC) principles to ensure seamless system stability.About the Job:Lead operating system upgrades across our production and cloud...
-
Application Engineer Brazil
1 semana atrás
Fortaleza, Ceará, Brasil Fluence Corporation Tempo inteiroJoin Our Team as a Application Engineer Are you a seasoned Application Engineer seeking a dynamic opportunity with a publicly traded company? Are you looking to work for a global organization that positively impacts the environment? Would you like to work for a multicultural team? Look no further As part of the Fluence team, you would play a pivotal role in...
-
Global Security Solutions Specialist
Há 4 dias
Fortaleza, Ceará, Brasil beBeeSecurity Tempo inteiro R$112.776 - R$141.594Job Overview:This role plays a pivotal part in crafting and implementing security frameworks for complex global applications built on Microsoft Azure technology.The position requires expertise in multiple IT system architectures, cloud technologies, and supporting systems like IAM, network security, firewalls, user account management, auditing, and logging...
-
Software Engineer
1 semana atrás
Fortaleza, Ceará, Brasil beBeeSoftware Tempo inteiro R$93.000 - R$121.000Job Title: Software EngineerAbout the RoleWe are seeking a highly skilled software engineer to join our team. As a software engineer, you will be responsible for designing, developing, and maintaining scalable microservices using Node.js.Key ResponsibilitiesMicroservices Development: Develop scalable microservices using Node.js to ensure modularity,...
-
Senior Cloud Software Engineer
1 semana atrás
Fortaleza, Ceará, Brasil beBeeSoftwareEngineer Tempo inteiro R$60.000 - R$80.000About the RoleAs a talented senior software engineer, you will play a key role in driving our cloud-native application development projects forward.Key Responsibilities:Develop and maintain scalable cloud-based applications using .NET / .NET Core and related technologies.Design efficient database schemas, write complex queries, and optimize SQL performance...
-
AI Engineer – Application Development
Há 6 dias
Fortaleza, Ceará, Brasil beBeeArtificial Tempo inteiro US$128.000 - US$187.600Job Description:As a key member of our cross-functional team, you will collaborate with product managers, solution engineers, and client experience managers to create world-class, AI-enabled solutions.Our goal is to deliver a seamless experience for every patient and a scalable path to automation for every clinic.This role offers an opportunity to join a...
-
consultor devsecops
Há 24 horas
Fortaleza, Ceará, Brasil G4F Tempo inteiro R$70.000 - R$120.000 por anoConsultor (a) DEVSECOPSAG4Fé uma empresa com uma trajetória sólida de 15 anos, dedicada a conectar pessoas, ideias e tecnologia para oferecer soluções inovadoras. Somos mais de 8.000#greatersatuando em todo o Brasil.Atribuições Ao CargoDefinição de indicadores (KPI) para as tarefas e ações de segurança realizadas em todo o processo de...