
Application Security Engineer
Há 23 horas
We are seeking an experienced Application Security Engineer to serve as a trusted partner to our software development teams. This role focuses on making our product secure by design—embedding security into how software is architected, written, deployed, and maintained. Unlike infrastructure security roles, this position centers on application-layer and code-level security, working closely with developers to enable fast, confident delivery by providing meaningful, actionable security tooling and feedback. This includes leveraging modern AI-assisted techniques to accelerate vulnerability analysis, exploit chaining, and demonstration of actual risk. You will ensure engineering teams move faster—not slower—while minimizing noise. This role is part of the IT & Security team and prioritizes embedding guardrails into developer workflows rather than enforcement gates.
About NerdyAt Nerdy (NYSE: NRDY) - the company behind Varsity Tutors - we\'re redrawing the blueprint of learning. Our Live + AI platform fuses real-time human expertise with proprietary generative-AI systems, setting a new bar for measurable academic impact at global scale. We recruit the kind of technologists and operators you\'d bet on as solo founders - people who turn ambiguous problems into shipping code, iterate faster than markets move, and compound their advantage with every data point. In an era where great employees can deliver 10-times the leverage of the merely good, we back those who play to win.
How we compete- AI-Native at every level From the CEO to day-one hires, everyone builds and ships with generative AI. If you\'re not wielding AI, you\'re not done.
- Entrepreneurial velocity Move at founder speed, prototype in hours, and measure in real user outcomes. Slow teams die.
- Free-market rigor Ideas rise or fall on merit and results - no committees, no politics, no cap on upside.
- Full-stack ownership You design, build, and run what you ship; accountability is a feature, not a bug.
- Reward for contribution Pay rises with impact, not years. Outstanding results earn outsized rewards. We evaluate both what you achieve and how you achieve it: living our leadership principles and using AI effectively are formally measured and rewarded.
- Relentless exploration Push the frontier of generative AI in live learning and - because only the paranoid survive - questioning every legacy assumption along the way.
- Is Apolitical You stay focused on mission-aligned outcomes, not distractions or unrelated causes.
If you\'re a technically minded builder who thrives on open competition, personal responsibility, and the chance to redefine how the world learns - while continually stretching the limits of what generative AI can do - come do the most ambitious and rewarding work of your career here. Learn more at nerdy.com.
Shareholder LettersNerdy\'s shareholder letters below explain our latest products and strategy:
- Q2-2025 Shareholder Letter
- Q1-2025 Shareholder Letter
- Q4-2024 Shareholder Letter
Required :
- Experience as an Application Security Engineer, Security Consultant, or Security-focused Software Engineer.
- Strong understanding of secure coding practices and common vulnerability patterns.
- Ability to apply common web application attack techniques and create proof-of-concept exploits to validate whether vulnerabilities are exploitable in our environment.
- Proven ability to analyze exploit chains and demonstrate actual risk, leveraging AI to accelerate discovery and validation.
- Hands-on experience integrating security tooling into CI/CD pipelines.
- Familiarity with Ruby, Go, JavaScript/React, and related frameworks.
- Deep familiarity with OWASP guidance, including the OWASP Top 10, ASVS, and Secure Coding Guidelines.
- Partner with DevOps to embed application security into CI/CD pipeline design and practices.
- Ability to assess and communicate application risk in architectural and business context.
- Comfortable demonstrating real-world exploits to technical and non-technical stakeholders.
- Excellent written and verbal communication skills in an async-first, remote environment.
Preferred :
- Experience leveraging and adapting open-source tools and frameworks for application security testing and validation.
- Experience with API security testing and continuous monitoring, leveraging AI for fuzzing, intelligent input generation, and automated discovery.
- Experience building or maintaining secure development training programs.
- Security certifications (OSWE, OSCP, GIAC) are a plus but not required.
- Enable engineering teams to move quickly while embedding security into development workflows—security and speed go hand-in-hand.
- Partner with engineering on secure use of AI services, evaluating controls such as AI gateways, prompt inspection, and policy enforcement.
- Identify, prioritize, and implement security tooling in developer environments and CI/CD pipelines, with AI-assisted triage to reduce noise and highlight exploitable risks.
- Collaborate with developers to identify vulnerabilities in code, APIs, and dependencies; improve secure coding awareness; and participate in design reviews and threat modeling.
- Demonstrate practical exploit techniques to raise security awareness and drive remediation, including chaining multiple weaknesses across services to illustrate end-to-end risk.
- Analyze vulnerabilities across code, dependencies, APIs, and logic, with AI-assisted techniques to identify and prioritize exploit chains.
- Build or adapt automation scripts and tools for continuous security validation, using AI copilots to accelerate script generation and validation.
- Provide coaching, documentation, and embedded training to help developers understand and apply security guidance within their workflows.
- Continuously evaluate emerging AI and application security threats and detection techniques.
- Lead incident response activities as part of the incident commander rotation.
- Drive continuous improvement of incident response runbooks and playbooks.
- Competitive USD Compensation : Market-leading rate paid in U.S. dollars.
- 100% Remote : Work from anywhere in your home country—no relocation required.
- Flexible Time Off : Flexible PTO lets you recharge on your terms.
- Local Holiday Pay : Paid holidays in your nation.
- Continuous Learning : Free learning membership for you and your household with tutoring hours and on-demand classes.
- Supercharge with AI : Access to AI tools to boost productivity.
- Feedback-Rich, Collaborative Culture : Regular training and peer reviews in a collaborative environment.
- Make a Global Impact : Your expertise fuels a learning platform used worldwide.
- Seniority level : Mid-Senior level
- Employment type : Contract
- Job function : Information Technology
- Industries : Technology, Information and Internet
Referrals increase your chances of interviewing at Varsity Tutors, a Nerdy Company by 2x
Get notified about new Application Security Engineer jobs in Porto Alegre, Rio Grande do Sul, Brazil.
#J-18808-Ljbffr-
Application Security Engineer
Há 20 horas
Porto Alegre, Rio Grande do Sul, Brasil Varsity Tutors LLC Tempo inteiroOverview We are seeking an experienced Application Security Engineer to serve as a trusted partner to our software development teams. This role focuses on making our product secure by design—embedding security into how software is architected, written, deployed, and maintained. Unlike infrastructure security roles, this position centers on...
-
Senior Application Security Engineer
Há 2 dias
Porto Alegre, Rio Grande do Sul, Brasil Rain Tempo inteiroOverviewSenior Application Security Engineer at RainRain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus.We have raised nearly $400M in funding—including the largest Series A in fintech history—and recently closed our Series B to fuel our next stage of...
-
Application Security Specialist
Há 2 dias
Porto Alegre, Rio Grande do Sul, Brasil beBeeSecurity Tempo inteiro US$1.440.000 - US$2.160.000Secure Our Systems by Joining Our Team as a Skilled Application Security ProfessionalAbout the RoleWe are seeking an experienced Application Security Engineer to protect our systems' security and integrity.Key ResponsibilitiesConduct thorough security assessments and risk analysis to identify vulnerabilities.Develop and implement effective security protocols...
-
Senior Application Security Engineer
1 dia atrás
Porto Alegre, Rio Grande do Sul, Brasil Rain Tempo inteiroOverview Senior Application Security Engineer at Rain Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. We have raised nearly $400M in funding—including the largest Series A in fintech history—and recently closed our Series B to fuel our next stage of...
-
Expert Application Security Specialist
Há 22 horas
Porto Alegre, Rio Grande do Sul, Brasil beBeeApplication Tempo inteiro US$110.000 - US$140.000Secure Software Engineering ExpertiseWe are seeking an experienced Application Security Engineer to serve as a trusted partner to our software development teams. This role focuses on making our product secure by design—embedding security into how software is architected, written, deployed, and maintained.This position centers on application-layer and...
-
Senior Application Security Professional
1 semana atrás
Porto Alegre, Rio Grande do Sul, Brasil beBeeSecurity Tempo inteiro US$100.000 - US$120.000Key role for a senior application security engineer.This position requires strong technical expertise and ability to collaborate with development teams. The right candidate will partner closely with engineering squads, work alongside the Cloud Security team and improve the overall security posture of our applications and platforms.Main Responsibilities:Work...
-
Information Security Engineer
2 semanas atrás
Porto Alegre, Rio Grande do Sul, Brasil Wex Tempo inteiroJoin to apply for the Information Security Engineer - IAM role at WEXJoin to apply for the Information Security Engineer - IAM role at WEXAbout The Team/RoleWe are the WEX Identity Protection Team, tasked with deploying and managing security IAM technologies and procedures across the enterprise.We work closely with internal teams and clients to ensure the...
-
Information Security Engineer
1 semana atrás
Porto Alegre, Rio Grande do Sul, Brasil WEX Tempo inteiroJoin to apply for the Information Security Engineer - IAM role at WEX Join to apply for the Information Security Engineer - IAM role at WEX About The Team/RoleWe are the WEX Identity Protection Team, tasked with deploying and managing security IAM technologies and procedures across the enterprise. We work closely with internal teams and clients to ensure...
-
Information Security Engineer
Há 5 dias
Porto Alegre, Rio Grande do Sul, Brasil WEX Tempo inteiroJoin to apply for the Information Security Engineer - IAM role at WEXJoin to apply for the Information Security Engineer - IAM role at WEXAbout The Team/RoleWe are the WEX Identity Protection Team, tasked with deploying and managing security IAM technologies and procedures across the enterprise. We work closely with internal teams and clients to ensure the...
-
Security Software Engineer
Há 7 dias
Porto Alegre, Rio Grande do Sul, Brasil Canonical Tempo inteiroJoin or sign in to find your next job Join to apply for the Security Software Engineer role at Canonical 1 week ago Be among the first 25 applicants Join to apply for the Security Software Engineer role at Canonical Get AI-powered advice on this job and more exclusive features. Canonical is a leading provider of open source software and operating...