Application Security Engineer

Há 5 dias


Fortaleza, Brasil Nerdy Tempo inteiro

OverviewWe are seeking an experienced Application Security Engineer to serve as a trusted partner to our software development teams.
This role focuses on making our product secure by design—embedding security into how software is architected, written, deployed, and maintained.
Unlike infrastructure security roles, this position centers on application-layer and code-level security, working closely with developers to enable fast, confident delivery by providing meaningful, actionable security tooling and feedback.
This includes leveraging modern AI-assisted techniques to accelerate vulnerability analysis, exploit chaining, and demonstration of actual risk.
You will ensure engineering teams move faster—not slower—while minimizing noise.
This role is part of the IT & Security team and prioritizes embedding guardrails into developer workflows rather than enforcement gates.About NerdyAt Nerdy (NYSE: NRDY) - the company behind Varsity Tutors - we're redrawing the blueprint of learning.
Our Live + AI platform fuses real-time human expertise with proprietary generative-AI systems, setting a new bar for measurable academic impact at global scale.
We recruit the kind of technologists and operators you'd bet on as solo founders - people who turn ambiguous problems into shipping code, iterate faster than markets move, and compound their advantage with every data point.
In an era where great employees can deliver 10-times the leverage of the merely good, we back those who play to win.Fortune favors the bold.
Join us.How we competeAI-Native at every levelFrom the CEO to day-one hires, everyone builds and ships with generative AI.
If you're not wielding AI, you're not done.Entrepreneurial velocityMove at founder speed, prototype in hours, and measure in real user outcomes.
Slow teams die.Free-market rigorIdeas rise or fall on merit and results - no committees, no politics, no cap on upside.Full-stack ownershipYou design, build, and run what you ship; accountability is a feature, not a bug.Reward for contributionPay rises with impact, not years.
Outstanding results earn outsized rewards.
We evaluate both what you achieve and how you achieve it: living our leadership principles and using AI effectively are formally measured and rewarded.Relentless explorationPush the frontier of generative AI in live learning and - because only the paranoid survive - questioning every legacy assumption along the way.Is ApoliticalYou stay focused on mission-aligned outcomes, not distractions or unrelated causes.If you're a technically minded builder who thrives on open competition, personal responsibility, and the chance to redefine how the world learns - while continually stretching the limits of what generative AI can do - come do the most ambitious and rewarding work of your career here.
Learn more at nerdy.com.
Nerdy's shareholder letters below explain our latest products and strategy:Experience as an Application Security Engineer, Security Consultant, or Security-focused Software Engineer.Strong understanding of secure coding practices and common vulnerability patterns.Ability to apply common web application attack techniques and create proof-of-concept exploits to validate whether vulnerabilities are exploitable in our environment.Proven ability to analyze exploit chains and demonstrate actual risk, leveraging AI to accelerate discovery and validation.Hands-on experience integrating security tooling into CI/CD pipelines.Deep familiarity with OWASP guidance, including the OWASP Top 10, Application Security Verification Standard (ASVS), and Secure Coding Guidelines.Partner with DevOps to embed application security into CI/CD pipeline design and practices.Ability to assess and communicate application risk in architectural and business context.Comfortable demonstrating real-world exploits to technical and non-technical stakeholders.Excellent written and verbal communication skills in an async-first, remote environment.PreferredExperience leveraging and adapting open-source tools and frameworks for application security testing and validation.Experience with API security testing and continuous monitoring, leveraging AI for fuzzing, intelligent input generation, and automated discovery.Experience building or maintaining secure development training programs.Security certifications (OSWE, OSCP, GIAC) are a plus but not required.ResponsibilitiesEnable engineering teams to move quickly while embedding security into development workflows—security and speed go hand-in-hand.Partner with engineering on secure use of AI services, evaluating controls such as AI gateways, prompt inspection, and policy enforcement.Identify, prioritize, and implement security tooling in developer environments and CI/CD pipelines, with AI-assisted triage to reduce noise and highlight exploitable risks.Collaborate with developers to identify vulnerabilities in code, APIs, and dependencies; improve secure coding awareness; and participate in design reviews and threat modeling.Demonstrate practical exploit techniques to raise security awareness and drive remediation, including chaining multiple weaknesses across services to illustrate end-to-end risk.Analyze vulnerabilities across code, dependencies, APIs, and logic, with AI-assisted techniques to identify and prioritize exploit chains.Build or adapt automation scripts and tools for continuous security validation, using AI copilots to accelerate script generation and validation.Provide coaching, documentation, and embedded training to help developers understand and apply security guidance within their workflows.Continuously evaluate emerging AI and application security threats and detection techniques.Lead incident response activities as part of the incident commander rotation.Drive continuous improvement of incident response runbooks and playbooks.
#J-18808-Ljbffr



  • Fortaleza, Brasil Nerdy Tempo inteiro

    Overview We are seeking an experienced Application Security Engineer to serve as a trusted partner to our software development teams. This role focuses on making our product secure by design—embedding security into how software is architected, written, deployed, and maintained. Unlike infrastructure security roles, this position centers on...


  • Fortaleza, Brasil Nerdy Tempo inteiro

    OverviewWe are seeking an experienced Application Security Engineer to serve as a trusted partner to our software development teams. This role focuses on making our product secure by design—embedding security into how software is architected, written, deployed, and maintained. Unlike infrastructure security roles, this position centers on application-layer...


  • Fortaleza, Ceará, Brasil Varsity Tutors, a Nerdy Company Tempo inteiro

    Overview We are seeking an experienced Application Security Engineer to serve as a trusted partner to our software development teams. This role focuses on making our product secure by design—embedding security into how software is architected, written, deployed, and maintained. Unlike infrastructure security roles, this position centers on...

  • Reverse Engineer

    2 semanas atrás


    Fortaleza, Brasil Ranger Technical Resources Tempo inteiro

    Android Reverse Engineer Position Summary:Our partner, a leading cybersecurity provider specializing in Extended Detection and Response (XDR) solutions, is seeking a highly skilled Android Reverse Engineer to join a dynamic security team focused on identifying malicious behaviors and vulnerabilities in Android applications.As an engineer, you will primarily...


  • Fortaleza, Brasil FullStack Labs Tempo inteiro

    OverviewPart-time Security Engineer - Remote - Latin America. Join our talent network to connect with U.S. clients for flexible, project-based development work as a Part-time Security Engineer. ResponsibilitiesYou will integrate directly into our client's team and work alongside their existing designers and engineers on a daily basis. Qualifications4+...

  • IT Security Engineer

    3 semanas atrás


    Fortaleza, Brasil Rocket.Chat Tempo inteiro

    OverviewJoin to apply for the IT Security Engineer role at Rocket.Chat . You will report to our Head of Security and join the Security team. On TheOrg you can view the complete structure of our organisation, including information about every team member, hiring managers and the size of each department. What You\'ll DoSupport compliance and audit...

  • Application Engineer Brazil

    3 semanas atrás


    Fortaleza, Brasil Fluence Corporation Tempo inteiro

    Join Our Team as a Application EngineerAre you a seasoned Application Engineer seeking a dynamic opportunity with a publicly traded company? Are you looking to work for a global organization that positively impacts the environment? Would you like to work for a multicultural team? Look no further! As part of the Fluence team, you would play a pivotal role in...

  • Security Engineer

    1 semana atrás


    Fortaleza, Brasil Nerdy Tempo inteiro

    Security Engineer - Detection & ResponseOverview: You are an AI-powered Security Engineer responsible for identifying and responding to malicious or suspicious activity across our environment with speed and confidence.This role leads the engineering work behind these capabilities—designing scalable systems to detect threats and trigger automated...

  • Consultor Devsecops

    Há 5 dias


    Fortaleza, Brasil G4F Tempo inteiro

    Consultor (a) DEVSECOPSAG4Fé uma empresa com uma trajetória sólida de 15 anos, dedicada a conectar pessoas, ideias e tecnologia para oferecer soluções inovadoras.Somos mais de 8.000#greatersatuando em todo o Brasil.Atribuições Ao CargoDefinição de indicadores (KPI) para as tarefas e ações de segurança realizadas em todo o processo de...

  • Security Engineer

    2 semanas atrás


    Fortaleza, Brasil Nerdy Tempo inteiro

    Security Engineer - Detection & Response Overview: You are an AI-powered Security Engineer responsible for identifying and responding to malicious or suspicious activity across our environment with speed and confidence. This role leads the engineering work behind these capabilities—designing scalable systems to detect threats and trigger automated...