Staff Security Engineer – AppSec
Posted 3hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Arquiteto AppSec definindo padrões e controles para proteger aplicações, APIs e sistemas com LLMs da Stone, empresa brasileira de tecnologia e serviços financeiros.
Responsibilities:
- Define security architecture standards with Engineering and Product teams, including for applications with LLMs, agents, and RAG pipelines
- Create architectural plans for new systems and technical migration roadmaps for legacy systems
- Identify vulnerabilities, assess risks, and help prevent attacks
- Participate in security incident analysis and response
- Train and raise awareness among development teams about best practices and the safe use of AI assistants
- Define and implement security strategies for applications using LLMs and generative AI
- Integrate security practices from the beginning of the software development lifecycle
- Conduct architecture, code, and design reviews
- Define guardrails and standards for LLM risks, such as prompt injection, insecure output handling, data leakage, excessive agency, and denial-of-wallet
- Establish guidelines for the safe use of AI-assisted development tools
- Develop security standards and best practices
- Provide technical security guidance and training
- Use and understand automated validation tools in CI/CD, such as SAST, DAST, SCA, and Secret Scanning
- Monitor threat trends, including threats to AI systems
- Develop solutions to complex security challenges
- Hunt for threats in corporate and production environments
Requirements:
- Bachelor's degree, completed or in progress, in Information Security, Computer Science, Information Systems, Software Engineering, or a related field
- Knowledge of common attack vectors
- Experience conducting threat modeling
- Experience with effective protection mechanisms for APIs and mobile applications
- Knowledge of fundamental Cloud security services and concepts (AWS, Azure, or GCP)
- Familiarity with security risks in applications that use LLMs and generative AI, including the OWASP Top 10 for LLM Applications and MITRE ATLAS
- Ability to identify opportunities for improvement, new solutions, and alerts
- Influencing and negotiation skills to guide teams
- Ability to work autonomously
- Concise, candid, and assertive communication, with the ability to translate complex problems into accessible language
- Proactive in seeking or requesting information
- Ability to work effectively on multidisciplinary teams using agile methodologies
- Ability to read and communicate in English
- Experience participating in incidents and identifying root causes (a plus)
- Experience with projects subject to financial-sector requirements, such as Bacen, PCI, and SOX (a plus)
- Strong programming skills (a plus)
- Hands-on experience with threat modeling and controls for LLM applications in production (a plus)
- Experience securing APIs that expose AI models (a plus)
- Experience developing policies and controls for the enterprise use of generative AI tools (a plus)
- Knowledge of the NIST AI RMF and ISO/IEC 42001 (a plus)
Benefits:
- Base salary
- Variable compensation package (profit sharing, long-term incentive plan, or commission), depending on role eligibility
- Health and dental insurance with co-payments
- Hospital Virtual Verde: telemedicine team available 24 hours a day, 7 days a week
- Medication allowance
- Meal and/or food allowance – Pluxee
- Childcare assistance for children up to 5 years and 11 months old
- Assistance for employees with children with disabilities
- Life insurance
- Fuel allowance or commuting assistance
- Home office allowance for hybrid or remote contracts
- Welcome kit for new parents
- SESC partnership
- Education benefit: in-house self-development platform (Studa and Stone Library)
- Acolhe360°: free emotional support
- Quick massage and on-site clinic
- Optional benefits: Wellhub, TotalPass, Pet Club, Flash, Férias&Co, transportation vouchers, Allya, and educational partnerships


















