Staff Security Engineer – AppSec

Posted 3hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Arquiteto AppSec definindo padrões e controles para proteger aplicações, APIs e sistemas com LLMs da Stone, empresa brasileira de tecnologia e serviços financeiros.

Responsibilities:

  • Define security architecture standards with Engineering and Product teams, including for applications with LLMs, agents, and RAG pipelines
  • Create architectural plans for new systems and technical migration roadmaps for legacy systems
  • Identify vulnerabilities, assess risks, and help prevent attacks
  • Participate in security incident analysis and response
  • Train and raise awareness among development teams about best practices and the safe use of AI assistants
  • Define and implement security strategies for applications using LLMs and generative AI
  • Integrate security practices from the beginning of the software development lifecycle
  • Conduct architecture, code, and design reviews
  • Define guardrails and standards for LLM risks, such as prompt injection, insecure output handling, data leakage, excessive agency, and denial-of-wallet
  • Establish guidelines for the safe use of AI-assisted development tools
  • Develop security standards and best practices
  • Provide technical security guidance and training
  • Use and understand automated validation tools in CI/CD, such as SAST, DAST, SCA, and Secret Scanning
  • Monitor threat trends, including threats to AI systems
  • Develop solutions to complex security challenges
  • Hunt for threats in corporate and production environments

Requirements:

  • Bachelor's degree, completed or in progress, in Information Security, Computer Science, Information Systems, Software Engineering, or a related field
  • Knowledge of common attack vectors
  • Experience conducting threat modeling
  • Experience with effective protection mechanisms for APIs and mobile applications
  • Knowledge of fundamental Cloud security services and concepts (AWS, Azure, or GCP)
  • Familiarity with security risks in applications that use LLMs and generative AI, including the OWASP Top 10 for LLM Applications and MITRE ATLAS
  • Ability to identify opportunities for improvement, new solutions, and alerts
  • Influencing and negotiation skills to guide teams
  • Ability to work autonomously
  • Concise, candid, and assertive communication, with the ability to translate complex problems into accessible language
  • Proactive in seeking or requesting information
  • Ability to work effectively on multidisciplinary teams using agile methodologies
  • Ability to read and communicate in English
  • Experience participating in incidents and identifying root causes (a plus)
  • Experience with projects subject to financial-sector requirements, such as Bacen, PCI, and SOX (a plus)
  • Strong programming skills (a plus)
  • Hands-on experience with threat modeling and controls for LLM applications in production (a plus)
  • Experience securing APIs that expose AI models (a plus)
  • Experience developing policies and controls for the enterprise use of generative AI tools (a plus)
  • Knowledge of the NIST AI RMF and ISO/IEC 42001 (a plus)

Benefits:

  • Base salary
  • Variable compensation package (profit sharing, long-term incentive plan, or commission), depending on role eligibility
  • Health and dental insurance with co-payments
  • Hospital Virtual Verde: telemedicine team available 24 hours a day, 7 days a week
  • Medication allowance
  • Meal and/or food allowance – Pluxee
  • Childcare assistance for children up to 5 years and 11 months old
  • Assistance for employees with children with disabilities
  • Life insurance
  • Fuel allowance or commuting assistance
  • Home office allowance for hybrid or remote contracts
  • Welcome kit for new parents
  • SESC partnership
  • Education benefit: in-house self-development platform (Studa and Stone Library)
  • Acolhe360°: free emotional support
  • Quick massage and on-site clinic
  • Optional benefits: Wellhub, TotalPass, Pet Club, Flash, Férias&Co, transportation vouchers, Allya, and educational partnerships