Grupo QuintoAndar | Sênior Security Engineer
Grupo QuintoAndarBrasil1w ago
Job description
Sênior Security Engineer at Grupo QuintoAndar.
About the role
Grupo QuintoAndar is seeking a Senior Security Engineer to strengthen the company's security posture across its platforms and infrastructure. This role involves designing, implementing, and maintaining security controls that protect sensitive data and critical systems from evolving threats. The engineer will work closely with development and operations teams to embed security practices throughout the entire software development lifecycle and contribute to building a strong security culture within the organization. The position is based in Brasil and reports to the security leadership team within the company.
Key facts
What you'll do
- Lead the design and implementation of security architectures for platform services and internal applications.
- Conduct thorough security assessments of existing systems and infrastructure to identify potential vulnerabilities.
- Collaborate with engineering teams to integrate security measures into development workflows and internal processes.
- Monitor and respond to security incidents, coordinating remediation efforts across multiple departments quickly.
- Develop and maintain comprehensive security policies, standards, and detailed documentation for the entire organization.
- Perform penetration testing and detailed code reviews to evaluate application security levels consistently.
- Advise product teams on secure coding practices and conduct threat modeling exercises on a regular basis.
- Manage relationships with external security vendors and evaluate new security tools and services available.
- Drive security awareness initiatives and training programs across all technical staff members within the company.
- Automate security checks and controls within continuous integration and deployment pipelines to ensure compliance.
- Evaluate and recommend security tools and services that align with the company's strategic objectives.
- Participate in architecture review meetings to ensure security considerations are addressed from the start.
Requirements
- Demonstrated experience in security engineering or a closely related discipline and relevant professional setting.
- Strong understanding of application security principles, common vulnerabilities, and effective mitigation strategies.
- Proficiency with security frameworks and compliance standards relevant to the modern technology industry.
- Ability to communicate complex security concepts to both technical and non-technical audiences with clarity.
- Experience working in a fast-paced environment with multiple concurrent priorities and shifting deadlines.
- Solid foundation in networking protocols, operating systems, and modern cloud computing environments and services.
- Proven track record of improving organizational security posture through practical, actionable, and measurable measures.
- Bachelor's degree or equivalent professional experience in computer science or a related technical field.
- Experience with security operations and incident response procedures, including forensic analysis and documentation.
Nice to have
- Familiarity with Brazilian data protection regulations and compliance requirements for technology companies operating locally.
- Experience with security automation tooling and infrastructure-as-code practices in production environments at scale.
- Background in threat intelligence and proactive security research activities within the broader technology industry.
- Knowledge of containerization and orchestration platforms in security contexts, including deployment and runtime monitoring.
- Understanding of software supply chain security and dependency management practices in modern development.
Skills & tools
- Security information and event management platforms for monitoring, alerting, and incident response workflows.
- Programming and scripting languages commonly used for building security tooling and automation solutions.
- Cloud security services and identity and access management solutions for modern distributed infrastructures.
- Vulnerability scanning and static analysis tools for evaluating code quality and infrastructure security.
- Container and orchestration security frameworks for securing modern deployment pipelines and runtime environments.
- Network security appliances and intrusion detection and prevention systems for comprehensive perimeter defense.
- Endpoint detection and response platforms for protecting devices and workstations across the organization.
- Database security controls and encryption technologies for protecting sensitive data at rest and in transit.
Practical notes
- This role is based in Brasil and follows local labor regulations and standard employment practices.
- The engagement type and compensation details have not been disclosed by the company at this time and may be discussed during later stages.
- Candidates should expect to work with cross-functional teams across multiple departments within the organization.
- The hiring process may include technical assessments and security-focused interviews with the engineering leadership team.
- The company values continuous learning and provides opportunities for professional development in the security domain.
- Applicants should be prepared to discuss past security projects and contributions during the interview process.