Arquiteto de Segurança em Desenvolvimento (AppSec) Senior

45 minutes ago
Full-time
Senior
Software Development
Harford County Public Library

Harford County Public Library

Access, Information, Service, Anytime, Anywhere

Diversified Consumer Services
51-250
Founded 1945

Description

  • Define and implement security strategies for applications, including systems that integrate LLMs and generative AI components.
  • Collaborate with development, engineering, and product teams to embed security practices early in the software lifecycle.
  • Review architecture, code, and designs to identify vulnerabilities and security issues.
  • Define guardrails and security standards for LLM-based applications, addressing risks such as prompt injection, insecure output handling, data leakage, excessive agent autonomy, and denial-of-wallet abuse.
  • Establish guidelines for the safe use of AI-assisted development tools across engineering teams.
  • Develop and promote security standards and best practices for the development organization.
  • Provide technical guidance and security training to development teams.
  • Use CI/CD validation tools such as SAST, DAST, SCA, and secret scanning.
  • Monitor emerging security threats and continuously update protections, including threats affecting AI systems.
  • Develop creative solutions for complex security problems that balance business needs and risk.
  • Investigate threats in corporate and production environments using security experience and intuition.
  • Participate in incident analysis and response, supporting continuous improvement of security processes and practices.

Requirements

  • Experience with common attack vectors.
  • Experience performing threat modeling.
  • Experience protecting APIs and mobile applications.
  • Knowledge of cloud security fundamentals and basic cloud services in AWS, Azure, or GCP.
  • Ability to work within multidisciplinary teams using agile methodologies.
  • Familiarity with security risks in LLM and generative AI applications, including OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Ability to read and communicate in English.
  • Strong communication skills with the ability to translate complex problems into accessible language.
  • Ability to work autonomously.
  • Ability to use influence and negotiation to drive teams toward secure architectures and issue remediation.
  • Initiative to seek or request information when needed.
  • Bachelor’s degree completed or in progress in Information Security, Computer Science, Information Systems, Software Engineering, or related fields.
  • Passion for learning and thriving in a dynamic, constantly changing environment.
  • Preferred: incident response experience focused on root-cause analysis.
  • Preferred: experience in regulated financial projects involving Bacen, PCI, SOX, or similar requirements.
  • Preferred: solid programming knowledge.
  • Preferred: hands-on experience with threat modeling and defining controls for production LLM applications such as chatbots, copilots, agents, and RAG.
  • Preferred: experience securing APIs that expose AI models, including direct and indirect prompt injection, structured output validation, and authorization controls for function calling and tool use.
  • Preferred: experience defining policies and controls for enterprise use of generative AI tools, including prevention of data and intellectual property leakage.
  • Preferred: knowledge of emerging AI governance and security frameworks such as NIST AI RMF and ISO/IEC 42001.

Benefits

  • Health and dental insurance.
  • 24/7 virtual hospital access.
  • Meal voucher and/or food voucher.
  • Remote work allowance for remote roles.
  • Flexible working hours.
  • Education benefit with access to books, podcasts, training, and video lessons through internal learning platforms.
  • Wellhub membership.
  • TotalPass membership.
  • Childcare assistance.
  • Profit sharing bonus (PLR).
  • Life insurance.
  • Transportation voucher for onsite roles.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

AI Architect

Nimble Gravity 51-250 IT Services

Nimble Gravity is seeking an AI Architect to design and deliver Azure-based AI applications that integrate cloud services, software engineering, and real-world AI workflows.

Azure C# CI/CD FastAPI Material UI Python React TypeScript
1 hour ago

Application Engineer

Parachute Health 51-250 Health Care Providers & Services

Parachute Health is hiring a software engineer for its IT & Security team to build internal platforms and AI-driven workflows that improve security, compliance, and operational efficiency across its healthcare technology environment.

AWS Datadog EC2 GCP GitHub GraphQL HIPAA JavaScript Node.js Penetration Testing Python React REST API Ruby on Rails SIEM Splunk SQL TDD TypeScript
1 hour, 30 minutes ago

[Job 29543] Principal Engineer / Principal Architect - Plataforma Técnica (IDP)

CI&T 5K-10K Internet Software & Services

Principal Engineer / Principal Architect role at a remote-first company in Brazil, responsible for defining and governing the technical platform strategy and architecture roadmap for an entire area.

Microservices
1 hour, 45 minutes ago

[Job 29643] AI Engineer (Software Architect)

CI&T 5K-10K Internet Software & Services

CI&T is seeking a senior AI Engineer in its dedicated client operation in Brazil to reshape software development with AI-driven architecture and engineering practices across iOS, Android, and Java BFF teams.

Agile Android iOS Java Microservices
1 hour, 45 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers