Wellhub

Wellhub

Wellhub: An Upstream OS for data-driven decisions, optimizing production, reducing costs, and minimizing downtime in the Oil & Gas industry.

Gas Utilities
1-10
Founded 2016

Description

  • Lead the technical security strategy for product and application security, including architecture standards, security baselines, and secure coding guidelines.
  • Architect and implement DevSecOps pipelines with SAST, DAST, SCA, and container scanning across CI/CD pipelines.
  • Drive threat modeling for critical product flows and work with engineering leaders to identify and mitigate risks before production.
  • Design and implement centralized security telemetry that unifies application logs, WAF events, and fraud signals in a SIEM platform.
  • Evaluate, select, and implement security tools for application security, SIEM/SOAR, PAM, API gateway security, and container scanning.
  • Build and mentor a team of embedded DevSecOps engineers across product verticals and provide technical leadership.
  • Own the security engineering roadmap for reducing detection and fraud response times through automation.
  • Partner with product and engineering leaders to balance rapid feature delivery with security and risk mitigation.
  • Promote a culture of shared security responsibility and wellbeing across engineering teams.

Requirements

  • At least 4 years of experience in a senior technical leadership role in application security, cloud security, or security engineering.
  • Deep expertise in secure software development lifecycle (SSDLC), threat modeling, and security architecture for distributed systems and microservices.
  • Hands-on experience with SAST, DAST, SCA, container scanning, and SIEM platforms.
  • Extensive cloud security knowledge in AWS and/or GCP, including IAM, VPC security, secrets management, and Kubernetes/EKS security.
  • Experience building and scaling DevSecOps programs and integrating security into CI/CD pipelines.
  • Proficiency in at least two programming languages such as Python, Go, Java, or JavaScript.
  • Familiarity with compliance frameworks such as ISO 27001, PCI DSS, LGPD, and GDPR.
  • Strong communication skills in both Portuguese and English.
  • Prior experience in application security engineering and DevSecOps pipeline implementation is mandatory.
  • Experience with tools such as Checkmarx, Snyk, SonarQube, Burp Suite, OWASP ZAP, Trivy, Prisma, Elastic, Splunk, or Sentinel is preferred.

Benefits

  • Free Gold membership with access to onsite gyms, studios, digital fitness programs, and wellness resources.
  • Ability to add up to three family members to the Wellhub plan.
  • Health insurance.
  • Hybrid and remote work options with a one-time home office setup reimbursement and a monthly work allowance.
  • Flexible scheduling aligned with time zones, team needs, and personal routines.
  • Minimum of 25 days paid holiday per year, plus additional tenure-based days and an extra birthday holiday.
  • 100% paid parental leave, including extended leave and a ramp-back period for birth parents.
  • Career growth support including learning platforms, interactive sessions, personalized development roadmaps, and internal opportunities.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Infrastructure Software Engineer, Identity & Auth Engineering

Dropbox 1K-5K Internet Software & Services

Dropbox is hiring a software engineer to re-architect its Identity platform and services for a future as a multi-product company, with work focused on scaling foundational systems across the organization.

Go OAuth OpenID Connect Python SAML
51 minutes ago

Senior Detection and Response Engineer

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is hiring a Senior Detection and Response Engineer to build and operate defensive security controls that protect the infrastructure supporting its defense technology products.

AWS Azure CI/CD CloudFormation Docker GitHub Go Kubernetes Network Security Python Rust SQL Terraform
1 hour, 6 minutes ago

DevSecOps Engineer

INflow Federal 51-250 Aerospace & Defense

INflow Federal is seeking a fully remote DevSecOps Engineer to support an enterprise case management solution for Department of Defense mission partners by securing and automating cloud-based CI/CD and infrastructure operations in AWS GovCloud.

Agile AWS Bash CI/CD CloudFormation Docker ELK Stack Git GitLab CI Helm Jenkins Kubernetes PowerShell Prometheus Python Terraform
1 hour, 24 minutes ago

Security Engineer - South Africa

SenseOn 51-250 Professional Services

SenseOn is seeking a Security Engineer to own customer deployments, integrations, and technical success for its security platform across real-world environments.

AWS Azure Bash GCP GitHub Go JavaScript Python REST API SIEM
1 hour, 36 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers