← Back to job listings
TL
Senior Product Security Engineer
Tessera Labs · Remote, Brazil
About The Role
Senior Product Security Engineer
The Role
We're hiring a Senior Product Security Engineer to work hand-in-hand with developers to secure the product across its entire lifecycle. You'll be the person who makes our platform defensible — through design reviews, threat modeling, hands-on penetration testing, and secure-coding partnership — and you'll do it as a collaborator who helps engineers ship securely, not a gatekeeper who slows them down.
This role partners closely with product engineering and platform engineering teams.
What You'll Do
- Partner directly with developers to secure the product across the Software Development Life Cycle (SDLC), embedding security early rather than bolting it on at the end.
- Lead security design and architecture reviews, and run threat modeling on new features and services.
- Perform hands-on penetration testing of web applications and Application Programming Interfaces (APIs), and translate findings into clear, prioritized, fixable work.
- Conduct secure code reviews and help define secure-coding standards and security acceptance criteria.
- Operate and tune Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and dependency / supply-chain scanning, and triage what they surface.
- Help engineers understand the "why" behind findings so the same class of issue doesn't recur.
- Contribute security evidence and rigor to our compliance posture (System and Organization Controls 2, or SOC 2, ISO 27001, etc.).
What You'll Need (Required)
- A strong track record in product or application security — you've measurably made real products more secure.
- Hands-on penetration testing experience against web applications and APIs.
- Deep understanding of how modern web applications work — single-page front ends, APIs, authentication and authorization (for example, OAuth 2.0 / OpenID Connect), sessions, and the common ways each is attacked (for example, the Open Worldwide Application Security Project, or OWASP, Top 10).
- Experience running security design reviews and threat modeling.
- Solid understanding of the SDLC and how to embed security into it.
- Strong communication skills — you work directly with developers and can explain risk in terms they'll act on.
Nice to Have
- Familiarity with open-source security tooling (for example, OWASP ZAP and Burp Suite Community Edition for testing, Semgrep for SAST, Trivy or Grype for dependency and container scanning, Nuclei for templated scanning).
- A relevant offensive-security certification (for example, Offensive Security Certified Professional, or OSCP).
- Cloud security experience (Amazon Web Services, Microsoft Azure, or Google Cloud Platform) and container / Kubernetes security.
- Experience supporting a SOC 2, International Organization for Standardization (ISO) 27001, or similar program.
- Background in enterprise or regulated environments where deployment security is non-negotiable.
What Success Looks Like (First 90 Days)
- You've reviewed the product's architecture and threat surface and identified the highest-priority security risks.
- A repeatable, lightweight process exists for security design reviews on new work.
- Security findings have a clear triage-to-remediation path, and developers know how to engage you early.
Location and Work Model
Remote in Brazil
Similar roles you might like
See all →TL
Technical GRC Analyst (Compliance & Assurance)
Tessera Labs
Salary not disclosedPosted today
BT
Incident Response Analyst
BRT TREND MICRO DO BRASIL LTDA
Salary not disclosedPosted today
BP
Analista de IAM
BTG Pactual
Salary not disclosedPosted today
R
Cyber Security Analyst II
RecargaPay
Salary not disclosedPosted today
T
Senior IAM / Identity Governance Analyst - Construction Technology (Short-Term)
Truelogic
Salary not disclosedPosted today
OP
Cybersecurity Manager (BR118-CSEC)
OKTO PAYMENTS
Salary not disclosedPosted today
E
Consulting Systems Engineer
Edel
Salary not disclosedPosted 1 day ago
M
Security Operations Analyst
Megaport
Salary not disclosedPosted 1 day ago
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
