高级安全工程师 | AppSec
Staff Security Engineer | AppSec
**你的健康,我们的使命。加入一家塑造更健康世界的公司。**
**了解我们**
在Wellhub,我们正在革新职场健康。我们的平台将全球员工与最佳的健身、正念、心理咨询、营养和睡眠合作伙伴连接在一起,所有服务都包含在一个简单的订阅中。总部位于纽约市,团队成员遍布欧洲、北美洲和南美洲,我们致力于让每家公司都成为健康公司。
我们相信工作应该是充实、鼓舞人心且平衡的。在这里,你会遇到一个重视健康、协作和多元视角的团队,激情与创造力推动边界,创造真正的影响力。你的贡献将帮助你和全球数百万人打造一个更健康、更平衡的世界。
**加入我们,重新定义健康的未来!**
**职位机会**
我们正在巴西招聘一名**资深安全工程师 | 应用安全(AppSec)**,加入我们的**信息安全团队**!这是一份**远程 – 巴西**职位,意味着你可以在全国任何地方工作。请注意,该职位仅对巴西的候选人开放。
信息安全团队负责保护我们面向全球数百万用户的订阅制产品。作为资深安全工程师,你将全面负责多个安全领域——你的核心在软件安全(安全的SDLC、漏洞管理、威胁建模、渗透测试和红队演练),同时根据团队的职责范围,跨领域涉及事件响应、威胁情报、云安全和合规性。
你将成为组织中处理最复杂、跨领域安全权衡问题的权威人物——那些没有明确负责人的挑战。通过将渗透测试结果、事件根本原因、合规要求和云配置错误整合到统一的风险策略中,你将制定基础安全标准,指导工程团队,并推动与我们成长相匹配的中大型战略项目。
**你的影响**
- **全面负责**多个安全领域,作为整个组织中复杂、跨服务安全挑战的技术权威。
- **建立**以安全为设计标准的架构,领导威胁建模会议,并设定其他工程师遵循的安全编码基准。
- **主导**复杂的跨服务事件响应和事后分析,将关键发现转化为系统性的防护措施和平台级预防方案。
查看英文原文
**Your wellbeing, our mission. Join a company shaping a healthier world.**
**GET TO KNOW US**
At Wellhub we're revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.
We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.
**Join us in redefining the future of wellbeing!**
**THE OPPORTUNITY**
We are hiring a **Staff Security Engineer | AppSec** to our **Information Security team** in **Brazil!** This is a **Remote – Brazil** position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.
The Information Security team is responsible for protecting our subscription-based product serving millions of users globally. As a Staff Security Engineer, you will own multiple security domains end-to-end — with your center of gravity in software security (secure SDLC, vulnerability management, threat modeling, pentesting, and red teaming) while reaching across incident response, threat intelligence, cloud security, and compliance as the team's mandate requires.
You will become the organization's go-to authority for the hardest, cross-domain security trade-offs — the ones without an obvious owner. By connecting pentest findings, incident root causes, compliance requirements, and cloud misconfigurations into a unified risk strategy, you will shape baseline security standards, mentor engineering teams, and drive medium-to-large strategic initiatives that scale with our growth.
**YOUR IMPACT**
- **Own** multiple security domains end-to-end, serving as the technical authority for complex, cross-service security challenges across the entire organization.
- **Establish** secure-by-design architectural standards, lead threat modeling sessions, and set the secure-coding benchmarks that other engineers follow.
- **Drive** complex, cross-service incident responses and post-mortems, converting critical findings into systemic guardrails and platform-level preventions.
- **Lead** offensive and defensive strategy initiatives—including Red Team exercises and pentest engagements—driving root-cause remediation directly with engineering teams.
- **Ensure** organization-wide security posture by setting SLAs, SLOs, and KPIs (remediation windows, response times, posture drift), building the monitoring needed to hold teams accountable.
- **Partner with** cross-functional leadership (Engineering, Product, Legal) to align threat intelligence, compliance needs, and long-term security investments with business priorities.
_Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life wellness._
**WHO YOU ARE**
- A seasoned security specialist with **extensive experience in** Security Engineering (or software engineering with high security impact) and a proven track record of scaling security in complex cloud environments.
- An adaptable professional with a **willingness to** step outside your primary focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
- A strategic technical partner with **expert knowledge** in secure architecture design, threat modeling, and setting engineering-wide secure coding standards.
- An influential communicator with **fluency in** English and Portuguese, **able to** translate intricate security tradeoffs into clear risk statements for executive leadership and product partners.
- A pragmatic risk navigator with the **ability to** balance long-term risk reduction against business velocity, making high-stakes decisions independently.
- A forward-thinking specialist with a **deep understanding of** attacker TTPs, modern cloud ecosystems (AWS/EKS, GCP/GKE, Istio, ArgoCD), and regulatory frameworks (SOC 2, ISO 27001, LGPD, GDPR).
- A dedicated mentor with **prior work experience** guiding and uplifting engineering teams to foster a security-minded engineering culture.
_We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don't match the job description 100%. We welcome your application and will be delighted to explore if you could be a great fit for our team. For this specific role, please note that prior experience in security engineering is a mandatory requirement._
**WHAT WE OFFER YOU**
With thoughtful benefits, emotional wellbeing resources, and a culture that empowers you to take ownership of your role and your wellbeing, we create an environment where you can thrive in all dimensions of your life.
Our flexible benefits program allows you to customize some of the benefits, according to your needs!
**Our benefits include:**
**WELLHUB:** Free Gold+ membership with access to onsite gyms and studios, digital fitness programs, and online wellness resources for meditation, nutrition, mental wellbeing support, and more! Add up to three family members to your plan, ensuring access to wellness for those who matter most to you.
**WELLZ:** A complete emotional wellbeing program with a unique approach. It offers personalized journeys that combine individual therapy sessions (52 per year) and on-demand content.
**HEALTHCARE:** Health, dental, and life insurance.
**FLEXIBLE WORK:** As a Flexible First company, we offer hybrid and remote options to give you the freedom to work in a way that suits you. The model for this specific role can be discussed with your recruiter and hiring manager. When you join, use our home office reimbursement to set up your home office.
**PAID TIME OFF:** It’s important to take time away from work to recharge.Employees receive vacations after 6 months and additional 3 days off per year + 1 day off for each year of tenure (up to 5 additional days) + an extra holiday for your birthday!
**PAID PARENTAL LEAVE:** Welcoming a new child is one of the most special moments in your life. Take the time to be present and enjoy your growing family. We offer 100% paid parental leave to all new parents. Parents giving birth are eligible for an extended leave and a ramp-back period to return part-time while they get settled.
**CAREER GROWTH:** Access world-class platforms, participate in interactive sessions, build your personalized development roadmap, and explore internal opportunities. We focus on continuous learning and feedback to support your journey toward personal and professional success.
**CULTURE:** You’ll join a team of passionate people who come together to break boundaries, support each other, and create a meaningful impact in workplace wellness. We win together, building trust through open communication and a culture where every perspective matters. [Learn more about our shared culture and values here.](https://wellhub.com/en-us/careers/our-values/)
**Want to see what it’s really like to work here? Follow us on** [**Instagram**](https://www.instagram.com/lifeatwellhub/) **@lifeatwellhub and watch our team video on** [**YouTube**](https://www.youtube.com/watch?v=ZgIPiszTVm4) **!**
**Diversity, Equity, and Belonging at Wellhub**
We aim to create a collaborative, supportive, and inclusive space where everyone knows they belong.
Wellhub is committed to creating a diverse work environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex, gender identity or expression, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law.
Our commitment to inclusion also extends to how we recognize and reward our people. We’re proud to be Syndio Fair Pay Certified, reflecting our ongoing dedication to equitable and fair pay practices across our global team. [Read more about it here.](https://www.linkedin.com/posts/wellhub_fairpay-syndio-activity-7407826561531363328-wbN_?utm_source=share&utm_medium=member_desktop&rcm=ACoAAAzHQWABKsRqcpvxy4QpDCJNe_szRdC4hgY)
Questions on how we treat your personal data? See our [Aviso de Privacidade para Candidatos.](https://wellhub.com/en-us/careers/job-applicant-privacy-notice/#:~:text=Aviso%20de%20Privacidade%20para%20Candidatos)
**#LI-REMOTE**
#LI-CM1