高级安全工程师 | AppSec
Senior Security Engineer | AppSec
**你的健康,我们的使命。加入一家塑造更健康世界的企业。**
**了解我们**
在Wellhub,我们正在革新职场健康。我们的平台将全球员工与最佳的健身、正念、心理咨询、营养和睡眠合作伙伴连接在一起,所有服务都通过一个简单的订阅实现。我们总部位于纽约,团队成员遍布欧洲、北美和南美,我们的使命是让每家公司都成为健康公司。
我们相信工作应该是充实、激励和平衡的。在这里,你会遇到一个重视健康、协作和多元视角的团队,激情与创造力推动边界,创造真正的影响力。你的贡献将帮助塑造一个更健康、更平衡的世界,惠及你和全球数百万人。
**加入我们,重新定义健康的未来!**
**职位机会**
我们正在巴西招聘一名**高级安全工程师| 应用安全**,加入我们的**信息安全团队**!这是一份**远程 – 巴西**的职位,意味着你可以在全国任何地方工作。请注意,该职位仅对巴西的候选人开放。
信息安全团队负责保护我们服务于数百万用户的全球订阅平台。作为高级安全工程师,你将推动我们产品线中的软件安全——从应用安全(安全的SDLC、SAST/DAST、安全设计评审)开始,并扩展到检测工程、身份和访问管理(IAM)以及漏洞管理等相邻领域。这是一个独特的机会,在高速增长的环境中从零开始构建安全工程计划。你将全面负责一个控制领域,这个职位有意设计为通才角色——我们寻找的是能够深入分析根本原因,并与工程团队紧密合作,将安全无缝嵌入产品交付的人。
**你的影响**
- **全面负责**核心应用安全服务、安全工具(如SAST/DAST、IAM、漏洞管理)和检测流程。
- **主导**事件后的响应和复盘,将根本原因发现转化为具体的防护措施、自动化和政策改进。
- **推动**安全设计标准在产品开发中的实施,通过撰写清晰的RFC、威胁模型和高风险项目的架构设计文档。
- **建立并执行**漏洞修复SLA和安全指标,利用监控工具确保工程团队承担责任。
查看英文原文
**Your wellbeing, our mission. Join a company shaping a healthier world.**
**GET TO KNOW US**
At Wellhub we're revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.
We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.
**Join us in redefining the future of wellbeing!**
**THE OPPORTUNITY**
We are hiring a **Senior Security Engineer| AppSec** to our **Information Security team** in **Brazil**! This is a **Remote – Brazil** position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.
The Information Security team is responsible for protecting our global subscription platform serving millions of users. As a Senior Security Engineer, you will drive software security across our product verticals — starting with application security (secure SDLC, SAST/DAST, secure design reviews) and expanding into adjacent domains like detection engineering, IAM, and vulnerability management. This is a unique opportunity to help build a security engineering program from the ground up in a high-growth environment. You will own a control domain end-to-end in a role that is deliberately generalist — we are looking for someone who reasons deeply about root causes and partners closely with engineering teams to embed security seamlessly into product delivery.
**YOUR IMPACT**
- **Own** core application security services, security tooling (e.g., SAST/DAST, IAM, vulnerability management), and detection pipelines end-to-end.
- **Lead** post-incident responses and post-mortems, transforming root-cause findings into concrete guardrails, automation, and policy improvements.
- **Drive** security-by-design standards across product development by writing clear RFCs, threat models, and architectural design docs for high-risk projects.
- **Establish** and enforce vulnerability remediation SLAs and security metrics, utilizing monitoring tools to hold engineering teams accountable.
- **Execute** seamless security-critical migrations and platform updates while preserving data integrity and auditability throughout.
- **Partner with** cross-functional teams (Engineering, Legal, Product) to deliver medium-to-large security initiatives while maintaining transparency as scope evolves.
_Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life balance._
**WHO YOU ARE**
- An experienced security engineer with **prior work experience** delivering high-impact security tooling, detection logic, or secure SDLC mechanisms in modern cloud environments.
- An adaptable and collaborative professional with a **willingness to** step outside your primary AppSec focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
- A proactive technical partner with **extensive experience in** modern cloud architectures and container ecosystems (e.g., AWS/EKS, GCP/GKE, Istio, ArgoCD).
- A clear, empathetic communicator with **fluency in** English and Portuguese, **able to** translate complex technical security risks into actionable guidance for engineers and non-technical stakeholders alike.
- A pragmatic problem-solver with the **ability to** balance rigorous security standards against product velocity, making data-informed trade-off decisions.
- A developer at heart with **in-depth knowledge** of secure coding practices, proficient in writing clean, well-tested code for security automation.
- A security champion with **familiarity with** key governance and compliance frameworks (e.g., SOC 2, ISO 27001, LGPD/GDPR) to inform daily engineering decisions.
_We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don't match the job description 100%. We welcome your application and will be delighted to explore if you could be a great fit for our team. For this specific role, please note that prior experience in security engineering is a mandatory requirement_ _._
**WHAT WE OFFER YOU**
With thoughtful benefits, emotional wellbeing resources, and a culture that empowers you to take ownership of your role and your wellbeing, we create an environment where you can thrive in all dimensions of your life.
Our flexible benefits program allows you to customize some of the benefits, according to your needs!
**Our benefits include:**
**WELLHUB:** Free Gold+ membership with access to onsite gyms and studios, digital fitness programs, and online wellness resources for meditation, nutrition, mental wellbeing support, and more! Add up to three family members to your plan, ensuring access to wellness for those who matter most to you.
**WELLZ:** A complete emotional wellbeing program with a unique approach. It offers personalized journeys that combine individual therapy sessions (52 per year) and on-demand content.
**HEALTHCARE:** Health, dental, and life insurance.
**FLEXIBLE WORK:** As a Flexible First company, we offer hybrid and remote options to give you the freedom to work in a way that suits you. The model for this specific role can be discussed with your recruiter and hiring manager. When you join, use our home office reimbursement to set up your home office.
**PAID TIME OFF:** It’s important to take time away from work to recharge.Employees receive vacations after 6 months and additional 3 days off per year + 1 day off for each year of tenure (up to 5 additional days) + an extra holiday for your birthday!
**PAID PARENTAL LEAVE:** Welcoming a new child is one of the most special moments in your life. Take the time to be present and enjoy your growing family. We offer 100% paid parental leave to all new parents. Parents giving birth are eligible for an extended leave and a ramp-back period to return part-time while they get settled.
**CAREER GROWTH:** Access world-class platforms, participate in interactive sessions, build your personalized development roadmap, and explore internal opportunities. We focus on continuous learning and feedback to support your journey toward personal and professional success.
**CULTURE:** You’ll join a team of passionate people who come together to break boundaries, support each other, and create a meaningful impact in workplace wellness. We win together, building trust through open communication and a culture where every perspective matters. [Learn more about our shared culture and values here.](https://wellhub.com/en-us/careers/our-values/)
**And to get a glimpse of life at Wellhub… Follow us on** [**Instagram**](https://www.instagram.com/lifeatwellhub/) **@lifeatwellhub** **and** [**LinkedIn**](https://www.linkedin.com/company/wellhub/) **!**
**Diversity, Equity, and Belonging at Wellhub**
We aim to create a collaborative, supportive, and inclusive space where everyone knows they belong.
Wellhub is committed to creating a diverse work environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex, gender identity or expression, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law.
Our commitment to inclusion also extends to how we recognize and reward our people. We’re proud to be Syndio Fair Pay Certified, reflecting our ongoing dedication to equitable and fair pay practices across our global team. [Read more about it here.](https://www.linkedin.com/posts/wellhub_fairpay-syndio-activity-7407826561531363328-wbN_?utm_source=share&utm_medium=member_desktop&rcm=ACoAAAzHQWABKsRqcpvxy4QpDCJNe_szRdC4hgY)
Questions on how we treat your personal data? See our [Aviso de Privacidade para Candidatos.](https://wellhub.com/en-us/careers/job-applicant-privacy-notice/#:~:text=Aviso%20de%20Privacidade%20para%20Candidatos)
**#LI-REMOTE**
#LI-CM1