Quick Summary
About Clicksign
We are a leading Brazilian company in electronic signatures. We facilitate digital relationships between people and businesses. Our mission, backed by cutting-edge technology and a focus on security, is to foster global growth by making digital interactions smarter.
How We Work
Our core value is Trust. We operate with focus, clear communication, and data-driven decisions. We are meticulous, ensuring quality in every task. Empathy and respect are fundamental to our team culture.
Job Description
We are seeking an AppSec (Application Security) Specialist with robust experience in Information Security, Application Security, and secure software development. If you excel at identifying vulnerabilities, performing code reviews, and enhancing application security, and are eager to collaborate with Engineering teams to propose and implement product security improvements, this is your opportunity! You will join a team dedicated to ensuring product security from the development phase, reviewing, evaluating, and writing code to prevent vulnerabilities and elevate application security standards. This is a collaborative, remote role.
Responsibilities and Attributions
- Evaluate technical vulnerabilities and propose solutions to enhance platform security, working with our stack (Ruby, Go, and PHP) and developing security fixes in AWS/Lambda.
- Agilely assess development queue demands, reducing AppSec bottlenecks and accelerating Engineering deliveries.
- Actively propose and implement code fixes, moving beyond mere identification of security findings.
- Conduct threat modeling and apply secure-by-design principles in product initiatives.
- Create security guardrails, tooling, and automations to establish the secure path as the default for Engineering teams.
- Integrate and calibrate security tools within the CI/CD pipeline (SAST, SCA, and secret scanning), ensuring minimal noise and false positives.
Requirements and Qualifications
- Experience in software or security engineering, including writing and delivering production code (ideally Ruby and PHP), and developing automations in AWS/Lambda.
- Proven experience with Application Security/Product Security: threat modeling, secure-by-design methodologies, and the creation of guardrails and tooling.
- Solid knowledge of CI/CD pipeline security, with expertise in calibrating SAST, SCA, and secret scanning tools.
- Knowledge of AWS cloud security as applied to product development.
- Information security certifications are desirable.
- Strong ability to collaborate effectively with Engineering teams, proposing and implementing code corrections directly, rather than solely communicating findings.
- Proficiency in English communication (written and spoken).
Additional Information
What You Can Expect From Us:
- 100% remote work.
- A culture of trust, focused on results, offering significant challenges and learning opportunities.
- Autonomy and ownership in a collaborative and empathetic environment.
- A strong feedback culture and regular 1:1s with human-centric leadership, free from micromanagement.
- Comprehensive benefits package including: meal/food vouchers, childcare assistance, home office allowance, health, education, and culture benefits, Gympass, birthday day-off, discounts on therapy and English courses, among other partnerships.


