cover

AppSec (Application Security) Specialist/ 2 days ago

Clicksign
Attractive
Application ends: 2026-10-22

Quick Summary

Clicksign is hiring a remote AppSec (Application Security) Specialist in Brazil with strong experience in Information Security, Application Security, and secure software development. This role involves collaborating with Engineering teams to enhance product security, evaluating technical vulnerabilities, proposing and implementing code fixes in Ruby, Go, PHP, and AWS/Lambda, and applying secure-by-design principles. Key responsibilities include conducting threat modeling, creating security guardrails and tooling, and integrating/calibrating security tools like SAST, SCA, and secret scanning within CI/CD pipelines. Required qualifications include experience in software/security engineering (Ruby, PHP, AWS/Lambda), proven AppSec/Product Security expertise, solid CI/CD pipeline security knowledge, AWS cloud security, and strong English communication skills.

About Clicksign

We are a leading Brazilian company in electronic signatures. We facilitate digital relationships between people and businesses. Our mission, backed by cutting-edge technology and a focus on security, is to foster global growth by making digital interactions smarter.

How We Work

Our core value is Trust. We operate with focus, clear communication, and data-driven decisions. We are meticulous, ensuring quality in every task. Empathy and respect are fundamental to our team culture.

Job Description

We are seeking an AppSec (Application Security) Specialist with robust experience in Information Security, Application Security, and secure software development. If you excel at identifying vulnerabilities, performing code reviews, and enhancing application security, and are eager to collaborate with Engineering teams to propose and implement product security improvements, this is your opportunity! You will join a team dedicated to ensuring product security from the development phase, reviewing, evaluating, and writing code to prevent vulnerabilities and elevate application security standards. This is a collaborative, remote role.

Responsibilities and Attributions

  • Evaluate technical vulnerabilities and propose solutions to enhance platform security, working with our stack (Ruby, Go, and PHP) and developing security fixes in AWS/Lambda.
  • Agilely assess development queue demands, reducing AppSec bottlenecks and accelerating Engineering deliveries.
  • Actively propose and implement code fixes, moving beyond mere identification of security findings.
  • Conduct threat modeling and apply secure-by-design principles in product initiatives.
  • Create security guardrails, tooling, and automations to establish the secure path as the default for Engineering teams.
  • Integrate and calibrate security tools within the CI/CD pipeline (SAST, SCA, and secret scanning), ensuring minimal noise and false positives.

Requirements and Qualifications

  • Experience in software or security engineering, including writing and delivering production code (ideally Ruby and PHP), and developing automations in AWS/Lambda.
  • Proven experience with Application Security/Product Security: threat modeling, secure-by-design methodologies, and the creation of guardrails and tooling.
  • Solid knowledge of CI/CD pipeline security, with expertise in calibrating SAST, SCA, and secret scanning tools.
  • Knowledge of AWS cloud security as applied to product development.
  • Information security certifications are desirable.
  • Strong ability to collaborate effectively with Engineering teams, proposing and implementing code corrections directly, rather than solely communicating findings.
  • Proficiency in English communication (written and spoken).

Additional Information

What You Can Expect From Us:

  • 100% remote work.
  • A culture of trust, focused on results, offering significant challenges and learning opportunities.
  • Autonomy and ownership in a collaborative and empathetic environment.
  • A strong feedback culture and regular 1:1s with human-centric leadership, free from micromanagement.
  • Comprehensive benefits package including: meal/food vouchers, childcare assistance, home office allowance, health, education, and culture benefits, Gympass, birthday day-off, discounts on therapy and English courses, among other partnerships.

Share

Clicksign

Clicksign

  • Address
    Remoto
View Profile
Your experience on this site will be improved by allowing cookies Cookie Policy