Product Security Engineer (remote in Brazil)
Sign up free to see how well your resume matches this role.
What you'll do
- Conduct regular security assessments and code reviews to identify vulnerabilities and ensure compliance with security standards.
- Develop and maintain threat models for products, understanding potential threats and devising strategies to mitigate them.
- Integrate security practices into the software development lifecycle, ensuring that security is considered at each stage of development.
- Identify, assess, and coordinate the remediation of vulnerabilities within products. This includes staying up-to-date with the latest security threats and trends.
- Implement and maintain security tools and automation systems to streamline security processes for product security
- Participate in incident response activities, helping to manage and mitigate security incidents related to the product.
- Provide training and guidance to development teams on best practices in secure coding and product design.
- Ensure products comply with relevant industry security standards and regulations.
- Work closely with engineering, product management, and other teams to ensure security is a key consideration in all aspects of product development and deployment.
- Stay abreast of the latest security research, technologies, and methods to continuously improve product security.
- Conduct risk analysis to understand the impact of potential security threats and develop risk management strategies.
- Develop and enforce security policies and procedures related to product development and maintenance.
What they're looking for
- Bachelor’s degree in information security, information systems, or similar experience preferred
- Relevant field or experience in IT and infosec.
- Experience working in AWS and with Terraform
- Has strong understanding of information security, including a broad range of exposure to cloud infrastructure, systems analysis and application development, vulnerability scanning, policies and procedures, and audits.
- Experience with cloud computing environments including infrastructure as code, containers and functions.
- Strong knowledge of CWE top 25 and OWASP top 10 vulnerabilities
- Understanding of MITRE ATT&CK matrix
- Experience with code development and can read and understand source code in several programming languages such as Ruby, PHP, Go, JS, Python.
- Automated and Manual Web, Mobile and Traditional application pentesting experience
- Experience with scripting and building automations leveraging tools such as Python and tools such as Claude Code
- Experience leveraging AI in your security testing workflows and processes
- Have a strong networking and security understanding
Nice to have
- Security certification such as OSWE, OSCP, CISSP, GPEN, CEH, CCSP, AWS desired.
Summarised by NextRaise from the employer’s description, which follows in full below.
Full description from employer
KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15-years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.
Please submit your resume in English.
To learn more about our team and office culture in São Paulo, Brazil, visit the following links.
Careers Page: https://www.knowbe4.com/careers/locations/sao-paulo
Glassdoor: https://www.glassdoor.com/Location/KnowBe4-S%C3%A3o-Paulo-Location-EI_IE969384.0,7_IL[…]M_-C1lsxoZq7Cx8IriVE8MkrzuTmnJzqego77RAWZz9sqGt_55BflwYKpQeg
LinkedIn: https://www.linkedin.com/company/knowbe4/life/brazil/
Responsibilities:
- Application Security Testing & Pentesting: Conduct automated and manual security assessments and penetration tests across web, mobile, and traditional applications.
- Code Security Reviews: Analyze source code across multiple programming languages to identify vulnerabilities and guide remediation before and after production deployment.
- Vulnerability Triage & Remediation: Work closely with engineering teams to assess, prioritize, and resolve application vulnerabilities.
- Threat Modeling & Automation: Maintain threat models and build security automations to streamline security testing workflows.
- Security Engagement: Partner with product and development teams to embed secure coding practices throughout the software development lifecycle (SDLC).
Requirements:
- Experience in Application Security, Penetration Testing, or Red Teaming.
- Pentesting Expertise: Strong hands-on experience with both automated and manual web, mobile, and traditional application pentesting
- Code Comprehension: Proven ability to read and analyze source code in multiple languages (such as Ruby, PHP, Go, JavaScript, or Python)
- Security Fundamentals: Broad understanding of web application vulnerabilities (e.g., OWASP Top 10, CWE) and core information security concepts
- Language & Communication: Strong technical English communication skills (written and spoken) to collaborate smoothly across international teams
- Cultural Fit: Collaborative, open mindset with a strong focus on teamwork and positive team dynamics
Preferred / Nice-to-Have
- Experience with cloud computing environments (AWS, Terraform)
- Familiarity with security tools (e.g., Burp Suite, SAST/DAST, dependency scanning)
- Experience with Python scripting or leveraging AI tools in security workflows
- Relevant industry certifications (e.g., OSCP, OSWE, GPEN, CISSP)
Our Fantastic Benefits
Note: An applicant assessment and background check may be part of your hiring procedure.
Individuals seeking employment at KnowBe4 are considered without prejudice to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, sexual orientation or any other characteristic protected under applicable federal, state, or local law. If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please visit www.knowbe4.com/careers/request-accommodation.
No recruitment agencies, please.
Company
Company facts come from this company's own listings. We only show what the postings themselves carry.