At a Glance Legrand has an exciting opportunity for a Security Engineer III to join the ZPE Systems Team in Blumenau, BR. We are seeking a Security Engineer III to drive application and product security across the ZPE Cloud and Nodegrid product lines. Based in Blumenau and working with engineering teams in Brazil, the United States, and Europe, this role embeds security into the software development lifecycle, facilitates threat modeling and secure design review, and works directly with development teams to identify and remediate vulnerabilities before they reach customers. The primary focus is cloud and web application security, with growing exposure to embedded product security. Main Responsibilities: Application & Product Security Conduct security code reviews and provide practical remediation guidance to development teams Build out, tune, and maintain the SAST, DAST, SCA, and secrets scanning toolchain within CI/CD pipelines Triage vulnerability findings, assign severity, and drive remediation to closure with owning teams Develop secure coding guidelines, reusable patterns, and developer security training material Manage software supply chain risk, including SBOM generation and CVE triage and response Scope and coordinate third-party penetration tests; perform targeted internal assessments Secure Design & Architecture Facilitate threat modeling for new features, services, and system designs Perform security design reviews and document mitigations and accepted risks Develop and maintain security reference architectures and reusable design patterns for product teams Contribute to the design of authentication, authorization, and secrets management for product services Define encryption and key management requirements for product data at rest and in transit Evaluate and recommend application and cloud security tooling Compliance Support Implement and evidence the technical controls required by ISO 27001, SOC 2, and the EU Cyber Resilience Act Provide technical input to customer security questionnaires and RFI/RFP responses Leadership & Collaboration Mentor engineers on secure development practices and help establish a security champions program Contribute to the product security roadmap with Product and Engineering leadership Act as the security point of contact in design and architecture discussions Conduct regular Knowledge Sharing Sessions (KSS) on security topics and emerging threats Communicate effectively across Brazil, US, and EU time zones, in English, written and verbal Profile : 5+ years in security engineering or software engineering, with at least 2 years focused on application or product security Professional working proficiency in English, written and spoken, sufficient for customer-facing documentation and cross-region collaboration; fluent Portuguese Demonstrated experience performing security code review across more than one language Proven experience integrating and tuning security tooling within CI/CD pipelines Experience with threat modeling and secure design review Familiarity with at least one major compliance framework (ISO 27001 or SOC 2) from a control implementation perspective Experience producing technical security documentation for internal and customer audiences Availability for occasional international travel Desirable (not required) Experience helping establish or mature an application security practice Experience with embedded or hardware product security: secure boot, TPM, firmware signing, SBOM Familiarity with EU Cyber Resilience Act, FIPS 140-3, or Common Criteria obligations Certifications such as CompTIA Security+, CISSP, OSCP, CKS, or a cloud security certification; sponsorship available Contributions to open-source security projects, security research, or conference speaking Skills/Knowledge/Abilities: Technical Skills Reading and reviewing application code in Go, Python, or similar; scripting for security automation Cloud security controls and architecture on at least one major provider; GCP preferred Application authentication and authorization: OAuth 2.0, OIDC, SAML, RBAC Applied cryptography: TLS, encryption, hashing, PKI, certificate and key management Container and Kubernetes security, IaC scanning, and policy as code CI/CD platforms such as GitLab CI, Jenkins, GitHub Actions, or ArgoCD Practical experience with SAST, DAST, SCA, and secrets scanning tooling Knowledge Areas OWASP Top 10, OWASP ASVS, and common web and API vulnerability classes Threat modeling frameworks: STRIDE, PASTA, MITRE ATT&CK Secure SDLC practices and DevSecOps methodologies Software supply chain security: SBOM, dependency management, CVE triage Security compliance and regulatory requirements: NIST CSF, CIS Controls, ISO 27001, SOC 2, LGPD Abilities Explain complex security concepts clearly to technical and non-technical audiences Influence engineering teams and drive remediation without direct authority Balance security requirements against business needs and delivery timelines Work autonomously across distributed teams and time zones with strong ownership
Senior Security Engineer (Offensive Security)
Nubank
Senior Security Engineer - Application Security- BR - 2026
Nubank
Lead DevOps Engineer (AWS Migration & Security)
N-iX
Senior Information Security Engineer
Wexinc
Grupo QuintoAndar | Sênior Security Engineer (DataSecurity)
Grupo QuintoAndar
Application Security Engineer - Remote Work | REF
BairesDev