Senior AppSec Architect

Stone

Completely RemoteFull TimeInformation Technology
Posted 2 days ago

Job description

Responsibilities

  • Define and implement security strategies for applications, including those integrating LLMs and generative AI components
  • Collaborate with development teams to integrate security practices throughout the software lifecycle
  • Perform architecture, code, and design reviews to identify potential vulnerabilities
  • Define guardrails and standards for LLM applications, addressing risks like prompt injection and data leakage
  • Establish guidelines for the secure use of AI-assisted development tools
  • Develop and promote security standards and best practices across the development team
  • Provide technical guidance and security training to engineering teams
  • Utilize CI/CD validation tools such as SAST, DAST, SCA, and Secret Scanning
  • Monitor emerging security threats, including those targeting AI systems
  • Develop creative solutions for complex security problems that balance business needs and risks

Requirements

  • Degree in Information Security, Computer Science, Software Engineering, or related fields
  • Knowledge of common attack vectors
  • Experience in threat modeling
  • Experience in protection mechanisms for APIs and mobile applications
  • Knowledge of Cloud security concepts (AWS, Azure, or GCP)
  • Familiarity with security risks in LLM and generative AI applications (OWASP Top 10 for LLM, MITRE ATLAS)
  • Ability to work autonomously and within agile multidisciplinary teams
  • Proficiency in reading and communicating in English

Preferred Qualifications

  • Experience in incident response and root cause analysis
  • Experience with financial sector requirements (Bacen, PCI, SOX)
  • Strong programming skills
  • Practical experience in defining controls for production LLM applications (chatbots, agents, RAG)
  • Knowledge of AI governance frameworks (NIST AI RMF, ISO/IEC 42001)

About the Company

Stone is a technology and financial services company focused on the customer, aiming to be a protagonist in the transformation of the Brazilian payments industry.

Skills & tools

AppSecLLMAWS

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 01Degree in IT or related field
  2. 02Threat modeling experience
  3. 03API and mobile security experience
  4. 04Cloud security knowledge (AWS/Azure/GCP)
  5. 05LLM security familiarity
  6. 06English proficiency
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches