Back to Jobs
Gympass
Development 6h ago

Senior Security Engineer | AppSec

Gympass
BrazilBrazil
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

DevOps1h 38mFree Trial ✹
Start 10-Day Free Trial
Cloud SecurityGCPCybersecurityAWS

Want to know if you're a match for this job?

Calculate My Match Score

We are hiring a Senior Security Engineer | AppSec to our Information Security team in Brazil! This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.

The Information Security team is responsible for protecting our global subscription platform serving millions of users. As a Senior Security Engineer, you will drive software security across our product verticals — starting with application security (secure SDLC, SAST/DAST, secure design reviews) and expanding into adjacent domains like detection engineering, IAM, and vulnerability management. This is a unique opportunity to help build a security engineering program from the ground up in a high-growth environment. You will own a control domain end-to-end in a role that is deliberately generalist — we are looking for someone who reasons deeply about root causes and partners closely with engineering teams to embed security seamlessly into product delivery.

YOUR IMPACT

  • Own core application security services, security tooling (e.g., SAST/DAST, IAM, vulnerability management), and detection pipelines end-to-end.
  • Lead post-incident responses and post-mortems, transforming root-cause findings into concrete guardrails, automation, and policy improvements.
  • Drive security-by-design standards across product development by writing clear RFCs, threat models, and architectural design docs for high-risk projects.
  • Establish and enforce vulnerability remediation SLAs and security metrics, utilizing monitoring tools to hold engineering teams accountable.
  • Execute seamless security-critical migrations and platform updates while preserving data integrity and auditability throughout.
  • Partner with cross-functional teams (Engineering, Legal, Product) to deliver medium-to-large security initiatives while maintaining transparency as scope evolves.

Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life balance.

WHO YOU ARE

  • An experienced security engineer with prior work experience delivering high-impact security tooling, detection logic, or secure SDLC mechanisms in modern cloud environments.
  • An adaptable and collaborative professional with a willingness to step outside your primary AppSec focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
  • A proactive technical partner with extensive experience in modern cloud architectures and container ecosystems (e.g., AWS/EKS, GCP/GKE, Istio, ArgoCD).
  • A clear, empathetic communicator with fluency in English and Portuguese, able to translate complex technical security risks into actionable guidance for engineers and non-technical stakeholders alike.
  • A pragmatic problem-solver with the ability to balance rigorous security standards against product velocity, making data-informed trade-off decisions.
  • A developer at heart with in-depth knowledge of secure coding practices, proficient in writing clean, well-tested code for security automation.
  • A security champion with familiarity with key governance and compliance frameworks (e.g., SOC 2, ISO 27001, LGPD/GDPR) to inform daily engineering decisions.

We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don't match the job description 100%. We welcome your application and will be delighted to explore if you could be a great fit for our team. For this specific role, please note that prior experience in security engineering is a mandatory requirement.

How would you rate this job post?

See what other professionals think about this role.

banner

Gympass is a leading fitness and wellness platform that connects individuals with a wide range of gyms, studios, and fitness classes. Founded with the mission of making fitness accessible to all, Gympass has revolutionized the way people engage in physical activity. By partnering with thousands of gyms and studios worldwide, Gympass provides its users with unparalleled flexibility and choice, allowing them to discover new workouts, try different disciplines, and stay motivated. The platform's user-friendly interface and mobile app enable users to easily find and book classes, track their progress, and access exclusive discounts and promotions. Gympass also offers a variety of wellness programs, including meditation, yoga, and nutrition counseling, catering to the diverse needs of its users. With a strong focus on community building, Gympass fosters a supportive environment where users can connect with like-minded individuals, share their fitness journeys, and celebrate their achievements. By promoting a culture of wellness and inclusivity, Gympass has become a trusted and beloved brand, empowering people to take control of their health and wellbeing. As a pioneer in the fitness technology space, Gympass continues to innovate and expand its offerings, solidifying its position as a leader in the industry.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More