Product Security Engineer - Remote Work
External job listingat INDI Staffing Services
Product Security Engineer role focused on hands-on SAST triage, secure code review, evidence-based findings, and vulnerability remediation.
Salary
Not provided
Location
Rio de Janeiro, Brazil
Employment type
Full time
Workplace
Not provided
Product Security Engineer - Remote Work
Rio de Janeiro, Brazil
Job description
INDI Staffing Services connects leading companies with top talent and describes a dynamic environment where innovation thrives.
About the role
The Product Security Engineer role focuses on hands-on static analysis triage. Triage quality shapes how risk is understood and remediated across the product.
Responsibilities
- Perform hands-on SAST triage as the primary daily activity.
- Conduct source-to-sink analysis and secure code review across real codebases.
- Disposition findings with evidence-based documentation in a regulated environment.
- Tune static analysis tools and manage false positive rates across the product portfolio.
- Partner with engineering teams to validate and drive remediation of confirmed vulnerabilities.
Requirements
- 5+ years of hands-on experience in product security, application security, or software engineering with a security focus.
- Proven SAST triage experience beyond tool integration or pipeline configuration.
- Strong source-to-sink data flow analysis and secure code review skills.
- Experience operating tools such as Checkmarx, Fortify, Veracode, or Coverity at the findings level.
- Ability to produce audit-traceable documentation of finding dispositions in compliance-driven environments.
- Advanced level of English.
Benefits
- Flexibility to choose where and how you work.
- Tailored compensation to suit your financial goals.
- Access to tech-driven tools for seamless collaboration.
Key facts
- Hands-on SAST triage is the primary daily activity.
- Requires 5+ years of hands-on experience in product security, application security, or software engineering with a security focus.
- Advanced level of English is required.
- Benefits include flexibility, tailored compensation, and tech-driven tools.
Is this your job posting?
Claim it for free and receive video applications on CazVid.
Frequently asked questions
What does the role involve?
The role focuses on hands-on static analysis triage, source-to-sink analysis, and secure code review. It also involves documenting findings and driving remediation of confirmed vulnerabilities.
What experience and skills are required?
The listing requires 5+ years of hands-on experience in product security, application security, or software engineering with a security focus. It also asks for SAST triage, code analysis, and advanced English.
What benefits are listed?
Benefits include flexibility to choose where and how you work, tailored compensation, and access to tech-driven tools for collaboration.