Senior Security Engineer | AppSec
Your wellbeing, our mission. Join a company shaping a healthier world.
GET TO KNOW US
At Wellhub we're revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.
We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.
Join us in redefining the future of wellbeing!
THE OPPORTUNITY
We are hiring a Senior Security Engineer| AppSec to our Information Security team in Brazil ! This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.
The Information Security team is responsible for protecting our global subscription platform serving millions of users. As a Senior Security Engineer, you will drive software security across our product verticals — starting with application security (secure SDLC, SAST/DAST, secure design reviews) and expanding into adjacent domains like detection engineering, IAM, and vulnerability management. This is a unique opportunity to help build a security engineering program from the ground up in a high-growth environment. You will own a control domain end-to-end in a role that is deliberately generalist — we are looking for someone who reasons deeply about root causes and partners closely with engineering teams to embed security seamlessly into product delivery.
YOUR IMPACT
-
Own core application security services, security tooling (e.g., SAST/DAST, IAM, vulnerability management), and detection pipelines end-to-end.
-
Lead post-incident responses and post-mortems, transforming root-cause findings into concrete guardrails, automation, and policy improvements.
-
Drive security-by-design standards across product development by writing clear RFCs, threat models, and architectural design docs for high-risk projects.
-
Establish and enforce vulnerability remediation SLAs and security metrics, utilizing monitoring tools to hold engineering teams accountable.
-
Execute seamless security-critical migrations and platform updates while preserving data integrity and auditability throughout.
-
Partner with cross-functional teams (Engineering, Legal, Product) to deliver medium-to-large security initiatives while maintaining transparency as scope evolves.
Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life balance.
WHO YOU ARE
- An experienced security engineer with prior work experience delivering high-impact security tooling, detection logic, or secure SDLC mechanisms in modern cloud environments.
- An adaptable and collaborative professional with a willingness to step outside your primary AppSec focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
- A proactive technical partner with extensive experience in modern cloud architectures and container ecosystems (e.g., AWS/EKS, GCP/GKE, Istio, ArgoCD).
- A clear, empathetic communicator with fluency in English and Portuguese, able to translate complex technical security risks into actionable guidance for engineers and non-technical stakeholders alike.
- A pragmatic problem-solver with the ability to balance rigorous security standards against product velocity, making data-informed trade-off decisions.
- A developer at h