Application Security Engineer

Latin America-Brazil-São Paulo-São Paulo

Kenvue

Everyday care is a powerful catalyst in making you feel better, inside and out. Learn about the iconic brands, products, people, and history that make up Kenvue.

View all jobs at Kenvue

Apply now Apply later

Application Security Engineer-2507033261W

Description

 

Kenvue is currently recruiting for:

Application Security Engineer

This role is based in Brazil, part of a global team, and reports to the Director, Application & Cloud Security & xDLC.

Who We Are

At Kenvue, we realize the extraordinary power of everyday care. Built on over a century of heritage and rooted in science, we’re the house of iconic brands - including NEUTROGENA®, AVEENO®, TYLENOL®, LISTERINE®, JOHNSON’S® and BAND-AID® that you already know and love. Science is our passion; care is our talent. Our global team is made up of 22,000 diverse and brilliant people, passionate about insights, innovation and committed to deliver the best products to our customers. With expertise and empathy, being a Kenvuer means to have the power to impact life of millions of people every day. We put people first, care fiercely, earn trust with science and solve with courage – and have brilliant opportunities waiting for you! Join us in shaping our future–and yours.

What You Will Do

As an Application Security Engineer, you will be safeguarding digital assets and data through advanced cybersecurity solutions and processes. We are seeking a highly motivated and talented Application Security Senior Engineer to join our dynamic team. If you have a passion for identifying and mitigating security risks in applications, working with developers, we invite you to apply and be a part of our dedicated cybersecurity workforce.

Key Responsibilities:

·        Conduct comprehensive architecture security reviews of applications to identify vulnerabilities and weaknesses.

·        Secure cloud-native services, including container orchestration platforms like Kubernetes.

·        Maintain and operate various security tools SAST, DAST, CWPP, CSPM, SSPM, CASB...

·        Perform penetration testing, code reviews, and vulnerability scanning to ensure the security of web and mobile applications.

·        Collaborate with development teams to provide guidance on secure coding practices and assist in the remediation of identified security issues, or misconfigurations.

·        Develop and maintain security standards, policies, procedures, work instructions and requirements related to application security.

·        Stay current with the latest security trends, threats, and vulnerabilities affecting application security.

·        Participate in incident response and security incident investigations related to application security.

·        Work closely with cross-functional teams to integrate security into the technology development lifecycle.

·        Automate vulnerability scanning, and compliance checks into development workflows.

·        Proficiency in cloud eco-systems such as AWS, GCP or Azure.

·        Knowledge of DNS and IP management

·        Develop, maintain and run security automation scripts using languages such as python or other software and scripting languages.

·        Knowledge of source code systems such as Bitbucket or GitHub.

Qualifications

 

What We Are Looking For

Required Qualifications

 

·        Bachelor’s degree in computer science, Information Security, or related field or 5+ years of cyber security experience.

·        Advanced English Level (C1 minimum)

·        Working experience with application security assessments, vulnerability testing, and secure code reviews.

·        Knowledge of web application security vulnerabilities and common attack vectors (e.g., OWASP Top 10).

·        Experience with security assessment tools such as Burp Suite, Nessus, OWASP ZAP, Snyk, etc.

·        Understanding of encryption technologies, authentication mechanisms, and secure coding practices.

·        5+ years’ experience in software development/engineering with programming/scripting skills in languages like Java, Python, Ruby, or similar languages.

·        Experience with roles, processes, and tools to enable a high-performing DevOps practice in an Agile environment.

·        Strong knowledge of Kubernetes and containerization (Docker).

·        Relevant security certifications such as CISSP, CEH, CompTIA Security+, Azure Security Engineer, and AWS certified – Security Specialty, and Cloud are a plus.

·        Excellent problem-solving and analytical skills, along with effective communication and teamwork abilities.

·        Experience leading a small team and facilitating stand-up meetings.

·        Strategic thinking to align security goals with business objectives.

·        Experience with Atlassian tools such as Jira, Confluence, and Bitbucket.

·        Knowledge of either Azure or AWS cloud platforms and associated security standards and best practices.

·        Strong knowledge of software development tools such as IDEs, security, and code quality tools.

 

Desired Qualifications

 

·        Mobile application development a plus

 

What’s In It For You

 

·        Competitive Benefit Package

·        Paid Company Holidays, Paid Vacation, Volunteer Time & More!

·        Learning & Development Opportunities

·        Employee Resource Groups 

·        This list could vary based on location/region

Kenvue is proud to be an Equal Opportunity Employer.  All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

 

 

Primary Location

 Latin America-Brazil-São Paulo-São Paulo

Job Function

 Information Security
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0

Tags: Agile Application security Automation AWS Azure Bitbucket Burp Suite CASB CEH CISSP Cloud Compliance CompTIA Computer Science Confluence CSPM DAST DevOps DNS Docker Encryption GCP GitHub Incident response Java Jira Kubernetes Nessus OWASP Pentesting Python Ruby SAST Scripting Security assessment Vulnerabilities

Perks/benefits: Career development

Regions: North America South America
Country: Brazil

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.