Security Engineer, Mid

ARQ

2h ago 0 views 0 applications
Full-time Hybrid
São Paulo
Competitive
Full-time
Security Engineer

Job Description

Forge the Future of Fintech Security: Founding Security Engineer, Brazil

Are you ready to seize a unique opportunity to define and build the security posture for a rapidly growing fintech leader in Latin America? ARQ is searching for our first Security Engineer based in Brazil to champion our regional security strategy from the ground up. This is your chance to lead, innovate, and shape the future of how ARQ protects its systems and users across a dynamic market.

About the Opportunity
As ARQ's inaugural Security Engineer in Brazil, you won't just be joining a team; you'll be building one. This is a foundational role, empowering you with significant autonomy to establish what "excellent security" looks like locally, collaborating closely with our global security team while driving regional initiatives. We thrive on a multidisciplinary approach, with security spanning Application Security, Security Operations, and Governance, Risk & Compliance. We need a versatile professional comfortable navigating at least two of these critical domains, ready to tackle challenges head-on and define the roadmap for security in Brazil.

Your Core Responsibilities

Lead and contribute to application security efforts, including conducting threat modeling sessions, performing secure code reviews, executing API security testing, and integrating security checks into CI/CD pipelines.
Proactively assess and monitor AI/agentic workflows to identify and mitigate prompt risks, prevent unsafe automated actions, and guard against data exposure.
Design, build, and maintain robust SIEM detection rules, optimize alert pipelines, and develop comprehensive incident response playbooks using our key platforms: Datadog SIEM, CrowdStrike, and Cloudflare. Own the end-to-end detection coverage for designated systems.
Play a pivotal role in incident response, including triaging alerts, executing IR playbooks, and facilitating tabletop exercises to enhance our readiness.
Conduct thorough cloud security assessments across AWS and Kubernetes environments, guided by senior team expertise.
Manage vendor security assessments, applying our established due diligence framework and overseeing the review process for a segment of our vendor pipeline.

What You'll Bring to the Team

2–4 years of progressive experience in information security or a closely related technical discipline (e.g., security operations, cloud/infrastructure engineering with a security focus).
2+ years working within a regulated fintech, banking, or payment company environment.
Demonstrated working experience with at least one major cloud environment (AWS preferred) and familiarity with Kubernetes fundamentals.
Foundational understanding of application security concepts, such as threat modeling, secure code review, or API security testing.
A keen curiosity about the risks associated with AI/agentic tooling (LLM integrations, MCP servers, automated workflows). While not required, prior hands-on experience in this area is a significant plus.
Exposure to SIEM platforms and a genuine interest in detection engineering, evidenced by experience writing or tuning detection rules.
Exceptional written and verbal communication skills in English, essential for collaboration with our global team.

Perks & Benefits

Competitive salary and a comprehensive benefits package designed to support your well-being.
Equity opportunities (stock options) to ensure you share directly in ARQ's success and growth.
Discretionary performance bonuses recognizing your contributions.
Access to the latest cutting-edge tools and technology to empower your work.
Collaborate with a world-class team that will challenge your abilities and foster your professional growth.
Be part of building the best fintech application in Latin America, making a tangible impact.
Our vibrant office environment encourages collaboration, with an in-office policy of 3-4 days a week.