AppSec (Application Security) Specialist

Clicksigngupypublished 09/21/2026
Must-have:RubyPHPAWSCI/CDSecurityRemote
Machine translation — original language: Portuguese.Show original

About Clicksign

We are a leading Brazilian electronic signature company. In essence, we facilitate relationships between people and companies in the digital environment. Behind our cutting-edge technology and focus on security, we have the mission to make the world grow, making digital relationships increasingly intelligent.

How we work:

Our essence is Trust. We work with focus, rhythm, clear communication, and data to support us. We work with craftsmanship; we put care and quality into everything we do. Empathy and respect are pillars of our team.

Job Description:

We are looking for an AppSec (Application Security) Specialist with experience in Information Security, Application Security, and secure development. If you consider yourself a talented professional in identifying vulnerabilities, reviewing code, and strengthening application security, and you are interested in working side-by-side with Engineering teams, proposing and implementing improvements that increase product security, this is your chance! You will be part of the team responsible for ensuring product security from development onwards, reviewing, evaluating, and writing code to prevent vulnerabilities and raise the security level of applications, acting collaboratively and remotely.

Responsibilities and duties

  • Evaluate technical vulnerabilities and propose solutions to raise the security of our platform, working within our stack (Ruby, Go, and PHP) and developing security fixes in AWS/Lambda.
  • Agility in evaluating demands from the development queue, reducing the AppSec bottleneck and unblocking Engineering deliveries.
  • Actively propose and implement code fixes, going beyond merely pointing out findings.
  • Conduct threat modeling and apply secure-by-design principles to product initiatives.
  • Create guardrails, tooling, and automations that make the secure path the default path for Engineering teams.
  • Integrate and calibrate security tools in the CI/CD pipeline (SAST, SCA, and secret scanning), maintaining low levels of noise and false positives.

Requirements and qualifications

  • Experience with software or security engineering writing and delivering production code (ideally Ruby and PHP), including automations in AWS/Lambda.
  • Experience with Application Security/Product Security: threat modeling, secure-by-design, and the creation of guardrails and tooling.
  • Solid knowledge of CI/CD pipeline security, with calibrated SAST, SCA, and secret scanning.
  • Knowledge of AWS cloud security applied to the product.
  • Desirable certifications in the information security area.
  • Strong ability to collaborate with Engineering teams, proposing and implementing fixes directly in the code; and not just communicating findings.
  • Ability to communicate in English (written and spoken).

Additional information

What can you expect from us?

  • 100% remote work.
  • A culture of trust, focused on results, with plenty of challenge and learning.
  • Autonomy and protagonism, in an environment full of collaboration and empathy.
  • Feedback culture and 1:1s with human leadership and no micromanagement. Full benefits such as: meal/food vouchers, childcare assistance, home office, health, education, and culture, gympass, birthday day-off, discounts on therapy and English courses, among other partnerships.