Staff Security Engineer [AppSec]

Stone - LinkedinRemotoJob.bopublished 09/09/2026
This job is no longer listed
The source has removed this listing — applying via the original link is no longer possible.
Must-have:AWSAzureGoogle CloudCloudCI/CDAIPrincipalRemote
Machine translation — original language: Portuguese.Show original

About Stone:

We are much more than a card machine company! Stone is a technology and financial services company focused on the customer.

We were born with the purpose of being protagonists in the transformation of the payments industry, serving the Brazilian entrepreneur and transforming their dreams into results.

We are the largest independent payment methods company in Brazil, with more than fifteen thousand people spread across the five regions of the country, in a scenario full of challenges and opportunities. We value teamwork, flexibility, continuous development, and disruptive thinking, tirelessly seeking solutions for our REASON.

Our Culture:

Here, we live our culture every day, guided by these 5 values:

💚 The customer is the reason The customer is the reason we exist and we only succeed if they succeed.

⚡ Ownership mindset We do what is right, the right way, with responsibility and technology to make better decisions.

🎯 Straight to the point Depth to understand and simplicity to resolve.

🤝 Excellence is a team game We build a long-term business, as a team and through collaboration.

✨ Passion in every detail We do it with passion, attention to detail, and the will to surprise to help the customer win.

Stone has an opportunity in its Development Security (AppSec) team within the Information Security area! Do you like seeking new challenges and acquiring new knowledge to accelerate your career development? If so, come join our Information Security team as a Development Security Architect at Stone!

The AppSec team's purpose is to ensure that applications are developed, maintained, and used in a secure manner and protected against cyber threats — including the growing number of systems that integrate language models (LLMs) and generative AI into our products and engineering workflows. We seek to prevent our systems from having vulnerabilities that could be exploited by cybercriminals, aiming to protect sensitive data, user privacy, and application integrity.

The main objectives we pursue are:

Definition of architectural security standards, together with the Engineering and Product teams, so they can be used in the construction and operation of the systems we build — including applications that use LLMs, agents, and RAG pipelines

Ability to create plans that define an architectural standard for new systems and that include a viable technical roadmap for migrating legacy systems

Identification of vulnerabilities and their respective risk level, thereby helping to prevent attacks

Participation in security incident analysis and response, seeking continuous improvement of our processes and practices

Training, awareness, and collaboration with development teams to use good programming practices and software architectural standards — including the secure use of AI assistants (Copilot, Cursor, and similar) in the development cycle

What is it like to be a Staff / Development Security Architect (AppSec)?

Among the expected work activities are:

Define and implement security strategies for applications, including those that integrate LLMs and generative AI components

Collaborate with development teams to integrate security practices from the beginning of the software lifecycle

Perform architecture, code, and design reviews to identify potential vulnerabilities and security issues

Define guardrails and standards for applications with LLM, addressing risks such as prompt injection, insecure output handling, data leakage via outputs, excessive agency in agents, and cost abuse (denial-of-wallet)

Establish guidelines for the secure use of AI-assisted development tools by engineering teams, balancing productivity, intellectual property protection, and prevention of sensitive data leakage

Develop and promote security standards and best practices for the entire development team

Provide technical guidance and security training to development teams

Be familiar with tools for automatic quality validation in the CI/CD pipeline such as SAST, DAST, SCA, and Secret Scanning

Monitor trends and evolutions of security threats and constantly update protection measures — including the emerging threat landscape for AI systems

Develop creative solutions for complex security problems that balance business needs and risks

Use your security experience and intuition to hunt for threats in corporate and production environments

Read and communicate in English

What we expect from you:

Ability to identify opportunities for improvement, new solutions, and alerts that can benefit and/or facilitate operations

Use influence and negotiation skills to direct teams to fix problems or use architectures that are appropriate from a security standpoint

Ability to work with autonomy

Communicate in a concise, frank, and assertive manner, knowing how to translate complex problems into a language accessible to the audience you are communicating with

Initiative to seek or request information when needed

Hold a Higher Education degree (completed or in progress) in Information Security, Computer Science, Information Systems, Software Engineering, or related courses

Passion for learning and thriving in a dynamic and constantly changing environment

Knowledge of common attack vectors

Experience in performing threat modeling

Experience in effective mechanisms for protecting APIs and mobile applications

Knowledge of basic services and security concepts of Cloud (AWS, Azure, or GCP)

Ease of working within multi-disciplinary teams using agile methodology

Familiarity with security risks in applications that use LLMs and generative AI (references such as OWASP Top 10 for LLM Applications and MITRE ATLAS)

What increases your chances:

Experience in participating in incidents seeking to identify root causes

Experience in projects where requirements for the financial area are applicable (Bacen, PCI, SOX, among others)

Solid programming knowledge

Practical experience in threat modeling and defining controls for applications with LLMs in production (chatbots, copilots, agents, RAG)

Experience in protecting APIs that expose AI models: direct and indirect prompt injection, structured output validation, authorization controls in function calling and tool use

Experience in defining policies and controls for corporate use of generative AI tools (code assistants, chat platforms), including prevention of data and intellectual property leakage

Knowledge of emerging governance and security frameworks in AI (NIST AI RMF, ISO/IEC 42001)

LI-remote

Our Remuneration and Benefits package:

(items with an asterisk have specific eligibility rules, which will be explained by recruiters throughout the selection process)

💸Fixed Salary

💰 Variable Remuneration Package* (PLR, ILP, or Commission - provided according to the position's eligibility, not being a model of free choice)

🏥 Health and Dental Plan with co-payment (except for professionals with disabilities who do not have co-payment)

🩺Verde Virtual Hospital: telemedicine team available 24 hours a day, 7 days a week

💊Medication subsidy

🍽️ Meal Voucher and/or Food Voucher - Pluxee* (except for Commercial Executive positions - 6hrs)

👶 Daycare Allowance (for children up to 5 years and 11 months)

💙 Allowance for Children with Disabilities

🛡️ Life Insurance

⛽Fuel allowance or commuting allowance *

🏠 Home office allowance * (only for Hybrid or Remote contracts)

🎁 Welcome Kit for new parents

🏢 SESC agreement*

📚 Education Benefit - Internal self-development platform (Studa and Stone Library)

🧠 Acolhe360º - Emotional support (free)

💆 Quick Massage and Clinic*

Optionals:

Wellhub - TotalPass - Pet Club - Flash - Férias&Co - VT - Allya - Educational partnerships

  • In addition to affirmative vacancies, all Stone vacancies are also intended for people with disabilities.