# Sr./Staff Security Engineer

**Company:** [Oscilar](https://hotfix.jobs/companies/oscilar)
**Location:** Remote
**Role:** Security Engineering
**Salary:** R$394k – R$574k/yr
**Experience:** 5+ years
**Skills:** Java, Python, Go, SSO, SAML, Oauth 2.0, Jwt, Mtls, Jose, RBAC, Semgrep, Dependabot, Snyk, Kubernetes, Aws Iam
**Posted:** 2026-05-15

> Leads product and application security for a multi-tenant AI risk platform, including threat modeling, identity controls, AppSec tooling, incident response, and LLM security guardrails. Requires 5+ years of software development experience and 3+ years in application or product security.

## Job Description

## Responsibilities
- Own threat modeling across core platform APIs, risk decisioning and event-ingestion systems, and agentic AI products.
- Harden multi-tenant isolation and data handling across designs and pull requests.
- Design, implement, and deploy authentication, authorization, user and API access controls, and RBAC.
- Establish the application security program, including SAST, SCA, secret scanning, and container scanning.
- Build guardrails for LLM usage, including prompt-injection defenses, output validation, and cost and abuse monitoring for Bedrock, Anthropic, and OpenAI calls.
- Drive security incident processes, vulnerability triage, and responsible disclosure.
- Maintain `SECURITY.md` and a threat registry, and promote secure-by-default patterns across engineering.
- Partner with IT on incident response, access reviews, and audit evidence collection.
- Collaborate with product and engineering teams to embed security early in feature design.
- Track current security standards and trends, including OWASP, MITRE ATT&CK, and emerging LLM and agent security guidance.

## Requirements
- 5+ years building software, with the last 3+ years focused on application or product security.
- Strong software engineering fundamentals, ideally in a fintech or data-heavy SaaS environment.
- Hands-on Java, Python, or Go code review experience.
- Experience with SSO, SAML, OAuth 2.0, JWT, mTLS, JOSE, multi-tenant authorization, and PII handling or tokenization.

## Nice to Have
- Familiarity with AWS security primitives, including IAM, KMS, Secrets Manager, and VPC.
- Kubernetes experience.
- Experience providing technical evidence and controls for SOC 2, PCI, or ISO 27001 audits.
- Experience building or tuning SAST rules with Semgrep or CodeQL.
- OSCP, CISSP, or a meaningful bug-bounty track record.

## Compensation and Benefits
- Competitive salary; candidates are hired as CLT employees.
- Stock options.
- 100% company-paid medical and dental coverage for employees and dependents.
- 100% company-paid life and long-term disability insurance.
- Caju Card monthly meal allowance.
- Remote-first flexibility.
- Family-friendly environment, team events, and offsites.
- Learning and professional development opportunities.

## Similar jobs

- [Lead Product GRC Subject Matter Expert](https://hotfix.jobs/jobs/57c937d5-05e3-4033-875a-890645c4aa6b) - Vanta - Remote - $230k – $270k/yr
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Senior Product Security Engineer](https://hotfix.jobs/jobs/349d94de-bb90-497f-aff4-96221f8c389d) - Tessera Labs - Remote - $50k – $60k/yr
- [Technical GRC Analyst](https://hotfix.jobs/jobs/59eac364-5d69-4af7-a82d-99ebfcf9f7fc) - Tessera Labs - Remote - $50k – $60k/yr
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr

**Apply:** https://hotfix.jobs/jobs/3117e25f-4708-4083-85b6-dff853475448
**Canonical:** https://hotfix.jobs/jobs/3117e25f-4708-4083-85b6-dff853475448