← Back to results

Security Engineer, Senior

Be ARQ's first Security Engineer in Brazil, shaping security practices across application security, operations, and compliance.

Location
São Paulo
Compensation
Not disclosed
Level
senior
Type
full time · Hybrid

Posted by employer 1 week ago

First seen on Joblaze 1 week ago

Last verified on the company career page 1 day ago

Apply at ARQ → Save job Scanned from arqfinance.com

AI in the day-to-day

Assess and secure AI/agentic workflows across the company.

Requirements

Experience
4–7 years

Not disclosed in this posting: compensation, visa sponsorship.

Benefits

Office Policy: 3-4 days a week in-office Competitive salary and benefits Latest tools and technology Discretionary performance bonus Opportunity to help build the best fintech app in Latin America World-class team Stock Options

Joblaze summary

In this role, the Senior Security Engineer at ARQ will establish and enhance security protocols across various domains, including application security and cloud infrastructure. The position requires a strong background in information security, particularly in cloud environments like AWS and Kubernetes, along with hands-on experience in threat modeling and SIEM platforms. Ideal candidates will have 4-7 years of experience, preferably in a startup or high-growth context, where they have actively shaped security functions. As the first Security Engineer in Brazil, this individual will play a pivotal role in defining local security standards and practices.

Joblaze insights

Quick facts

Is the Security Engineer, Senior role remote?
It's hybrid — ARQ expects some on-site time in São Paulo.
How much experience is required?
4–7 years of relevant experience for this Security Engineer, Senior role.
Where is the role based?
ARQ is hiring for this position in São Paulo.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, Application Security, CloudFlare, Cloudflare Access, CrowdStrike, Datadog.
What seniority level is this role?
ARQ targets senior candidates for this position.
Is this full-time or contract?
Full-time for this Security Engineer, Senior role at ARQ.

From the original posting

What We're Looking For

You'll be ARQ's first Security Engineer based in Brazil – it's the chance to lay the foundation for how we do security in the region and shape how that function grows from here. You'll work closely with our global security team but have real autonomy in deciding what "good" looks like locally, from day one.

We're looking for someone who enjoys a multidisciplinary role. Security at ARQ spans Application Security, Security Operations, and Governance/Risk/Compliance, and we need someone comfortable moving across at least two of these three areas – because in a founding role, there's no one else to hand off the parts that don't fit your specialty.

What you'll do

  • Drive application security initiatives: threat modelling, secure code review support, API testing, and security pipeline improvements

  • Assess and secure AI/agentic workflows across the company — reviewing prompts, preventing destructive actions, and controlling data exposure

  • Build and improve SIEM detection rules, alert pipelines, and automated response playbooks (Datadog SIEM, CrowdStrike, Cloudflare)

  • Contribute to incident response readiness, including IR playbooks, tabletop exercises, and forensic procedures

  • Conduct cloud security assessments across AWS and Kubernetes environments

  • Establish and run the vendor security assessment process — building a scalable due diligence framework for third-party onboarding

What you'll need

  • 4–7 years in information security, ideally having built or significantly shaped the security function at a startup or high-growth company - you've been the person who sets things up, not just maintains them

  • Hands-on experience with cloud infrastructure security (AWS, Kubernetes)

  • Familiarity with application security practices: threat modelling, secure code review, CI/CD pipeline hardening, and API security testing

  • Ability to assess and secure emerging AI/agentic tooling - you understand the risks of LLM integrations, MCP servers, and automated workflows, and can define practical guardrails

  • Working knowledge of SIEM platforms and detection engineering - you've written detection rules

  • Experience with endpoint security tooling (EDR/XDR) and identity & access management in a SaaS-heavy environment (Google Workspace, Okta/Cloudflare Access, SSO/SCIM)

  • Experience running or contributing to vendor security assessments and third-party due diligence

  • Strong written and verbal communication in English

Benefits

  • Competitive salary and benefits

  • Stock options, so you own part of what you build

  • Discretionary performance bonus

  • The latest tools and technology

  • A world-class team that will challenge and grow your skills

  • The opportunity to help build the best fintech app in Latin America

  • Office Policy: 3-4 days a week in-office

Similar positions

ARQ
Security Engineer, Mid
ARQ · São Paulo
ARQ
Security Engineer, Lead
ARQ · São Paulo
Abnormal Security
Senior Cloud Security Engineer (AWS)
Abnormal Security · Remote - USA
Abnormal Security
Application Security Engineer II
Abnormal Security · Remote - USA