This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Software Engineer based in Brazil.
This role offers the opportunity to embed security expertise directly within software engineering teams and influence how products are designed, developed, tested, and maintained.
You will combine software engineering with proactive security practices such as threat modeling, architecture reviews, static analysis, fuzzing, and vulnerability response.
The position covers the full product security lifecycle, from developing secure features and hardening systems to investigating vulnerabilities and supporting security certifications.
You will work extensively with Linux and open source technologies while contributing to upstream projects and strengthening security across complex software ecosystems.
The role involves close collaboration with engineers, customers, partners, and open source communities to establish robust security practices and solutions.
You will have opportunities to work with technologies spanning Linux cryptography, security automation, vulnerability assessment, and low-level system components.
This position is ideal for a highly motivated security-focused engineer who combines strong technical skills with curiosity, accountability, and a passion for open source.
Accountabilities
- Define, implement, test, and document security features and capabilities across software products.
- Lead security-focused initiatives within product engineering teams and promote secure development practices throughout the software development lifecycle.
- Analyze, reproduce, remediate, and test vulnerabilities affecting open source software and Linux-based systems.
- Conduct source code audits and security analysis to identify vulnerabilities and recommend effective remediation strategies.
- Apply security engineering techniques including threat modeling, architecture and design reviews, tabletop exercises, static analysis, fuzzing, and proactive security assessments.
- Contribute to Ubuntu and upstream open source projects to improve security and support the broader open source community.
- Integrate security tools into engineering infrastructure, development pipelines, and operational processes.
- Develop and maintain hardening automation and security capabilities for Linux environments.
- Enhance Linux cryptographic components to support country-specific compliance and certification requirements, including FIPS and Common Criteria.
- Collaborate with external partners on security standards and Center for Internet Security benchmarks.
- Support the achievement and maintenance of relevant security certifications.
- Provide technical guidance and security best-practice support to other engineering teams.
- Monitor emerging security threats, technologies, vulnerabilities, and industry trends and incorporate relevant developments into engineering practices.
- Participate in international team events and other required travel at least twice per year.
- Undergraduate degree in Computer Science, STEM, or a related field, or a compelling alternative professional and technical background.
- Strong academic performance and a demonstrated history of exceeding expectations.
- Thorough understanding of common software security vulnerabilities, attack categories, and appropriate remediation techniques.
- Solid knowledge of modern software engineering practices and secure software development lifecycle principles.
- Experience acting as a security champion or driving security initiatives across engineering teams.
- Proficiency in at least one programming language such as C, C++, Python, Go, Rust, Java, Ruby, PHP, or JavaScript/TypeScript.
- Practical experience with Linux, preferably Debian or Ubuntu-based environments.
- Familiarity with open source development tools, workflows, methodologies, and community practices.
- Strong understanding of security engineering principles and the ability to apply them throughout product development.
- Excellent written and spoken English communication skills.
- Strong interpersonal, presentation, and collaboration skills, with the ability to influence technical teams effectively.
- High levels of curiosity, flexibility, accountability, self-motivation, and personal initiative.
- Results-oriented mindset with a strong commitment to delivering against agreed objectives.
- Willingness and ability to work effectively in a globally distributed environment and travel internationally at least twice per year.
- Experience with Linux kernel development is an advantage.
- Knowledge of FIPS, Common Criteria, security certifications, OVAL, OpenSSL, Libgcrypt, or low-level Linux cryptographic APIs is a plus.
- Experience with performance engineering, security tooling, or vulnerability assessment is beneficial.
- Demonstrated ability to learn quickly and adapt to new technologies is highly valued.
- Compensation based on geographical location, experience, and performance.
- Annual compensation review, with additional reviews where appropriate for graduates and associates.
- Performance-driven annual bonus.
- Distributed work environment with twice-yearly in-person team sprints.
- USD 2,000 annual personal learning and development budget.
- Recognition and performance rewards.
- Annual holiday leave.
- Maternity and paternity leave.
- Employee Assistance Programme.
- Opportunities to travel internationally and meet colleagues across global teams.
- Priority Pass and travel upgrades for eligible long-haul company events.
- Hands-on exposure to Linux security, open source software, cryptography, vulnerability response, security automation, and secure software engineering.
- Opportunities to contribute to upstream open source projects and collaborate with engineers, customers, partners, and security communities worldwide.
Requirements
Benefits

