Product Security Engineer (remote in Brazil)
Please submit your resume in English.
To learn more about our team and office culture in São Paulo, Brazil, visit the following links.
Careers Page: https://www.knowbe4.com/careers/locations/sao-paulo
Glassdoor: https://www.glassdoor.com/Location/KnowBe4-S%C3%A3o-Paulo-Location-EI_IE969384.0,7_IL[…]M_-C1lsxoZq7Cx8IriVE8MkrzuTmnJzqego77RAWZz9sqGt_55BflwYKpQeg
LinkedIn: https://www.linkedin.com/company/knowbe4/life/brazil/
KnowBe4 is seeking a mid-level Product Security Engineer in Brazil to join our Security team! In this role, your primary focus will be hands-on penetration testing and security reviews, evaluating application code before and after it hits production to ensure company and customer data remain safe.
As our engineering team accelerates development, you will play a critical role in scaling our security coverage, triaging findings, and collaborating directly with global engineering teams across the US and Brazil.
Responsibilities:
Application Security Testing & Pentesting: Conduct automated and manual security assessments and penetration tests across web, mobile, and traditional applications.
Code Security Reviews: Analyze source code across multiple programming languages to identify vulnerabilities and guide remediation before and after production deployment.
Vulnerability Triage & Remediation: Work closely with engineering teams to assess, prioritize, and resolve application vulnerabilities.
Threat Modeling & Automation: Maintain threat models and build security automations to streamline security testing workflows.
Security Engagement: Partner with product and development teams to embed secure coding practices throughout the software development lifecycle (SDLC).
Requirements:
Experience in Application Security, Penetration Testing, or Red Teaming.
Pentesting Expertise: Strong hands-on experience with both automated and manual web, mobile, and traditional application pentesting
Code Comprehension: Proven ability to read and analyze source code in multiple languages (such as Ruby, PHP, Go, JavaScript, or Python)
Security Fundamentals: Broad understanding of web application vulnerabilities (e.g., OWASP Top 10, CWE) and core information security concepts
Language & Communication: Strong technical English communication skills (written and spoken) to collaborate smoothly across international teams
Cultural Fit: Collaborative, open mindset with a strong focus on teamwork and positive team dynamics
Preferred / Nice-to-Have
Experience with cloud computing environments (AWS, Terraform)
Familiarity with security tools (e.g., Burp Suite, SAST/DAST, dependency scanning)
Experience with Python scripting or leveraging AI tools in security workflows
Relevant industry certifications (e.g., OSCP, OSWE, GPEN, CISSP)