Staff Security Engineer | AppSec
Gympass
- Location
- Brazil (Remote)
- Work model
- Remote
- Level
- Staff
- Posted
- 1h ago
Skills
About this role
Your wellbeing, our mission. Join a company shaping a healthier world.
GET TO KNOW US
At Wellhub we're revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.
We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.
Join us in redefining the future of wellbeing!
THE OPPORTUNITY
We are hiring a Staff Security Engineer | AppSec to our Information Security team in Brazil! This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.
The Information Security team is responsible for protecting our subscription-based product serving millions of users globally. As a Staff Security Engineer, you will own multiple security domains end-to-end — with your center of gravity in software security (secure SDLC, vulnerability management, threat modeling, pentesting, and red teaming) while reaching across incident response, threat intelligence, cloud security, and compliance as the team's mandate requires.
You will become the organization's go-to authority for the hardest, cross-domain security trade-offs — the ones without an obvious owner. By connecting pentest findings, incident root causes, compliance requirements, and cloud misconfigurations into a unified risk strategy, you will shape baseline security standards, mentor engineering teams, and drive medium-to-large strategic initiatives that scale with our growth.
YOUR IMPACT
• Own multiple security domains end-to-end, serving as the technical authority for complex, cross-service security challenges across the entire organization.
• Establish secure-by-design architectural standards, lead threat modeling sessions, and set the secure-coding benchmarks that other engineers follow.
• Drive complex, cross-service incident responses and post-mortems, converting critical findings into systemic guardrails and platform-level preventions.
• Lead offensive and defensive strategy initiatives—including Red Team exercises and pentest engagements—driving root-cause remediation directly with engineering teams.
• Ensure organization-wide security posture by setting SLAs, SLOs, and KPIs (remediation windows, response times, posture drift), building the monitoring needed to hold teams accountable.
• Partner with cross-functional leadership (Engineering, Product, Legal) to align threat intelligence, compliance needs, and long-term security investments with business priorities.
Live