ARQ logo

Security Engineer, Lead

ARQ

São Paulo, São Paulo, BrazilHybridFull-timeNo compensation foundPosted 1mo agoVerified open 4 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
São Paulo, São Paulo, BrazilHybrid
Schedule
Full-time
Work Authorization
Not specified

Job overview

ARQ is hiring a Security Engineer, Lead. ARQ is seeking its first Security Engineer in Brazil to establish and grow the regional security function. This role offers significant autonomy, working closely with the global security team while defining local security practices. The ideal candidate will thrive in a multidisciplinary environment, comfortable spanning application security, security operations, and governance/risk/compliance.

Key focus areas include Drive the application security roadmap, including threat modeling standards and API security testing strategy., Define the company's approach to securing AI/agentic workflows and advise teams building with LLMs/MCP servers., and Set technical direction for detection engineering, alert pipelines, and automated response across the security stack..

Successful candidates bring 7+ Years Information Security Experience, Experience Building Security Function, and 2+ Years Regulated Fintech/Bank/Payment Company Experience. Important skills include Application Security, Security Operations, Governance Risk Compliance, Threat Modelling Standards, Secure Code Review Practices, and API Security Testing Strategy.

Skills & qualifications

RequiredNice to have

Skills

Application SecuritySecurity OperationsGovernance Risk ComplianceThreat Modelling StandardsSecure Code Review PracticesAPI Security Testing StrategySecurity Pipeline ArchitectureSecuring AI/Agentic WorkflowsLLMsMCP ServersDetection EngineeringAlert PipelinesAutomated ResponseDatadog SIEMCrowdStrikeCloudflareIncident Response ReadinessIR Playbooks DesignTabletop Exercises LeadershipCloud Security AssessmentsAWSKubernetesVendor Security Assessment FrameworkTechnical MentorshipCloud Infrastructure SecurityArchitect ControlsThreat Modelling FrameworksSecure Code Review StandardsCI/CD Pipeline HardeningEndpoint Security ToolingEDR/XDRIdentity & Access Management ArchitectureGoogle WorkspaceSSO/SCIMVendor Security Assessment Program DesignThird-Party Due Diligence ProgramCommunicationBusiness Fluent English

Qualifications

7+ Years Information Security ExperienceExperience Building Security Function2+ Years Regulated Fintech/Bank/Payment Company Experience

Full job description

What We're Looking For You'll be ARQ's first Security Engineer based in Brazil – it's the chance to lay the foundation for how we do security in the region and shape how that function grows from here. You'll work closely with our global security team but have real autonomy in deciding what "good" looks like locally, from day one.

We're looking for someone who enjoys a multidisciplinary role. Security at ARQ spans Application Security, Security Operations, and Governance/Risk/Compliance, and we need someone comfortable moving across at least two of these three areas – because in a founding role, there's no one else to hand off the parts that don't fit your specialty.

What you'll do

  • Drive the application security roadmap: threat modelling standards, secure code review practices, API security testing strategy, and security pipeline architecture

  • Define the company's approach to securing AI/agentic workflows – setting guardrails for prompts, destructive actions, and data exposure, and advising other teams building with LLMs/MCP servers

  • Set the technical direction for detection engineering, alert pipelines, and automated response across the security stack (Datadog SIEM, CrowdStrike, Cloudflare), and raise the bar on how the team designs and reviews detections

  • Own incident response readiness at a program level: design IR playbooks, lead tabletop exercises, and act as technical lead during major incidents

  • Set the standard and approach for cloud security assessments across AWS and Kubernetes, reviewing findings from other engineers and tackling the most complex environments directly

  • Own the vendor security assessment framework itself: continuously improving the due diligence process and handling the highest-risk vendor reviews

  • Act as a technical mentor to mid and senior engineers, reviewing their detection logic, assessments, and playbooks without formal management responsibilities

What you'll need

  • 7+ years in information security, including demonstrated experience building or substantially maturing a security function or program from the ground up

  • 2+ years at a regulated fintech/bank/payment company

  • Deep, hands-on expertise in cloud infrastructure security (AWS, Kubernetes), able to architect controls

  • Proven experience driving application security programs: threat modelling frameworks, secure code review standards, CI/CD pipeline hardening, and API security testing strategy

  • Demonstrated ability to define practical security guardrails for AI/agentic tooling – you understand the risks of LLM integrations, MCP servers, and automated workflows at an architectural level

  • Strong detection engineering background – you've designed detection strategy and mentored others in writing rules

  • Deep experience with endpoint security tooling (EDR/XDR) and identity & access management architecture in a SaaS-heavy environment (Google Workspace, Okta/Cloudflare Access, SSO/SCIM)

  • Experience designing or significantly evolving a vendor security assessment/third-party due diligence program

  • Excellent written and verbal communication; comfortable representing security decisions to leadership and cross-functional stakeholders

  • Business fluent in English

Benefits

  • Competitive salary and benefits

  • Stock options, so you own part of what you build

  • Discretionary performance bonus

  • The latest tools and technology

  • A world-class team that will challenge and grow your skills

  • The opportunity to help build the best fintech app in Latin America

  • Office Policy: 3-4 days a week in-office

You've read the whole posting — now see how you match it.