Stop applying to remote jobs that are already dead.
Every listing shows the evidence: when we last checked it, how, and when it was posted and closed.

All listings

Tessera Labs via Ashby

Senior Product Security Engineer

Brazil senior
still open verified 2d ago posted 39d ago seen 3h ago
Apply at jobs.ashbyhq.com

This is the employer's own posting, not a copy on a job board.

What we know

Is it still open?

Confirmed still open

Last checked 2d ago — checked against the employer's own applicant tracking system, which is the company answering directly.

We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.

Check this listing's status as JSON

How old is it?

Posted 39d ago

The date the source published, not the day we noticed it (2026-09-01). Last seen at its source 3h ago.

We have tracked this listing since 5 Oct 2026 (5 days). The employer's own board has carried it every time we have read it, most recently 3 hours ago.

Is it remote?

Marked remote on the employer's board

Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.

Who may apply?

Brazil

The description states no restriction of its own. This is the source's own tag.

Pay not stated

Similar roles pay $93.8k–157.1k/yr

Middle 50% of 16 listings that do state pay — Engineering · Senior · Brazil · USD/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.

Skills named in the ad

AWSAzureGCPISO 27001KubernetesPenetration TestingSOC 2SSOThreat ModelingUser Stories

Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.

Carried by 1 source

The listing

Senior Product Security Engineer

Remote in Brazil or LATAM

The Role

We're hiring a Senior Product Security Engineer to work hand-in-hand with developers to secure the product across its entire lifecycle. You'll be the person who makes our platform defensible — through design reviews, threat modeling, hands-on penetration testing, and secure-coding partnership — and you'll do it as a collaborator who helps engineers ship securely, not a gatekeeper who slows them down.

This role partners closely with product engineering and platform engineering teams.

What You'll Do

  • Partner directly with developers to secure the product across the Software Development Life Cycle (SDLC), embedding security early rather than bolting it on at the end.

  • Lead security design and architecture reviews, and run threat modeling on new features and services.

  • Perform hands-on penetration testing of web applications and Application Programming Interfaces (APIs), and translate findings into clear, prioritized, fixable work.

  • Conduct secure code reviews and help define secure-coding standards and security acceptance criteria.

  • Operate and tune Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and dependency / supply-chain scanning, and triage what they surface.

  • Help engineers understand the "why" behind findings so the same class of issue doesn't recur.

  • Contribute security evidence and rigor to our compliance posture (System and Organization Controls 2, or SOC 2, ISO 27001, etc.).

What You'll Need (Required)

  • A strong track record in product or application security — you've measurably made real products more secure.

  • Hands-on penetration testing experience against web applications and APIs.

  • Deep understanding of how modern web applications work — single-page front ends, APIs, authentication and authorization (for example, OAuth 2.0 / OpenID Connect), sessions, and the common ways each is attacked (for example, the Open Worldwide Application Security Project, or OWASP, Top 10).

  • Experience running security design reviews and threat modeling.

  • Solid understanding of the SDLC and how to embed security into it.

  • Strong communication skills — you work directly with developers and can explain risk in terms they'll act on.

Nice to Have

  • Familiarity with open-source security tooling (for example, OWASP ZAP and Burp Suite Community Edition for testing, Semgrep for SAST, Trivy or Grype for dependency and container scanning, Nuclei for templated scanning).

  • A relevant offensive-security certification (for example, Offensive Security Certified Professional, or OSCP).

  • Cloud security experience (Amazon Web Services, Microsoft Azure, or Google Cloud Platform) and container / Kubernetes security.

  • Experience supporting a SOC 2, International Organization for Standardization (ISO) 27001, or similar program.

  • Background in enterprise or regulated environments where deployment security is non-negotiable.

What Success Looks Like (First 90 Days)

  • You've reviewed the product's architecture and threat surface and identified the highest-priority security risks.

  • A repeatable, lightweight process exists for security design reviews on new work.

  • Security findings have a clear triage-to-remediation path, and developers know how to engage you early.

Location and Work Model

Remote in Brazil or LATAM

Apply at jobs.ashbyhq.com