Gympass
Staff Security Engineer | AppSec
Remote role where the employee must remain based in a particular country.
Brazil only
Employer listed it 6 weeks ago · Added 5 days ago
Been open since 6 weeks ago, still being checked, but it has been live a while.
Salary
Not stated
Location
Brazil only
Timezone
Not stated
Contract
Full-time
Experience
Lead
Category
Software
This employer didn't state pay. Jobs like this usually pay around $200k–$275k a year, a typical range taken from 597 lead-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Work from home
This is a remote role, but the employee must be based in Brazil. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Brazil (Remote), São Paulo"
- Job description states: "work from anywhere within the country. Please note that this role is o"
What Nomaders makes of it
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Your wellbeing, our mission. Join a company shaping a healthier world.
GET TO KNOW US
At Wellhub we're revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.
We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.
Join us in redefining the future of wellbeing!
THE OPPORTUNITY
We are hiring a Staff Security Engineer | AppSec to our Information Security team in Brazil! This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.
The Information Security team is responsible for protecting our subscription-based product serving millions of users globally. As a Staff Security Engineer, you will own multiple security domains end-to-end — with your center of gravity in software security (secure SDLC, vulnerability management, threat modeling, pentesting, and red teaming) while reaching across incident response, threat intelligence, cloud security, and compliance as the team's mandate requires.
You will become the organization's go-to authority for the hardest, cross-domain security trade-offs — the ones without an obvious owner. By connecting pentest findings, incident root causes, compliance requirements, and cloud misconfigurations into a unified risk strategy, you will shape baseline security standards, mentor engineering teams, and drive medium-to-large strategic initiatives that scale with our growth.
YOUR IMPACT
Own multiple security domains end-to-end, serving as the technical authority for complex, cross-service security challenges across the entire organization.
Establish secure-by-design architectural standards, lead threat modeling sessions, and set the secure-coding benchmarks that other engineers follow.
Drive complex, cross-service incident responses and post-mortems, converting critical findings into systemic guardrails and platform-level preventions.
Lead offensive and defensive strategy initiatives—including Red Team exercises and pentest engagements—driving root-cause remediation directly with engineering teams.
Ensure organization-wide security posture by setting SLAs, SLOs, and KPIs (remediation windows, response times, posture drift), building the monitoring needed to hold teams accountable.
Partner with cross-functional leadership (Engineering, Product, Legal) to align threat intelligence, compliance needs, and long-term security investments with business priorities.
Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life wellness.
WHO YOU ARE
A seasoned security specialist with extensive experience in Security Engineering (or software engineering with high security impact) and a proven track record of scaling security in complex cloud environments.
An adaptable professional with a willingness to step outside your primary focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
A strategic technical partner with expert knowledge in secure architecture design, threat modeling, and setting engineering-wide secure coding standards.
An influential communicator with fluency in English and Portuguese, able to translate intricate security tradeoffs into clear risk statements for executive leadership and product partners.
A pragmatic risk navigator with the ability to balance long-term risk red uction against business velocity, making high-stakes decisions independently.
A forward-thinking specialist with a deep understanding of attacker TTPs, modern cloud ecosystems (AWS/EKS, GCP/GKE, Istio, ArgoCD), and regulatory frameworks (SOC 2, ISO 27001, LGPD, GDPR).
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
- ·With thoughtful benefits, emotional wellbeing resources, and a culture that empowers you to take ownership of your role and your wellbeing, we create an environment where you can thrive in all dimensions of your life.
- ·Our flexible benefits program allows you to customize some of the benefits, according to your needs!
- ·Our benefits include:
- ·WELLZ: A complete emotional wellbeing program with a unique approach. It offers personalized journeys that combine individual therapy sessions (52 per year) and on-demand content.
- ·HEALTHCARE: Health, dental, and life insurance.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Gympass, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $200k to $275k per year · You'll be taken to the employer's careers page.