SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
ARQ is seeking its first Security Engineer based in Brazil to establish and lead the security function in the region. This is a founding-level role with significant autonomy to shape security practices locally while collaborating with the global security team.
You will drive the application security roadmap, including threat modeling standards, secure code review practices, API security testing strategy, and security pipeline architecture. A key responsibility is defining the company's approach to securing AI/agentic workflows—setting guardrails for prompts, destructive actions, and data exposure while advising teams building with LLMs and MCP servers.
You'll set technical direction for detection engineering, alert pipelines, and automated response across the security stack (Datadog SIEM, CrowdStrike, Cloudflare), raising the bar on how the team designs and reviews detections. You own incident response readiness at a program level, designing IR playbooks, leading tabletop exercises, and acting as technical lead during major incidents.
Cloud security assessments across AWS and Kubernetes fall under your purview—you'll review findings from other engineers and tackle the most complex environments directly. You'll also own and continuously improve the vendor security assessment framework, handling the highest-risk vendor reviews.
As a technical mentor to mid and senior engineers, you'll review detection logic, assessments, and playbooks without formal management responsibilities, helping the team grow their expertise.
The role is hybrid, requiring 3-4 days per week in the São Paulo office.
REQUIREMENTS:
- 7+ years in information security, including demonstrated experience building or substantially maturing a security function or program from the ground up
- Deep, hands-on expertise in cloud infrastructure security (AWS, Kubernetes), able to architect controls
- Proven experience driving application security programs: threat modeling frameworks, secure code review standards, CI/CD pipeline hardening, and API security testing strategy
- Demonstrated ability to define practical security guardrails for AI/agentic tooling—understanding risks of LLM integrations, MCP servers, and automated workflows at an architectural level
- Strong detection engineering background—you've designed detection strategy and mentored others in writing rules
- Deep experience with endpoint security tooling (EDR/XDR) and identity & access management architecture in a SaaS-heavy environment (Google Workspace, Okta/Cloudflare Access, SSO/SCIM)
- Experience designing or significantly evolving a vendor security assessment/third-party due diligence program
- Excellent written and verbal communication; comfortable representing security decisions to leadership and cross-functional stakeholders
- Business fluent in English