SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer, Mid

ARQ - Sao Paulo, Brazil - Hybrid - posted 2026-09-01

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

ARQ is seeking its first Security Engineer based in Brazil to establish and grow the security function in the region. This is a founding-level role with significant autonomy to shape local security practices while collaborating with the global security team. You will work across three core security domains: Application Security, Security Operations, and Governance/Risk/Compliance. The role requires comfort moving between at least two of these areas, as there is no one else to hand off work that falls outside your primary specialty. Key responsibilities include: - Application Security: Lead threat modelling sessions, conduct secure code reviews, perform API security testing, and implement CI/CD pipeline security checks. - AI/Agentic Security: Review and monitor AI workflows for prompt injection risks, unsafe automated actions, and data exposure vulnerabilities. - Detection Engineering: Build and maintain SIEM detection rules, alert pipelines, and response playbooks using Datadog SIEM, CrowdStrike, and Cloudflare. Own detection coverage end-to-end for a defined set of systems. - Incident Response: Triage security alerts, execute incident response playbooks, and facilitate tabletop exercises. - Cloud Security: Conduct security assessments across AWS and Kubernetes environments under guidance from senior team members. - Vendor Security: Execute vendor security assessments using the established due diligence framework and own the review process for a portion of the vendor pipeline. This role offers the opportunity to build security foundations in a high-growth fintech company operating in Latin America, with exposure to emerging AI/ML security challenges and a multidisciplinary security practice. Requirements: - 2–4 years of experience in information security or closely related technical role (security operations, cloud/infrastructure engineering with security focus, or similar) - Working experience with at least one cloud environment (AWS preferred) and familiarity with Kubernetes fundamentals - Basic familiarity with application security concepts: threat modelling, secure code review, or API security testing - Curiosity about AI/agentic tooling risks (LLM integrations, MCP servers, automated workflows); prior hands-on experience is a plus but not required - Exposure to SIEM platforms and interest in detection engineering; must have written or tuned at least a few detection rules - Strong written and verbal communication in English

Similar roles