SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer, Senior

ARQ - Sao Paulo, SP, Brazil - Hybrid - posted 2026-09-01

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

ARQ is seeking its first Security Engineer based in Brazil to establish and lead the security function in the region. This is a founding-level role with significant autonomy to shape security practices from the ground up while collaborating with ARQ's global security team. You will own a multidisciplinary security portfolio spanning application security, security operations, and governance/risk/compliance. Key responsibilities include: - Drive application security initiatives including threat modeling, secure code review support, API testing, and CI/CD pipeline hardening - Assess and secure AI/agentic workflows across the company—reviewing prompts, preventing destructive actions, and controlling data exposure - Build and improve SIEM detection rules, alert pipelines, and automated response playbooks using Datadog SIEM, CrowdStrike, and Cloudflare - Contribute to incident response readiness through IR playbooks, tabletop exercises, and forensic procedures - Conduct cloud security assessments across AWS and Kubernetes environments - Establish and operationalize the vendor security assessment process, building a scalable due diligence framework for third-party onboarding This role requires comfort moving across multiple security domains—in a founding position, you'll handle work that spans your specialty and adjacent areas. You'll be the person setting things up and defining what "good" looks like locally, not maintaining existing processes. Benefits include competitive salary, stock options, discretionary performance bonus, and latest tools/technology. Office policy is 3-4 days per week in-office. REQUIREMENTS: - 4–7 years in information security, ideally having built or significantly shaped the security function at a startup or high-growth company - Hands-on experience with cloud infrastructure security (AWS, Kubernetes) - Familiarity with application security practices: threat modeling, secure code review, CI/CD pipeline hardening, API security testing - Ability to assess and secure emerging AI/agentic tooling—understanding risks of LLM integrations, MCP servers, and automated workflows, and defining practical guardrails - Working knowledge of SIEM platforms and detection engineering; experience writing detection rules - Experience with endpoint security tooling (EDR/XDR) and identity & access management in SaaS-heavy environments (Google Workspace, Okta/Cloudflare Access, SSO/SCIM) - Experience running or contributing to vendor security assessments and third-party due diligence - Strong written and verbal communication in English

Similar roles