- Location
- Sao Paulo, Brazil, Brazil
- Workplace
- Hybrid
- Employment
- Full time
- Level
- Mid level
- Posted
- 8 weeks ago
About this role
What We're Looking For
You'll be ARQ's first Security Engineer based in Brazil - it's the chance to lay the foundation for how we do security in the region and shape how that function grows from here. You'll work closely with our global security team but have real autonomy in deciding what "good" looks like locally, from day one.
We're looking for someone who enjoys a multidisciplinary role. Security at ARQ spans Application Security, Security Operations, and Governance/Risk/Compliance, and we need someone comfortable moving across at least two of these three areas - because in a founding role, there's no one else to hand off the parts that don't fit your specialty.
What you'll do
Drive the application security roadmap: threat modelling standards, secure code review practices, API security testing strategy, and security pipeline architecture
Define the company's approach to securing AI/agentic workflows - setting guardrails for prompts, destructive actions, and data exposure, and advising other teams building with LLMs/MCP servers
Set the technical direction for detection engineering, alert pipelines, and automated response across the security stack (Datadog SIEM, CrowdStrike, Cloudflare), and raise the bar on how the team designs and reviews detections
Own incident response readiness at a program level: design IR playbooks, lead tabletop exercises, and act as technical lead during major incidents
Set the standard and approach for cloud security assessments across AWS and Kubernetes, reviewing findings from other engineers and tackling the most complex environments directly
Own the vendor security assessment framework itself: continuously improving the due diligence process and handling the highest-risk vendor reviews
Act as a technical mentor to mid and senior engineers, reviewing their detection logic, assessments, and playbooks without formal management responsibilities
What you'll need
7+ years in information security, including demonstrated experience building or substantially maturing a security function or program from the ground up
2+ years at a regulated fintech/bank/payment company
Deep, hands-on expertise in cloud infrastructure security (AWS, Kubernetes), able to architect controls
Proven experience driving application security programs: threat modelling frameworks, secure code review standards, CI/CD pipeline hardening, and API security testing strategy
Demonstrated ability to define practical security guardrails for AI/agentic tooling - you understand the risks of LLM integrations, MCP servers, and automated workflows at an architectural level
Strong detection engineering background - you've designed detection strategy and mentored others in writing rules
Deep experience with endpoint security tooling (EDR/XDR) and identity & access management architecture in a SaaS-heavy environment (Google Workspace, Okta/Cloudflare Access, SSO/SCIM)
Experience designing or significantly evolving a vendor security assessment/third-party due diligence program
Excellent written and verbal communication; comfortable representing security decisions to leadership and cross-functional stakeholders
Business fluent in English
Benefits
Competitive salary and benefits
Stock options, so you own part of what you build
Discretionary performance bonus
The latest tools and technology
A world-class team that will challenge and grow your skills
The opportunity to help build the best fintech app in Latin America
Office Policy: 3-4 days a week in-office
As published by ARQ. Applications are handled on their site.
Skills this posting mentions
About ARQ
ARQ opens the world's strongest assets and markets to travelers, investors, and professionals in the Americas - so they can grow their money wherever they are.
All 39 openings at ARQOne click, then it is written
Apply to ARQ with a resume written for this role.
Queue Security Engineer, Lead and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in ARQ’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at ARQ
See all- 5 weeks ago
- 5 weeks ago
- 5 weeks ago
- 7 weeks ago
- 7 weeks ago
Financial Controller & Regulatory Reporting Officer - Gibraltar
Gibraltar , GibraltarHybrid
Mid levelFinance - 7 weeks ago
Similar roles elsewhere
See more- 5 days ago
- 5 days ago
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board ARQ publishes. Refolk is not the employer and does not handle their hiring. Applications go to ARQ directly.