hirly

ARQ

Security Engineer, Lead

São Paulo

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at ARQ first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

hirly's read of this role

Role family
Engineering
Seniority
Lead / management
Country
BR
Work mode
On-site / unstated
First seen by hirly
28 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

What We're Looking For

You'll be ARQ's first Security Engineer based in Brazil – it's the chance to lay the foundation for how we do security in the region and shape how that function grows from here. You'll work closely with our global security team but have real autonomy in deciding what "good" looks like locally, from day one.

We're looking for someone who enjoys a multidisciplinary role. Security at ARQ spans Application Security, Security Operations, and Governance/Risk/Compliance, and we need someone comfortable moving across at least two of these three areas – because in a founding role, there's no one else to hand off the parts that don't fit your specialty.

What you'll do

Drive the application security roadmap: threat modelling standards, secure code review practices, API security testing strategy, and security pipeline architecture

Define the company's approach to securing AI/agentic workflows – setting guardrails for prompts, destructive actions, and data exposure, and advising other teams building with LLMs/MCP servers

Set the technical direction for detection engineering, alert pipelines, and automated response across the security stack (Datadog SIEM, CrowdStrike, Cloudflare), and raise the bar on how the team designs and reviews detections

Own incident response readiness at a program level: design IR playbooks, lead tabletop exercises, and act as technical lead during major incidents

Set the standard and approach for cloud security assessments across AWS and Kubernetes, reviewing findings from other engineers and tackling the most complex environments directly

Own the vendor security assessment framework itself: continuously improving the due diligence process and handling the highest-risk vendor reviews

Act as a technical mentor to mid and senior engineers, reviewing their detection logic, assessments, and playbooks without formal management responsibilities

What you'll need

7+ years in information security, including demonstrated experience building or substantially maturing a security function or program from the ground up

Deep, hands-on expertise in cloud infrastructure security (AWS, Kubernetes), able to architect controls

Proven experience driving application security programs: threat modelling frameworks, secure code review standards, CI/CD pipeline hardening, and API security testing strategy

Demonstrated ability to define practical security guardrails for AI/agentic tooling – you understand the risks of LLM integrations, MCP servers, and automated workflows at an architectural level

Strong detection engineering background – you've designed detection strategy and mentored others in writing rules

Deep experience with endpoint security tooling (EDR/XDR) and identity & access management architecture in a SaaS-heavy environment (Google Workspace, Okta/Cloudflare Access, SSO/SCIM)

Experience designing or significantly evolving a vendor security assessment/third-party due diligence program

Excellent written and verbal communication; comfortable representing security decisions to leadership and cross-functional stakeholders

Business fluent in English

Benefits

Competitive salary and benefits

Stock options, so you own part of what you build

Discretionary performance bonus

The latest tools and technology

A world-class team that will challenge and grow your skills

The opportunity to help build the best fintech app in Latin America

Office Policy: 3-4 days a week in-office

Original posting on ARQ's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job