SumUp

Senior Security Engineer

São Paulo, SP
AWS Kubernetes SAST SCA CI/CD OWASP NIST CIS IAM OAuth 2.0 OIDC SAML PCI-DSS
Description

Senior Security Engineer

Location: São Paulo, São Paulo, Brazil

Department: IT

SumUp enables businesses to get paid easily, process orders quickly, sell online instantly and manage their money more efficiently. We create the tools businesses need to make their business and their customer experience thrive!

As a Senior Security Engineer for our tribe, you will be responsible for embedding and scaling robust security practices throughout the product development lifecycle at SumUp. You will work closely with engineering teams to ensure security is integrated into our architecture, development processes, and delivery pipelines, helping us build secure and compliant financial products at scale.

What You’ll Do

  • Embed security practices across the entire product development lifecycle, ensuring security is a core part of engineering processes and decisions
  • Define, document, and promote secure architectural standards and best practices based on industry frameworks (OWASP, NIST, CIS)
  • Support engineering teams in implementing and configuring security tooling (SAST, SCA, container scanning) within CI/CD pipelines, ensuring efficiency and low friction
  • Drive the adoption and optimization of SAST tools, including rule tuning, developer training, and results analysis
  • Contribute to the Software Supply Chain Security program by assessing risks in third-party dependencies and promoting secure development practices (e.g., SCA tools, commit signing, SLSA)
  • Conduct security analyses and threat modeling for new and existing products, identifying vulnerabilities and guiding teams on secure design decisions
  • Collaborate with teams to design and implement secure authentication and authorization solutions (IAM, OAuth 2.0, OIDC, SAML)
  • Ensure systems and processes comply with security standards such as PCI-DSS
  • Deliver security training and awareness initiatives, including workshops and guidance for engineers on secure coding practices
  • Support and secure cloud-native environments, particularly in AWS and Kubernetes, including infrastructure hardening, secrets management, and runtime protection
  • Continuously improve security practices by building automation, improving tooling coverage, and establishing scalable security engagement models with engineering teams.

You’ll be great for this role if you:

  • You have solid experience in application security and DevSecOps practices
  • You have hands-on experience implementing security tooling (such as SAST, SCA, or container scanning) and integrating it into CI/CD pipelines
  • You have strong knowledge of modern security standards and frameworks (e.g., OWASP Top 10, OWASP ASVS) and secure design principles
  • You have experience with threat modeling and identifying risks in complex systems
  • You are familiar with cloud-native environments and security practices in AWS and/or Kubernetes
  • You understand authentication and authorization concepts (e.g., IAM, OAuth 2.0, OIDC)
  • You are comfortable working cross-functionally, influencing engineering teams, and driving adoption of security best practices
  • You take ownership, are pragmatic in your approach to security, and balance risk with business needs
  • You have strong English communication skills and enjoy working in a global environment

Why you should join SumUp
🌍 Global Experience: Collaborate with a diverse team of 3,000+ people from over 90 countries, and join our global off-sites and hackathons.
🤝 Collaborative Culture: Join a team that values diversity, innovation, and teamwork, where your ideas and contributions truly matter.
📈 Career Growth: Be part of a global team working on large-scale fintech products used by millions of businesses.
💙 Great Benefits: Health plans, meal vouchers (VR), Zenklub, Wellhub, life insurance, childcare allowance, and more.
📚 Learning & Development: Access an annual budget of R$ 10,000 for education, certifications, and conferences.
🌴 Time Off: Enjoy 30 additional days off through our Break4Me program after 3 years at SumUp.
💸 Grow with Us: Participate in our virtual stock program and benefit from SumUp’s success with company shares.


Learn More About SumUp
🇧🇷 Office tour at São Paulo
💡 Ask me anything: Engineering at SumUp
🚀 SumUp’s Innovation Hackathon
🤝 Get to know our hiring process

Ready to Join us?
Apply now and help us shape the future of financial solutions for small businesses

 

Job Application Tip

We recognise that candidates feel they need to meet 100% of the job criteria in order to apply for a job. Please note that this is only a guide. If you don’t tick every box, it’s ok too because it means you have room to learn and develop your career at SumUp.

SumUp
SumUp

0 applies

0 views

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say