Security Engineer

Thunes
São Paulo
Workplace: HybridFull timeFunction: CybersecuritySkills: ["Problem-solving","Communication","Collaboration"]

Security Engineer at Thunes Financial Services focusing on bridging Infrastructure Security and Application Security in a hybrid role. You will implement CI/CD security, secure cloud infrastructure (AWS/GCP), manage vulnerability detection, automate security workflows, and ensure compliance for SOC-2 and PCI audits while supporting regulatory exams.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Thunes
Thunes
4 months ago

Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live

Job Summary

Security Engineer at Thunes Financial Services focusing on bridging Infrastructure Security and Application Security in a hybrid role. You will implement CI/CD security, secure cloud infrastructure (AWS/GCP), manage vulnerability detection, automate security workflows, and ensure compliance for SOC-2 and PCI audits while supporting regulatory exams.
Location: São Paulo
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •CI/CD Security Integration: Design, build, and maintain automation to integrate security testing (SAST/DAST/SCA) directly into deployment pipelines.
  • •Full-Stack Security: Own security across the lifecycle—from securing cloud infrastructure (AWS/GCP) to code reviews and architectural risk assessments.
  • •Vulnerability Management: Manage detection stack using modern vulnerability scanning and dependency management tools to identify, prioritize, and track risks.
  • •Security Automation: Build and maintain automated workflows for vulnerability reporting, triage, and remediation with AI-powered automation to accelerate response times.
  • •Compliance Engineering & Incident Response: Monitor security controls to meet cybersecurity compliance requirements (SOC-2, PCI) and participate in incident response.

Key Requirements

  • •Pipeline Proficiency: Hands-on experience building security guardrails within CI/CD tools (e.g., GitHub Actions, GitLab CI, or Jenkins).
  • •Hybrid Expertise: Deep experience in both Infrastructure Security (Cloud/K8s) and AppSec (OWASP Top 10, Secure SDLC).
  • •Tooling Experience: Proficiency with enterprise vulnerability management platforms and automated dependency scanning solutions.
  • •Automation Mindset: You write code (Python, Go, or Bash) to handle bugs and use AI-driven automation to streamline security workflows.
  • •Fintech Fluency: Understanding of working in a regulated environment and translating compliance requirements into technical reality.
Experience:Fintech
Skills:Problem-solvingCommunicationCollaboration
Languages:English
Tech Stack:PythonGoBashGitHub ActionsGitLab CIJenkinsAWSGCPSASTDASTSCAOWASP Top 10PCISOC-2Vulnerability managementDependency scanning

Company Brief

Thunes
Provides a global cross-border payments network enabling businesses to send and receive payments across markets via a single integration, serving merchants, fintechs, remitters, and banks with real-time settlement and compliance tools.
Industry: Fintech Infrastructure
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Headquarters: Singapore, Singapore
Founded: 2016
WebsiteLinkedIn