Skip to main content
Open to Brazil
Stone

Senior Security Architect (AppSec)

Remote Full time Software Engineering Financial Services

Posted 5 days ago

About Stone
We are much more than a company of payment machines! Stone is a technology and financial services company focused on the customer. We were born with the purpose of being protagonists in the transformation of the payment industry, serving Brazilian entrepreneurs and turning their dreams into results. We are the largest independent payment methods company in Brazil, with more than fifteen thousand people spread across the five regions of the country, in a scenario full of challenges and opportunities. We value teamwork, flexibility, continuous development, and tireless disruptive thinking in the search for solutions for our REASON.

Our Culture

Here, we live our culture day by day, guided by these 5 values:

  • Customer is the reason Customer is the reason we exist, and we only succeed if they succeed.
  • Owner's mindset We do what is right, the right way, with responsibility and technology to make better decisions.
  • Direct to the point Depth to understand and simplicity to solve.
  • Excellence is a team game We build a long-term business, in a team, and with collaboration.
  • Passion in every detail We do it with passion, attention to detail, and the desire to surprise to help the customer win.

The AppSec Team

The AppSec team aims to ensure that applications are developed, maintained, and used securely and protected against cyber threats — including the growing number of systems that integrate language models (LLMs) and generative AI in our products and engineering flows. We seek to prevent our systems from having vulnerabilities that can be exploited by cybercriminals, aiming to protect sensitive data, user privacy, and application integrity.

Main Objectives We Pursue

  • Defining security architectural standards, together with Engineering and Product teams, to be used in building and operating the systems we create — including applications that utilize LLMs, agents, and RAG pipelines.
  • Ability to create plans that define an architectural standard for new systems that include a viable technical migration roadmap for legacy systems.
  • Identification of vulnerabilities and their respective risk degree, and with that help prevent attacks.
  • Participation in the analysis and response to security incidents, seeking continuous improvement of our processes and practices.
  • Training, awareness, and collaboration with development teams to utilize good programming practices and software architectural standards — including the secure use of AI assistants (Copilot, Cursor, and similar) in the development cycle.

What Is It Like to Be a Senior Security Architect in Development (AppSec)?

Among the expected work activities are:

  • Defining and implementing security strategies for applications, including those integrating LLMs and generative AI components.
  • Collaborating with development teams to integrate security practices from the beginning of the software lifecycle.
  • Performing architecture, code, and design reviews to identify potential vulnerabilities and security issues.
  • Defining guardrails and standards for applications with LLMs, addressing risks such as prompt injection, insecure output handling, data leakage via outputs, excessive agency in agents, and cost abuse (denial-of-wallet).
  • Establishing guidelines for the safe use of AI-assisted development tools by engineering teams, balancing productivity, intellectual property protection, and prevention of sensitive data leakage.
  • Developing and promoting security standards and best practices for the entire development team.
  • Providing technical guidance and security training for development teams.
  • Knowing tools for automated quality validation in the CI/CD pipeline such as SAST, DAST, SCA, and Secret Scanning.
  • Tracking trends and evolutions of security threats and constantly updating protection measures — including the emerging threat landscape for AI systems.
  • Developing creative solutions for complex security problems that balance business needs and risks.
  • Using your security expertise and intuition to seek threats in corporate and production environments.
  • Reading and communicating in English.

What We Expect From You

  • Ability to identify opportunities for improvement, new solutions, and alerts that may benefit and/or facilitate operations.
  • Using influence and negotiation skills to guide teams in correcting problems or using appropriate architectures from a security perspective.
  • Ability to work autonomously.
  • Communicate concisely, frankly, and assertively, knowing how to translate complex problems into accessible language for the audience you communicate with.
  • Initiative to seek or request information when needed.
  • Possess a higher education degree (completed or ongoing) in Information Security, Computer Science, Information Systems, Software Engineering, or related fields.
  • Passion for learning and thriving in a dynamic and constantly changing environment.
  • Knowledge of common attack vectors.
  • Experience in threat modeling.
  • Experience in effective mechanisms for protecting APIs and mobile applications.
  • Knowledge of basic cloud security services and concepts (AWS, Azure, or GCP).
  • Ability to work within multidisciplinary teams with agile methodology.
  • Familiarity with security risks in applications that use LLMs and generative AI (references such as OWASP Top 10 for LLM Applications and MITRE ATLAS).

What Increases Your Chances

  • Experience participating in incidents seeking to identify root causes.
  • Experience in projects where financial area requirements are applicable (Bacen, PCI, SOX, among others).
  • Solid programming knowledge.
  • Practical experience in threat modeling and defining controls for applications with LLMs in production (chatbots, copilots, agents, RAG).
  • Experience in API protection that exposes AI models: direct and indirect prompt injection, structured output validation, authorization controls in function calling, and tool use.
  • Experience in defining policies and controls for corporate use of generative AI tools (code assistants, chat platforms), including data leakage prevention and intellectual property protection.
  • Knowledge of emerging AI governance and security frameworks (NIST AI RMF, ISO/IEC 42001).

Our Compensation and Benefits Package

  • Fixed Salary
  • Variable Compensation Package* (PLR, ILP, or Commission - provided according to position eligibility, not being a freely chosen model)
  • Health and Dental Plan with co-payment (except for professionals with disabilities who do not have co-payment)
  • Virtual Health Team: telemedicine team available 24 hours a day, 7 days a week.
  • Medication subsidy
  • Meal Voucher and/or Food Voucher - Pluxee* (except for Executive Sales positions - 6hrs)
  • Childcare Assistance (for children up to 5 years and 11 months)
  • Assistance for Disabled Children
  • Life Insurance
  • Fuel Assistance or commuting assistance*
  • Home office assistance* (only for Hybrid or Remote contracts)
  • Welcome Kit for new parents
  • SESC partnership*
  • Education Benefit - internal self-development platform (Studa and Stone Library)
  • Acolhe360º - emotional support (free)
  • Quick Massage and Clinic*
  • Optional benefits: Wellhub - TotalPass - Pet Club - Flash - Férias&Co - VT - Allya - Educational partnerships
Apply Now
Share

Next step

Ready to apply?

You apply straight with the employer — no middleman, no fees.

Apply Now

Keep exploring

More remote jobs open to you

Browse all remote positions available to Brazil.

View all Brazil jobs

Get New Remote Jobs Every Week

Join the newsletter and receive the latest remote opportunities directly in your inbox.

Free forever. Unsubscribe anytime. No spam.