Skip to main content
Back to Jobs

Security Engineer, Lead

Drive application security roadmap with threat modeling and secure code review

As ARQ's first Security Engineer in Brazil, you will drive the application security roadmap including threat modeling standards, secure code review practices, API security testing strategy, and security pipeline architecture. You will also define the company's approach to securing AI/agentic workflows, set technical direction for detection engineering and automated response, and own incident response readiness at a program level. This role inv...

Why This Role?

Shape how security function grows in Brazil as the first local hire with real autonomy from day one

Key Responsibilities

  • Drive application security roadmap including threat modeling standards and secure code review practices
  • Define approach to securing AI/agentic workflows with guardrails for prompts and data exposure
  • Set technical direction for detection engineering, alert pipelines, and automated response using Datadog SIEM, CrowdStrike, and Cloudflare
  • Own incident response readiness by designing IR playbooks, leading tabletop exercises, and acting as technical lead during major incidents
  • Set standards for cloud security assessments across AWS and Kubernetes, reviewing findings and tackling complex environments
  • Own and continuously improve the vendor security assessment framework, handling highest-risk vendor reviews

Requirements

  • 7+ years in information security with experience building or maturing a security function from the ground up
  • 2+ years at a regulated fintech, bank, or payment company
  • Deep hands-on expertise in cloud infrastructure security (AWS, Kubernetes) with ability to architect controls
  • Proven experience driving application security programs including threat modeling frameworks and secure code review standards
  • Experience with API security testing strategy and CI/CD pipeline hardening
  • Demonstrated ability to define practical security practices across application security, security operations, and GRC

Required Skills

cloud securityawskubernetesapplication securitythreat modelingincident responseDetection EngineeringVendor Risk ManagementTechnical Mentoring

Indonesia Context

Working Hours Overlap:
Flexible — work your own hours
See remote (USD) vs local pay →

Keywords

Security Engineer LeadApplication Security RoadmapAI Workflow SecurityDetection EngineeringCloud Security AWS KubernetesIncident Response PlaybooksVendor Security AssessmentFintech Security
View Original Description from Ashby Job Boards

Original description from Ashby Job Boards

WHAT WE'RE LOOKING FOR You'll be ARQ's first Security Engineer based in Brazil – it's the chance to lay the foundation for how we do security in the region and shape how that function grows from here. You'll work closely with our global security team but have real autonomy in deciding what "good" looks like locally, from day one. We're looking for someone who enjoys a multidisciplinary role. Security at ARQ spans Application Security, Security Operations, and Governance/Risk/Compliance, and we need someone comfortable moving across at least two of these three areas – because in a founding role, there's no one else to hand off the parts that don't fit your specialty. WHAT YOU'LL DO - Drive the application security roadmap: threat modelling standards, secure code review practices, API security testing strategy, and security pipeline architecture - Define the company's approach to securing AI/agentic workflows – setting guardrails for prompts, destructive actions, and data exposure, and advising other teams building with LLMs/MCP servers - Set the technical direction for detection engineering, alert pipelines, and automated response across the security stack (Datadog SIEM, CrowdStrike, Cloudflare), and raise the bar on how the team designs and reviews detections - Own incident response readiness at a program level: design IR playbooks, lead tabletop exercises, and act as technical lead during major incidents - Set the standard and approach for cloud security assessments across AWS and Kubernetes, reviewing findings from other engineers and tackling the most complex environments directly - Own the vendor security assessment framework itself: continuously improving the due diligence process and handling the highest-risk vendor reviews - Act as a technical mentor to mid and senior engineers, reviewing their detection logic, assessments, and playbooks without formal management responsibilities WHAT YOU'LL NEED - 7+ years in information security, including demonstrated experience building or substantially maturing a security function or program from the ground up - 2+ years at a regulated fintech/bank/payment company - Deep, hands-on expertise in cloud infrastructure security (AWS, Kubernetes), able to architect controls - Proven experience driving application security programs: threat modelling frameworks, secure code review standards, CI/CD pipeline hardening, and API security testing strategy - Demonstrated ability to define practical security guardrails for AI/agentic tooling – you understand the risks of LLM integrations, MCP servers, and automated workflows at an architectural level - Strong detection engineering background – you've designed detection strategy and mentored others in writing rules - Deep experience with endpoint security tooling (EDR/XDR) and identity & access management architecture in a SaaS-heavy environment (Google Workspace, Okta/Cloudflare Access, SSO/SCIM) - Experience designing or significantly evolving a vendor security assessment/third-party due diligence program - Excellent written and verbal communication; comfortable representing security decisions to leadership and cross-functional stakeholders - Business fluent in English BENEFITS - Competitive salary and benefits - Stock options, so you own part of what you build - Discretionary performance bonus - The latest tools and technology - A world-class team that will challenge and grow your skills - The opportunity to help build the best fintech app in Latin America - Office Policy: 3-4 days a week in-office

Salary Context

Similar Engineering roles on LokerDollar pay around $215k/yr (range $19.575k–2745.996k/yr, n=426 active listings).

Hiring at ARQ

ARQ has 12 other active roles on LokerDollar and has been hiring here since Jul 4, 2026 — across Engineering, Data & Analytics, Product, Marketing.

View all ARQ openings →
Track this application + get a follow-up reminder

Free account · no credit card · Log in

Pro $9/mo · unlimited applies + AI resume

Remote-friendly · fits your timezone
Company
ARQ
Source
Ashby Job Boards
Job Type
full time
Location
Remote
Category
Seniority
lead
PostedFresh
Jul 21, 2026

Share this job

Help a friend find their next remote role.

Frequently asked questions

Is Security Engineer, Lead at ARQ a remote job?
This role is based in Remote. See the listing for remote/onsite details.
What type of employment is Security Engineer, Lead at ARQ?
This is a full time position.
How do I apply?
Click the "Apply" button on this page to go to the official application at ARQ.

Explore related

Market data & reports

Salary & skill-demand research built from our own listings data.

From the blog

Track this application + get a follow-up reminder

Free account · no credit card · Log in

Pro $9/mo · unlimited applies + AI resume