Director Security Engineer | DevSecOps

WellhubMaking every company a wellness company.
Eventual restrictions regarding residency or citizenship. You may specify timezone restrictions and office locations (exceptionally). (UTC +01:00 — UTC -03:00) ·BR /PT
Permanent
Senior (10+ years)
Requires work permit
Languages: Required: English | Nice to have: Portuguese

Remote details

To apply for this job you must be willing to work in the time zones between Lisbon and Brasilia.

This is a Brazil or Portugal remote position, meaning you can work from anywhere within these countries. Please note that this role is only open to candidates in Brazil or Portugal.

Description

THE OPPORTUNITY

We are hiring a Director of Security Engineering for our Information Security team in Brazil or Portugal! 

The Information Security team is responsible for protecting our subscription-based product serving millions of users. As a Director of Security Engineering, you will be the technical leader driving application security, DevSecOps practices, and security engineering across our 10 product verticals. This is a unique opportunity to build security capabilities in a high-growth environment. You will help construct the technical security strategy, architect security solutions, lead threat modeling, and establish secure development practices across all engineering teams. The role requires deep technical expertise in application security, cloud security, and modern DevSecOps practices.In this capacity, you will serve as the primary architect for our security engineering roadmap, ensuring that protection is integrated at every stage. You will oversee the deployment of automated security tooling, mentor senior engineers in advanced vulnerability research, and partner with product leaders to balance rapid feature delivery with robust risk mitigation. Your leadership will be pivotal in scaling our security posture to meet the demands of a global, multi-vertical ecosystem while fostering a culture of shared security responsibility.

YOUR IMPACT 

  • Lead the technical security strategy for product and application security, defining architecture standards, security baselines, and secure coding guidelines aligned with OWASP ASVS, NIST SSDF, and BSIMM frameworks.
  • Architect and implement a comprehensive DevSecOps pipeline, integrating SAST, DAST, SCA, and container scanning across all CI/CD pipelines serving 10 product verticals.
  • Drive threat modeling practices across critical product flows, partnering with engineering leads to identify and mitigate security risks before they reach production.
  • Design and implement a centralized security telemetry architecture, connecting application logs, WAF events, and fraud signals into a unified SIEM platform for real-time detection.
  • Lead the technical evaluation, selection, and implementation of security tools (SAST/DAST, SIEM/SOAR, PAM, API Gateway security, container security scanners).
  • Establish and mentor a team of 7-8 embedded DevSecOps engineers across product verticals, providing technical guidance and ensuring consistent security standards.
  • Own the technical roadmap for reducing MTTD from >48h to <1h and fraud detection from D+1 to real-time through security engineering and automation.
  • Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life balance.

Requirements

WHO YOU ARE

  • A seasoned security engineer with experience in application security, cloud security, or security engineering, with at least 4 years in a senior technical leadership role.
  • Deep expertise in secure software development lifecycle (SSDLC), threat modeling (STRIDE, PASTA), and security architecture for distributed systems and microservices.
  • Hands-on experience with security tooling: SAST (Checkmarx, Snyk, SonarQube), DAST (Burp Suite, OWASP ZAP), SCA, container scanning (Trivy, Prisma), and SIEM platforms (Elastic, Splunk, Sentinel).
  • Extensive knowledge of cloud security (AWS and/or GCP), including IAM, VPC security, secrets management, and container orchestration security (Kubernetes/EKS).
  • Experience building and scaling DevSecOps programs, integrating security into CI/CD pipelines, and mentoring engineering teams on secure coding practices.
  • Proficiency in at least two programming languages (Python, Go, Java, or JavaScript) with the ability to review code, write security tooling, and automate security workflows.
  • Familiarity with compliance frameworks (ISO 27001, PCI DSS, LGPD/GDPR) and how they translate into technical security controls.
  • Effective communication skills (Portuguese and English) to translate complex technical security concepts into actionable guidance for engineering teams at all levels.

We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don't match the job description 100%. For this specific role, please note that prior experience in application security engineering and DevSecOps pipeline implementation is a mandatory requirement.

Perks

WHAT WE OFFER YOU 

We're a wellness company that is committed to the health and wellbeing of our employees. Our benefits include:

WELLHUB: We believe in our mission and encourage our employees and their families to take care of their wellbeing too. Access digital fitness programs, and online wellness resources for meditation, nutrition, mental health support, and more. You will receive the Gold plan at no cost, and other premium plans will be significantly discounted.

FITNESS: Additional fitness subsidy to access onsite gyms and fitness studios.

FLEXIBLE WORK: At Wellhub, flexibility fosters a happier, healthier, and more productive work environment for everyone. As a Flexible First company, we offer two work model options: flexible hybrid and full remote, and make the office a place for collaboration, community, and team building. The model for this role can be discussed with your recruiter and hiring manager. We offer all employees a home office stipend and a monthly flexible work allowance to help cover the costs of working from home.

FLEXIBLE SCHEDULE: We understand that together, Wellhubbers and their leaders can make the best decisions for their own individual scopes. This includes flexibility to adjust their working hours based on their personal schedule, time zone, and business needs. 

PAID TIME OFF: We know how important it is to take time away from work to recharge. Employees receive a minimum of 25 days paid holiday per year with an additional day for each year of tenure (up to 5) in addition to annual holidays (including an extra holiday on your birthday!).

PARENTAL LEAVE: Welcoming a new child is one of the most special moments in your life and we want our employees to take the time to be present and enjoy their growing family. We offer 100% paid parental leave to all new parents and extended maternity leave.

CAREER GROWTH: Outstanding opportunities for personal and career growth. That means we maintain a growth mindset in everything we do and invest deeply in employee development.

CULTURE: An exciting and supportive environment filled with passionate individuals from all over the world! You’ll partner with global colleagues and share in the success of a high-growth technology company disrupting the health and wellness space. Our value-based culture of trust, flexibility, and integrity makes this possible every day.
 

Diversity, Equity, and Belonging at Wellhub

We aim to create a collaborative, supportive, and inclusive space where everyone knows they belong. 

Wellhub is committed to creating a diverse work environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex, gender identity or expression, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law.