Job Overview
Job description
- Salary:
- USD 50,000 - 60,000 per year
- Location:
- Brazil
- Work arrangement:
- On-site
Role Summary
Senior Product Security Engineer
We're hiring a Senior Product Security Engineer to work hand-in-hand with developers to secure the product across its entire lifecycle. You'll be the person who makes our platform defensible — through design reviews, threat modeling, hands-on penetration testing, and secure-coding partnership — and you'll do it as a collaborator who helps engineers ship securely, not a gatekeeper who slows them down.
This role partners closely with product engineering and platform engineering teams.
Responsibilities
- Partner directly with developers to secure the product across the Software Development Life Cycle (SDLC), embedding security early rather than bolting it on at the end.
- Lead security design and architecture reviews, and run threat modeling on new features and services.
- Perform hands-on penetration testing of web applications and Application Programming Interfaces (APIs), and translate findings into clear, prioritized, fixable work.
- Conduct secure code reviews and help define secure-coding standards and security acceptance criteria.
- Operate and tune Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and dependency / supply-chain scanning, and triage what they surface.
- Help engineers understand the "why" behind findings so the same class of issue doesn't recur.
- Contribute security evidence and rigor to our compliance posture (System and Organization Controls 2, or SOC 2, ISO 27001, etc.).
What You'll Need (Required)
- A strong track record in product or application security — you've measurably made real products more secure.
- Hands-on penetration testing experience against web applications and APIs.
- Deep understanding of how modern web applications work — single-page front ends, APIs, authentication and authorization (for example, OAuth 2.0 / OpenID Connect), sessions, and the common ways each is attacked (for example, the Open Worldwide Application Security Project, or OWASP, Top 10).
- Experience running security design reviews and threat modeling.
- Solid understanding of the SDLC and how to embed security into it.
- Strong communication skills — you work directly with developers and can explain risk in terms they'll act on.
Requirements
Nice to Have
- Familiarity with open-source security tooling (for example, OWASP ZAP and Burp Suite Community Edition for testing, Semgrep for SAST, Trivy or Grype for dependency and container scanning, Nuclei for templated scanning).
- A relevant offensive-security certification (for example, Offensive Security Certified Professional, or OSCP).
- Cloud security experience (Amazon Web Services, Microsoft Azure, or Google Cloud Platform) and container / Kubernetes security.
- Experience supporting a SOC 2, International Organization for Standardization (ISO) 27001, or similar program.
- Background in enterprise or regulated environments where deployment security is non-negotiable.
What Success Looks Like (First 90 Days)
- You've reviewed the product's architecture and threat surface and identified the highest-priority security risks.
- A repeatable, lightweight process exists for security design reviews on new work.
- Security findings have a clear triage-to-remediation path, and developers know how to engage you early.
- Location and Work Model
- Remote in Brazil
- Salary: $50K – $60K
About the Company
ABOUT TESSERA LABS
Tessera Labs is a new category of enterprise software: an AI platform that changes how the world's largest companies run.
Every large enterprise carries the same weight — decades of accumulated process, data, and code that no longer match the business it has become. Changing any of it is a program measured in years and hundreds of millions of dollars, staffed by armies of consultants, and it fails more often than anyone admits. Most companies have quietly accepted this as the cost of being large.
We don't. Tessera is a transformation engine: a governed, multi-agent platform that understands an enterprise's process, data, and code as one connected system and changes it in weeks rather than years. We're vendor-agnostic by design — SAP, Salesforce, Workday, Oracle, Snowflake, MuleSoft — and tied to none of them.
Two things make this hard, and they're the reason the job is interesting. Governance: every action is logged, traceable, and reversible, because our customers are regulated and these are the systems that close their books. And generality: the platform has to work on landscapes it has never seen, at companies whose complexity is genuinely unique to them.
We sell a product, not a service. Our people are here to make the product successful, not the other way around. If you've watched enterprise AI companies quietly become consultancies, that distinction is the one to press us on.
- Role:
- Senior Product Security Engineer
- Job Type:
- Contract
Company profile
tessera-labs
tesseralabs.aiTessera Labs is an AI-native platform for enterprise transformation that uses governed, multi-agent AI to modernize ERP, CRM, HCM and finance systems. It aims to cut transformation timelines from years to weeks and costs by more than half, drawing on expertise across SAP, Salesforce, Workday and other systems of record, for industries including life sciences, semiconductors, financial services and energy.