About the job
bv stands among Brazil’s largest private banks, recognized by the Central Bank. For two consecutive years, the company has been named the best financial institution to work for in Brazil by the GPTW 2025 ranking. bv also holds the Diversity Seal in the Women category, reflecting a commitment to equity and inclusion.
The culture at bv centers on simplicity, integrity, partnership, and courage. Building strong relationships, encouraging innovation, and fostering a collaborative, inclusive workplace are core values. Diversity is intentional and celebrated throughout the organization.
As part of its ongoing growth, bv forms partnerships to make financial life easier for both individuals and businesses.
Role overview
The Application Security Specialist (AppSec) will join the team in São Paulo as a technical reference for secure software development. This role supports engineering teams throughout the development lifecycle, from code to production, helping to embed security practices without slowing down delivery.
Strong code reading skills, a focus on automation, and hands-on offensive security experience are essential. The position aims to scale security controls and practices across teams while minimizing friction for developers.
What you will do
- Support all stages of the development cycle as an Application Security expert
- Integrate, improve, and automate security controls within SDLC and CI/CD pipelines (including SAST, DAST, SCA, secrets management, and IaC checks)
- Work directly with developers to identify and resolve vulnerabilities
- Automate AppSec controls to help security scale across engineering teams
- Assess security for APIs, authentication, authorization, and other key flows
- Apply offensive security knowledge to anticipate attack vectors and prioritize risks
- Help define standards and best practices for secure coding
- Act as a liaison between Development, Architecture, and Security teams
Requirements
- Solid experience in Application Security (AppSec)
- Practical knowledge of:
- OWASP Top 10
- API Security (OAuth2, OIDC, JWT, mTLS)
- Web and backend vulnerabilities
- Strong code reading and comprehension skills in languages such as Java, Node.js, Python, Go, or similar
- Experience with automated security testing tools
