What We're Looking For
You'll be ARQ's first Security Engineer based in Brazil – it's the chance to lay the foundation for how we do security in the region and shape how that function grows from here. You'll work closely with our global security team but have real autonomy in deciding what "good" looks like locally, from day one.
We're looking for someone who enjoys a multidisciplinary role. Security at ARQ spans Application Security, Security Operations, and Governance/Risk/Compliance, and we need someone comfortable moving across at least two of these three areas – because in a founding role, there's no one else to hand off the parts that don't fit your specialty.
What you'll do
Drive application security initiatives: threat modelling, secure code review support, API testing, and security pipeline improvements
Assess and secure AI/agentic workflows across the company — reviewing prompts, preventing destructive actions, and controlling data exposure
Build and improve SIEM detection rules, alert pipelines, and automated response playbooks (Datadog SIEM, CrowdStrike, Cloudflare)
Contribute to incident response readiness, including IR playbooks, tabletop exercises, and forensic procedures
Conduct cloud security assessments across AWS and Kubernetes environments
Establish and run the vendor security assessment process — building a scalable due diligence framework for third-party onboarding
What you'll need
4–7 years in information security, ideally having built or significantly shaped the security function at a startup or high-growth company - you've been the person who sets things up, not just maintains them
2+ years at a regulated fintech/bank/payment company
Hands-on experience with cloud infrastructure security (AWS, Kubernetes)
Familiarity with application security practices: threat modelling, secure code review, CI/CD pipeline hardening, and API security testing
Ability to assess and secure emerging AI/agentic tooling - you understand the risks of LLM integrations, MCP servers, and automated workflows, and can define practical guardrails
Working knowledge of SIEM platforms and detection engineering - you've written detection rules
Experience with endpoint security tooling (EDR/XDR) and identity & access management in a SaaS-heavy environment (Google Workspace, Okta/Cloudflare Access, SSO/SCIM)
Experience running or contributing to vendor security assessments and third-party due diligence
Strong written and verbal communication in English
Benefits
Competitive salary and benefits
Stock options, so you own part of what you build
Discretionary performance bonus
The latest tools and technology
A world-class team that will challenge and grow your skills
The opportunity to help build the best fintech app in Latin America
Office Policy: 3-4 days a week in-office
Security Engineer, Senior at ARQ: FAQ
Is the Security Engineer, Senior role at ARQ remote?
Yes — ARQ is hiring this Security Engineer, Senior as a remote role, with a preference for candidates in Sao Paulo, Brazil. You can apply from anywhere unless the listing specifies a region.
What skills are required for the Security Engineer, Senior role at ARQ?
This Security Engineer, Senior role is associated with the following skills and technologies:
- Senior
- Security
- Devops
- AI
- Kubernetes
- Remote
Read the full job description above for the complete list of requirements.
Is the Security Engineer, Senior role at ARQ full-time or contract?
ARQ is hiring this Security Engineer, Senior as a full time position.
How do I apply for the Security Engineer, Senior role at ARQ?
You can apply for the Security Engineer, Senior role at ARQ directly on this page using the Apply button. Remote candidates are welcome. Applications submitted through CryptoJobsList reach the employer directly.