Kenvue 目前正在招聘 a:
我們做什麼
在 Kenvue,我們意識到日常護理的非凡力量。我們以一個多世紀的傳統為基礎,植根於科學,是標誌性品牌的品牌 - 包括您已經熟悉和喜愛的 NEUTRGENA®、AVEENO、TYLENOL®®、LISTERINE®、JOHNSON'S® 和 BAND-AID®。科學是我們的熱情所在;關心就是我們的才能。
我們是誰
我們的全球團隊由 ~ 22,000 名才華橫溢的員工組成,他們的職場文化中,每個聲音都很重要,每一個貢獻都受到讚賞。 我們熱衷於洞察, 創新並致力於為我們的客戶提供最好的產品。憑藉專業知識和同理心,成為 Kenvuer 意味著每天有能力影響數百萬人。我們以人為本,熱切關懷,以科學贏得信任,以勇氣解決——有絕佳的機會等著您!加入我們,塑造我們和您的未來。有關更多資訊,請按兩下 here.
Role reports to:
Product Owner Secure the Developer位置:
Latin America, Brazil, Sao Paulo, Sao Paulo工作地點:
混合你會做什麼
Kenvue is currently recruiting for:
Application Security Engineer
This role can be based in Sao Paulo, or Sao Jose, Brazil, part of a global team, and reports to the Director, Application & Cloud Security & xDLC.
Who We Are
At Kenvue, we realize the extraordinary power of everyday care. Built on over a century of heritage and rooted in science, we’re the house of iconic brands - including NEUTROGENA®, AVEENO®, TYLENOL®, LISTERINE®, JOHNSON’S® and BAND-AID® that you already know and love. Science is our passion; care is our talent. Our global team is made up of 22,000 diverse and brilliant people, passionate about insights, innovation and committed to deliver the best products to our customers. With expertise and empathy, being a Kenvuer means to have the power to impact life of millions of people every day. We put people first, care fiercely, earn trust with science and solve with courage – and have brilliant opportunities waiting for you! Join us in shaping our future–and yours.
What You Will Do
As an Application Security Engineer, you will be safeguarding digital assets and data through advanced cybersecurity solutions and processes. We are seeking a highly motivated and talented Application Security Senior Engineer to join our dynamic team. If you have a passion for identifying and mitigating security risks in applications, working with developers, we invite you to apply and be a part of our dedicated cybersecurity workforce.
Key Responsibilities
- Conduct comprehensive architecture security reviews of applications to identify vulnerabilities and weaknesses.
- Secure cloud-native services, including container orchestration platforms like Kubernetes.
- Maintain and operate various security tools SAST, DAST, CWPP, CSPM, SSPM, CASB...
- Perform penetration testing, code reviews, and vulnerability scanning to ensure the security of web and mobile applications.
- Collaborate with development teams to provide guidance on secure coding practices and assist in the remediation of identified security issues, or misconfigurations.
- Develop and maintain security standards, policies, procedures, work instructions and requirements related to application security.
- Stay current with the latest security trends, threats, and vulnerabilities affecting application security.
- Participate in incident response and security incident investigations related to application security.
- Work closely with cross-functional teams to integrate security into the technology development lifecycle.
- Automate vulnerability scanning, and compliance checks into development workflows.
- Proficiency in cloud eco-systems such as AWS, GCP or Azure.
- Knowledge of DNS and IP management
- Develop, maintain and run security automation scripts using languages such as python or other software and scripting languages.
- Knowledge of source code systems such as Bitbucket or GitHub.
What We Are Looking For
Required Qualifications
- Bachelor’s degree in computer science, Information Security, or related field or 5+ years of cyber security experience.
- Advanced English Level (C1 minimum)
- Strong background in Software Development
- Strong knowledge of software development tools such as IDEs, security, and code quality tools.
- Working experience with application security assessments, vulnerability testing, and secure code reviews.
- Knowledge of web application security vulnerabilities and common attack vectors (e.g., OWASP Top 10).
- Experience with security assessment tools such as Burp Suite, Nessus, OWASP ZAP, Snyk, etc.
- Understanding of encryption technologies, authentication mechanisms, and secure coding practices.
- 5+ years’ experience in software development/engineering with programming/scripting skills in languages like Java, Python, Ruby, or similar languages.
- Experience with roles, processes, and tools to enable a high-performing DevOps practice in an Agile environment.
- Strong knowledge of Kubernetes and containerization (Docker).
- Relevant security certifications such as CISSP, CEH, CompTIA Security+, Azure Security Engineer, and AWS certified – Security Specialty, and Cloud are a plus.
- Excellent problem-solving and analytical skills, along with effective communication and teamwork abilities.
- Experience leading a small team and facilitating stand-up meetings.
- Strategic thinking to align security goals with business objectives.
- Experience with Atlassian tools such as Jira, Confluence, and Bitbucket.
- Knowledge of either Azure or AWS cloud platforms and associated security standards and best practices.
Desired Qualifications
- Mobile application development
What’s In It For You
- Competitive Benefit Package
- Paid Company Holidays, Paid Vacation, Volunteer Time & More!
- Learning & Development Opportunities
- Employee Resource Groups
- This list could vary based on location/region
Kenvue is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, or protected veteran status and will not be discriminated against on the basis of disability.
*please submit your resume in English.
如果您是殘障人士,請查看我們的 殘障人士援助頁面瞭解如何申請便利