Senior Application Security Engineer

Hyundai Autoever · Piracicaba, SP, BR

**Description:** ---------------- Hyundai AutoEver is seeking a Senior Application Security Engineer to join its U.S.\-based Cyber Defense team in a remote role. The successful candidate will work closely with application development, platform engineering, DevOps, and cybersecurity teams to strengthen application security across the Software Development Lifecycle (SDLC). This role is responsible for establishing Secure SDLC requirements, integrating security controls into CI/CD pipelines, improving container security, and ensuring vulnerabilities are identified and remediated before production release. This position requires a strong combination of application security, DevSecOps, secure coding practices, and vulnerability management expertise, along with the ability to collaborate effectively with U.S.\-based and global teams. **Key Responsibilities** * Define, maintain, and promote Secure SDLC policies, standards, and security requirements. * Integrate security controls and automated security testing into CI/CD pipelines. * Implement and manage SAST, DAST, Software Composition Analysis (SCA), and dependency vulnerability scanning. * Develop and maintain hardened container images and secure container repositories. * Support secure design reviews, threat modeling activities, and application security assessments. * Partner with development teams to identify, prioritize, and remediate application security vulnerabilities. * Validate remediation efforts and support secure release decisions. * Improve application security processes, tooling, automation, and metrics. * Provide guidance on secure coding practices, application security risks, and vulnerability remediation. * Collaborate with U.S.\-based engineering, platform, and cybersecurity teams to strengthen application security across the organization. **Working Hours (Brazil Time)** * 12:00 PM to 9:00 PM during U.S. Daylight Saving Time (November through March) * 1:00 PM to 10:00 PM during the remainder of the year **Requirements:** ----------------- * Advanced to Fluent English. * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Software Engineering, or a related field. * 5\+ years of professional experience in Application Security, Product Security, Secure Software Development, DevSecOps, or related disciplines. * Hands\-on experience implementing Secure SDLC practices and integrating security throughout the software development lifecycle. * Experience with SAST, DAST, Software Composition Analysis (SCA), dependency scanning, and vulnerability management processes. * Strong understanding of OWASP Top 10, secure coding practices, application security testing, and modern software development methodologies. * Experience with CI/CD platforms, DevOps practices, and security automation. * Experience securing containerized applications and container platforms such as Docker and Kubernetes. * Strong troubleshooting, analytical, and collaboration skills. * Experience with enterprise Application Security platforms and tools for SAST, DAST, SCA, and container security. * Experience with cloud\-native application environments and modern application architectures. * Hands\-on experience with Kubernetes, Docker, container registries, and container security solutions. * Experience conducting threat modeling and secure architecture reviews. * Experience working in large\-scale, multinational, or highly regulated corporate environments. **Preferred Qualifications** * Master's degree in Cybersecurity, Computer Science, Information Technology, or a related field. * Bilingual proficiency in English and Korean. * Professional certifications such as: * CSSLP (Certified Secure Software Lifecycle Professional) * CISSP (Certified Information Systems Security Professional) * CISM (Certified Information Security Manager) * GWAPT (GIAC Web Application Penetration Tester) * Certified DevSecOps Professional * Equivalent Application Security certifications