NVIDIA
Jusbrasil
Security Engineer Partner | AppSec
About the challenge
We were born in Salvador, in 2008, outside the traditional tech hubs of the country. Today, we are the largest legal intelligence platform in Brazil and the most accessed legal website in the world.
More than 20 million people use Jusbrasil every month. More than 80% of Brazilian lawyers are registered on the platform. We organize more than 7 billion public interest legal documents.
With Jus IA, we expand the legal reasoning of those who use the platform. It is not a separate product: it is intelligence built for Law, not trained with the generic internet. The vision is clear: to be the universal legal agent for every Brazilian, so that no one faces a legal issue alone.
Today, we are 670 Jusbrasileiros, almost half in technology and product, living in more than 125 cities in Brazil and abroad. Real remote work: you choose where to live without losing the right job.
If you deliver even when no one is watching, take ownership of what needs to be done, and refuse the obvious path, this is the most difficult and most interesting game that exists in legaltech today.
And your next step is to elevate justice with us.
The Security Partner (AppSec) will be responsible for ensuring that Jusbrasil's B2B products are built with a solid security foundation — acting in an integrated and embedded manner within the Jus Soluções team. The role is hands-on and requires a builder mentality: more than reviewing what has already been done, we expect someone who participates from the beginning of the development cycle, anticipates risks, and implements real solutions.
Main responsibilities
- Act as the security focal point within Jus Soluções, participating in plannings, refinements, and RFCs with the engineering and product teams.
- Lead the implementation of robust authentication and Single Sign-On (SSO), including domain separation and integration with external identity providers.
- Ensure that applications, APIs, and integrations are developed with Secure by Design principles — from design to delivery.
- Conduct recurring threat modeling on critical products and flows, identifying and prioritizing risks based on business impact.
- Conduct continuous security reviews — of code, architecture, and external integrations — in conjunction with the engineering teams.
- Build and maintain AppSec practices: secure coding guidelines, review checklists, and documentation of technical security decisions.
- Translate technical risks into business impact for product stakeholders, leadership, and clients — including actionable reports and recommendations.
What we are looking for
- Solid experience with software development
- Practical knowledge in Application Security: OWASP Top 10, API Security, authentication (OAuth 2.0, JWT, SSO, OIDC) and data protection.
- Experience with cloud (GCP, AWS, or Azure) and modern architecture: microservices, APIs REST/gRPC, and external integrations.
- Ability to influence teams without direct authority — acting as a technical partner.
- Fluency in AI: Experience using Generative AI tools as part of the workflow.
- Proactive and problem-solving profile, with autonomy to build solutions from scratch and comfort with ambiguity.
Desirable requirements
- Experience with LGPD and data protection requirements applied to digital products
- Familiarity with secure infrastructure and development of projects with open-source solutions.
