Product Security Engineer (remote in Brazil)
Summary
KnowBe4 is hiring a Product Security Engineer in São Paulo to secure its applications and cloud environments: running security assessments, code reviews, and threat models, remediating vulnerabilities, and embedding security into the SDLC. Core stack includes AWS, Terraform, Python, Ruby, PHP, Go, JS, Burp Suite, and SAST/DAST tooling.
KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15-years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.
Please submit your resume in English.
To learn more about our team and office culture in São Paulo, Brazil, visit the following links.
Careers Page:
Glassdoor: https://www.glassdoor.com/Location/KnowBe4-S%C3%A3o-Paulo-Location-EI_IE969384.0,7_IL[…]M_-C1lsxoZq7Cx8IriVE8MkrzuTmnJzqego77RAWZz9sqGt_55BflwYKpQeg
LinkedIn:
Responsibilities:
- Application Security Testing & Pentesting: Conduct automated and manual security assessments and penetration tests across web, mobile, and traditional applications.
- Code Security Reviews: Analyze source code across multiple programming languages to identify vulnerabilities and guide remediation before and after production deployment.
- Vulnerability Triage & Remediation: Work closely with engineering teams to assess, prioritize, and resolve application vulnerabilities.
- Threat Modeling & Automation: Maintain threat models and build security automations to streamline security testing workflows.
- Security Engagement: Partner with product and development teams to embed secure coding practices throughout the software development lifecycle (SDLC).
Requirements:
- Experience in Application Security, Penetration Testing, or Red Teaming.
- Pentesting Expertise: Strong hands-on experience with both automated and manual web, mobile, and traditional application pentesting
- Code Comprehension: Proven ability to read and analyze source code in multiple languages (such as Ruby, PHP, Go, JavaScript, or Python)
- Security Fundamentals: Broad understanding of web application vulnerabilities (e.g., OWASP Top 10, CWE) and core information security concepts
- Language & Communication: Strong technical English communication skills (written and spoken) to collaborate smoothly across international teams
- Cultural Fit: Collaborative, open mindset with a strong focus on teamwork and positive team dynamics
Preferred / Nice-to-Have
- Experience with cloud computing environments (AWS, Terraform)
- Familiarity with security tools (e.g., Burp Suite, SAST/DAST, dependency scanning)
- Experience with Python scripting or leveraging AI tools in security workflows
- Relevant industry certifications (e.g., OSCP, OSWE, GPEN, CISSP)
Our Fantastic Benefits
Note: An applicant assessment and background check may be part of your hiring procedure.
Individuals seeking employment at KnowBe4 are considered without prejudice to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, sexual orientation or any other characteristic protected under applicable federal, state, or local law. If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please visit www.knowbe4.com/careers/request-accommodation.
No recruitment agencies, please.
Skills
As published by greenhouse · 10 questions
Basics
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location
Short answers (4)
- If selected "Events", please specify. optional
- If selected "Other", please specify. optional
- If selected "Referral", who referred you? optional
- If "Other", please specify. optional
Pick from a list (6)
- How did you learn about us? Select ALL that apply.
- Are you a current employee at KnowBe4?
- How well do you know us? Please select all of the following sources/tools that you have used to research KnowBe4 and learn more about us.
- CONSENT TO DATA PROTECTION POLICY FOR JOB APPLICANTS (“POLICY”) https://www.knowbe4.com/job-applicant-data-protection-policy-brazil By checking below and submitting this application, (a) you acknowledge that you have read, understood, and agreed to the above linked Policy, and consent to the collection, use, and/or disclosure of your personal data by us for the purposes set out in this Policy; and (b) in the event that we have received your job application or personal data from any third party that you have been engaged with (e.g., a recruiter agency, etc.), you warrant that such third party has been duly authorised by you to disclose your personal data to us for the purposes set out in this Policy.
- I understand and agree that KnowBe4 does not permit the use of AI tools or assistance during the interview process. Exceptions may be made for approved reasonable accommodations (please visit www.knowbe4.com/careers/request-accommodation to make a request).
- Are you located in or a national of Cuba, Iran, North Korea, or Syria, or are currently located in the Crimea, Donetsk, Luhansk, Kherson, or Zaporizhzhia territories?

