Legrand Slovenija

Security Engineer III

Legrand Slovenija Blumenau, Santa Catarina, Brazil

Appliances, Electrical, and Electronics Manufacturing · 2-10 employees

Aug 11
security Senior (5-10 yrs) Full-time Brazil
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Security Engineer III will drive application and product security across ZPE Cloud and Nodegrid product lines by embedding security into the software development lifecycle. This role involves facilitating threat modeling, conducting secure design reviews, and collaborating with global engineering teams to remediate vulnerabilities.

What they look for

Application security Product security Threat modeling Secure design review Vulnerability management CI/CD pipeline security Go Python Cloud security GCP OAuth 2.0 Cryptography Kubernetes security SAST DAST SCA

Requirements

Candidates must have at least 5 years of experience in security or software engineering, with a minimum of 2 years focused on application or product security. Proficiency in English and Portuguese is required, along with technical expertise in security code review, CI/CD integration, and threat modeling frameworks.

Benefits

Medical coverage Dental coverage Vision coverage 401k match Paid time off Holiday pay Short-term disability Long-term disability Paid maternity leave Paid parental leave Bonus opportunities Volunteer time off

Full description

At a Glance Legrand has an exciting opportunity for a Security Engineer III to join the ZPE Systems Team in Blumenau, BR.

We are seeking a Security Engineer III to drive application and product security across the ZPE Cloud and Nodegrid product lines. Based in Blumenau and working with engineering teams in Brazil, the United States, and Europe, this role embeds security into the software development lifecycle, facilitates threat modeling and secure design review, and works directly with development teams to identify and remediate vulnerabilities before they reach customers. The primary focus is cloud and web application security, with growing exposure to embedded product security.

Responsibilities

Main Responsibilities:

Application & Product Security

  • Conduct security code reviews and provide practical remediation guidance to development teams
  • Build out, tune, and maintain the SAST, DAST, SCA, and secrets scanning toolchain within CI/CD pipelines
  • Triage vulnerability findings, assign severity, and drive remediation to closure with owning teams
  • Develop secure coding guidelines, reusable patterns, and developer security training material
  • Manage software supply chain risk, including SBOM generation and CVE triage and response
  • Scope and coordinate third-party penetration tests; perform targeted internal assessments

Secure Design & Architecture

  • Facilitate threat modeling for new features, services, and system designs
  • Perform security design reviews and document mitigations and accepted risks
  • Develop and maintain security reference architectures and reusable design patterns for product teams
  • Contribute to the design of authentication, authorization, and secrets management for product services
  • Define encryption and key management requirements for product data at rest and in transit
  • Evaluate and recommend application and cloud security tooling

Compliance Support

  • Implement and evidence the technical controls required by ISO 27001, SOC 2, and the EU Cyber Resilience Act
  • Provide technical input to customer security questionnaires and RFI/RFP responses

Leadership & Collaboration

  • Mentor engineers on secure development practices and help establish a security champions program
  • Contribute to the product security roadmap with Product and Engineering leadership
  • Act as the security point of contact in design and architecture discussions
  • Conduct regular Knowledge Sharing Sessions (KSS) on security topics and emerging threats
  • Communicate effectively across Brazil, US, and EU time zones, in English, written and verbal

Qualifications

Profile:

  • 5+ years in security engineering or software engineering, with at least 2 years focused on application or product security
  • Professional working proficiency in English, written and spoken, sufficient for customer-facing documentation and cross-region collaboration; fluent Portuguese
  • Demonstrated experience performing security code review across more than one language
  • Proven experience integrating and tuning security tooling within CI/CD pipelines
  • Experience with threat modeling and secure design review
  • Familiarity with at least one major compliance framework (ISO 27001 or SOC 2) from a control implementation perspective
  • Experience producing technical security documentation for internal and customer audiences
  • Availability for occasional international travel

Desirable (not required)

  • Experience helping establish or mature an application security practice
  • Experience with embedded or hardware product security: secure boot, TPM, firmware signing, SBOM
  • Familiarity with EU Cyber Resilience Act, FIPS 140-3, or Common Criteria obligations
  • Certifications such as CompTIA Security+, CISSP, OSCP, CKS, or a cloud security certification; sponsorship available
  • Contributions to open-source security projects, security research, or conference speaking

Skills/Knowledge/Abilities:

Technical Skills

  • Reading and reviewing application code in Go, Python, or similar; scripting for security automation
  • Cloud security controls and architecture on at least one major provider; GCP preferred
  • Application authentication and authorization: OAuth 2.0, OIDC, SAML, RBAC
  • Applied cryptography: TLS, encryption, hashing, PKI, certificate and key management
  • Container and Kubernetes security, IaC scanning, and policy as code
  • CI/CD platforms such as GitLab CI, Jenkins, GitHub Actions, or ArgoCD
  • Practical experience with SAST, DAST, SCA, and secrets scanning tooling

Knowledge Areas

  • OWASP Top 10, OWASP ASVS, and common web and API vulnerability classes
  • Threat modeling frameworks: STRIDE, PASTA, MITRE ATT&CK
  • Secure SDLC practices and DevSecOps methodologies
  • Software supply chain security: SBOM, dependency management, CVE triage
  • Security compliance and regulatory requirements: NIST CSF, CIS Controls, ISO 27001, SOC 2, LGPD

Abilities

  • Explain complex security concepts clearly to technical and non-technical audiences
  • Influence engineering teams and drive remediation without direct authority
  • Balance security requirements against business needs and delivery timelines
  • Work autonomously across distributed teams and time zones with strong ownership

Legrand is the global specialist in electrical and digital building infrastructures. Its comprehensive offering of solutions for residential, commercial, and datacenter markets makes it a benchmark for customers worldwide.

Trusted by the world’s largest hyperscalers, Legrand's Power & Thermal Management division helps operators manage the critical infrastructure that powers modern data centers. Through a portfolio of best-in-class brands spanning power, cooling, connectivity, management, and supporting infrastructure, we enable customers to deploy, operate, and scale high-density environments. Combining deep domain expertise with a customizable design approach and dedicated support services, we help customers build and operate resilient infrastructure that meets current performance requirements while adapting to future demands. Power & Thermal Management industry-leading brands include Approved Networks, Raritan, Server Technology, Starline, Ortronics, Kratos Industries, and ZPE Systems.

Legrand, North & Central America offers comprehensive medical, dental, and vision coverage, as well as distinctive benefits like a high employer 401K match, paid time off (PTO) and holiday pay, short-term and long-term disability benefit plans, above-benchmark paid maternity and parental leave, bonus opportunities in accordance with the Company’s incentive plans, paid time off to volunteer, and an active/growing Employee Resource Group network. For more information, visit legrand.us.

Similar roles