Tessera Labs

Senior Product Security Engineer at Tessera Labs (Brazil)

Tessera Labs· Brazil·

Role details

Work type
Remote
Employment
Contract

Job description

Senior Product Security Engineer

The Role

We're hiring a Senior Product Security Engineer to work hand-in-hand with developers to secure the product across its entire lifecycle. You'll be the person who makes our platform defensible — through design reviews, threat modeling, hands-on penetration testing, and secure-coding partnership — and you'll do it as a collaborator who helps engineers ship securely, not a gatekeeper who slows them down.

This role partners closely with product engineering and platform engineering teams.

What You'll Do

  • Partner directly with developers to secure the product across the Software Development Life Cycle (SDLC), embedding security early rather than bolting it on at the end.
  • Lead security design and architecture reviews, and run threat modeling on new features and services.
  • Perform hands-on penetration testing of web applications and Application Programming Interfaces (APIs), and translate findings into clear, prioritized, fixable work.
  • Conduct secure code reviews and help define secure-coding standards and security acceptance criteria.
  • Operate and tune Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and dependency / supply-chain scanning, and triage what they surface.
  • Help engineers understand the "why" behind findings so the same class of issue doesn't recur.
  • Contribute security evidence and rigor to our compliance posture (System and Organization Controls 2, or SOC 2, ISO 27001, etc.).

What You'll Need (Required)

  • A strong track record in product or application security — you've measurably made real products more secure.
  • Hands-on penetration testing experience against web applications and APIs.
  • Deep understanding of how modern web applications work — single-page front ends, APIs, authentication and authorization (for example, OAuth 2.0 / OpenID Connect), sessions, and the common ways each is attacked (for example, the Open Worldwide Application Security Project, or OWASP, Top 10).
  • Experience running security design reviews and threat modeling.
  • Solid understanding of the SDLC and how to embed security into it.
  • Strong communication skills — you work directly with developers and can explain risk in terms they'll act on.

Nice to Have

  • Familiarity with open-source security tooling (for example, OWASP ZAP and Burp Suite Community Edition for testing, Semgrep for SAST, Trivy or Grype for dependency and container scanning, Nuclei for templated scanning).
  • A relevant offensive-security certification (for example, Offensive Security Certified Professional, or OSCP).
  • Cloud security experience (Amazon Web Services, Microsoft Azure, or Google Cloud Platform) and container / Kubernetes security.
  • Experience supporting a SOC 2, International Organization for Standardization (ISO) 27001, or similar program.
  • Background in enterprise or regulated environments where deployment security is non-negotiable.

What Success Looks Like (First 90 Days)

  • You've reviewed the product's architecture and threat surface and identified the highest-priority security risks.
  • A repeatable, lightweight process exists for security design reviews on new work.
  • Security findings have a clear triage-to-remediation path, and developers know how to engage you early.

Location and Work Model

Remote in Brazil

Why work at Tessera Labs

  • Culture highlights: Described as “enterprise serious, AI forward” – a blend of deep enterprise gravity and cutting-edge AI research. Team includes PhDs, ex-Google/Microsoft/Netflix engineers, and former SAP directors.
  • Remote/hybrid/office policy: Not explicitly stated, but headquarters in San Jose (CA) and Palo Alto, and job postings suggest a mix of on-site and remote flexibility (e.g., multiple backend engineer roles, a Technical Program Manager). Expect hybrid with a strong in-office core.
  • Notable perks or engineering culture: Working on the frontier of enterprise AI with real-world impact on massive transformation projects. Opportunity to shape a new category of software. Leadership includes one of UC San Diego’s youngest PhDs and a YC alumnus.
  • Open technical roles: Backend engineers, data engineers (ERP data harmonization), DevOps, product design, SAP consultants – 38 open positions as of mid-2026. jobs.ashbyhq.com/tessera-labs

Application questions