HireFT
Browse JobsHow it worksPricingAboutSuccess Stories
    Back to jobs
    LE

    Legrand Group

    Electrical and Digital Building Infrastructure

    Security Engineer III

    Blumenau, BrazilOn-SiteFull-time5+ yrs experiencePosted 3w ago
    All Legrand Group jobs

    Job description

    • Brand: Legrand
    • Employment type: Regular
    • Travel Required: No

    At a Glance
    Legrand has an exciting opportunity for a Security Engineer III to join the ZPE Systems Team in Blumenau, BR.

    We are seeking a Security Engineer III to drive application and product security across the ZPE Cloud and Nodegrid product lines. Based in Blumenau and working with engineering teams in Brazil, the United States, and Europe, this role embeds security into the software development lifecycle, facilitates threat modeling and secure design review, and works directly with development teams to identify and remediate vulnerabilities before they reach customers. The primary focus is cloud and web application security, with growing exposure to embedded product security.

    Responsibilities

    Main Responsibilities:

    Application & Product Security

    • Conduct security code reviews and provide practical remediation guidance to development teams
    • Build out, tune, and maintain the SAST, DAST, SCA, and secrets scanning toolchain within CI/CD pipelines
    • Triage vulnerability findings, assign severity, and drive remediation to closure with owning teams
    • Develop secure coding guidelines, reusable patterns, and developer security training material
    • Manage software supply chain risk, including SBOM generation and CVE triage and response
    • Scope and coordinate third-party penetration tests; perform targeted internal assessments

    Secure Design & Architecture

    • Facilitate threat modeling for new features, services, and system designs
    • Perform security design reviews and document mitigations and accepted risks
    • Develop and maintain security reference architectures and reusable design patterns for product teams
    • Contribute to the design of authentication, authorization, and secrets management for product services
    • Define encryption and key management requirements for product data at rest and in transit
    • Evaluate and recommend application and cloud security tooling

    Compliance Support

    • Implement and evidence the technical controls required by ISO 27001, SOC 2, and the EU Cyber Resilience Act
    • Provide technical input to customer security questionnaires and RFI/RFP responses

    Leadership & Collaboration

    • Mentor engineers on secure development practices and help establish a security champions program
    • Contribute to the product security roadmap with Product and Engineering leadership
    • Act as the security point of contact in design and architecture discussions
    • Conduct regular Knowledge Sharing Sessions (KSS) on security topics and emerging threats
    • Communicate effectively across Brazil, US, and EU time zones, in English, written and verbal

    Qualifications

    Profile:

    • 5+ years in security engineering or software engineering, with at least 2 years focused on application or product security
    • Professional working proficiency in English, written and spoken, sufficient for customer-facing documentation and cross-region collaboration; fluent Portuguese
    • Demonstrated experience performing security code review across more than one language
    • Proven experience integrating and tuning security tooling within CI/CD pipelines
    • Experience with threat modeling and secure design review
    • Familiarity with at least one major compliance framework (ISO 27001 or SOC 2) from a control implementation perspective
    • Experience producing technical security documentation for internal and customer audiences
    • Availability for occasional international travel

    Desirable (not required)

    • Experience helping establish or mature an application security practice
    • Experience with embedded or hardware product security: secure boot, TPM, firmware signing, SBOM
    • Familiarity with EU Cyber Resilience Act, FIPS 140-3, or Common Criteria obligations
    • Certifications such as CompTIA Security+, CISSP, OSCP, CKS, or a cloud security certification; sponsorship available
    • Contributions to open-source security projects, security research, or conference speaking

    Skills/Knowledge/Abilities:

    Technical Skills

    • Reading and reviewing application code in Go, Python, or similar; scripting for security automation
    • Cloud security controls and architecture on at least one major provider; GCP preferred
    • Application authentication and authorization: OAuth 2.0, OIDC, SAML, RBAC
    • Applied cryptography: TLS, encryption, hashing, PKI, certificate and key management
    • Container and Kubernetes security, IaC scanning, and policy as code
    • CI/CD platforms such as GitLab CI, Jenkins, GitHub Actions, or ArgoCD
    • Practical experience with SAST, DAST, SCA, and secrets scanning tooling

    Knowledge Areas

    • OWASP Top 10, OWASP ASVS, and common web and API vulnerability classes
    • Threat modeling frameworks: STRIDE, PASTA, MITRE ATT&CK
    • Secure SDLC practices and DevSecOps methodologies
    • Software supply chain security: SBOM, dependency management, CVE triage
    • Security compliance and regulatory requirements: NIST CSF, CIS Controls, ISO 27001, SOC 2, LGPD

    Abilities

    • Explain complex security concepts clearly to technical and non-technical audiences
    • Influence engineering teams and drive remediation without direct authority
    • Balance security requirements against business needs and delivery timelines
    • Work autonomously across distributed teams and time zones with strong ownership

    About Us

    Legrand is the global specialist in electrical and digital building infrastructures. Its comprehensive offering of solutions for residential, commercial, and datacenter markets makes it a benchmark for customers worldwide.

    Trusted by the world’s largest hyperscalers, Legrand's Power & Thermal Management division helps operators manage the critical infrastructure that powers modern data centers. Through a portfolio of best-in-class brands spanning power, cooling, connectivity, management, and supporting infrastructure, we enable customers to deploy, operate, and scale high-density environments. Combining deep domain expertise with a customizable design approach and dedicated support services, we help customers build and operate resilient infrastructure that meets current performance requirements while adapting to future demands. Power & Thermal Management industry-leading brands include Approved Networks, Raritan, Server Technology, Starline, Ortronics, Kratos Industries, and ZPE Systems.

    Legrand, North & Central America offers comprehensive medical, dental, and vision coverage, as well as distinctive benefits like a high employer 401K match, paid time off (PTO) and holiday pay, short-term and long-term disability benefit plans, above-benchmark paid maternity and parental leave, bonus opportunities in accordance with the Company’s incentive plans, paid time off to volunteer, and an active/growing Employee Resource Group network. For more information, visit legrand.us.

    Job details are sourced from the employer's original posting.

    Open job posting
    LE

    About the company

    Legrand Group

    Legrand Group is a global specialist in electrical and digital building infrastructures.

    View all Legrand Group jobs
    Industry
    Electrical and Digital Building Infrastructure
    Open roles
    328

    Interested in this role?

    Apply with HireFT

    Free to start — no card required.

    Your fit

    How well do you match?

    Sign in to see how your résumé lines up with this role.