Cloud Security Engineer

Job not on LinkedIn

🔥 0 minutes ago

🇧🇷 Brazil – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 10%

infoinfo

🗣️🇧🇷🇵🇹 Portuguese Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Digibee

Digibee

51 - 200 employees

Founded 2017

💼 Consulting

📣 Marketing

📦 Logistics

💰 $60.5M Series B - Digibee on 2023-06

Consulting • Marketing • Logistics

Digibee is a cloud-native integration and automation platform that helps enterprises connect apps, legacy systems, data, and AI. It provides low-code/visual tools for building integrations, orchestrating workflows, deploying agents, and managing MCP/AI connectivity with built-in observability, security, and serverless scaling. Digibee is offered as a SaaS platform for IT teams, developers, and architects to accelerate digital transformation, modernize core systems, and automate high-volume, mission-critical processes.

📋 Description

• Integrate security controls into CI/CD pipelines (SAST, SCA, image scanning, SBOM, image signing/verification), making security part of the delivery workflow rather than a manual gate at the end. • Assess, define, and lead the rollout of hardened container images (Wolfi/Chainguard, distroless), reducing the attack surface and CVEs in the base images used by Engineering. • Lead vulnerability management and governance: risk-based prioritization, remediation SLAs, and follow-up with Engineering teams through closure. • Design and implement security controls in GCP infrastructure (IAM, networking, Artifact Registry, organization policies), together with Infrastructure as Code (Terraform). • Serve as a technical authority for pipeline and cloud security, guiding Engineering squads on secure development practices (shift-left) without slowing delivery velocity. • Collaborate with SRE on observability and resilience through a security lens (runtime hardening, incident response, production security posture). • Perform targeted penetration-testing activities to validate controls and remediations, complementing formal penetration-testing engagements with external vendors. • Support audits and compliance requirements (SOC 2, PCI) related to pipelines, vulnerabilities, and images. • Embed security into the software development and delivery lifecycle (DevSecOps). • Work closely with Engineering, SRE, and Platform teams as a technical authority, without hierarchical authority.

🎯 Requirements

• 5+ years of experience in Cloud Security Engineering, DevSecOps, or Security Engineering, with hands-on experience in production environments. • Strong command of Google Cloud Platform (GCP), including IAM, networking, Artifact Registry, and organization security policies. • Hands-on experience integrating security into CI/CD pipelines (GitLab CI, Jenkins, or similar) and using vulnerability-scanning tools (e.g., Trivy, Snyk, Wiz). • Production experience with Docker/Kubernetes: multi-stage builds, runtime hardening, non-root execution, and dependency management. • Knowledge of secure/hardened container images (Wolfi, Chainguard, distroless), or a strong willingness to specialize in this area. • Strong scripting skills in Python and/or Bash for automating security controls. • Understanding of secure development practices (secure SDLC, OWASP Top 10, and basic threat modeling). • Experience with SRE practices (observability, reliability, and incident response) sufficient to collaborate technically with the SRE team. • Strong technical communication skills and the ability to influence Engineering squads without direct hierarchical authority. • Certifications such as Google Professional Cloud Security Engineer, Certified Kubernetes Security Specialist (CKS), or equivalent are a plus. • Previous experience specifically with Chainguard/Wolfi or other minimal container image ecosystems is a plus. • Experience with SBOMs, image signing (cosign/Sigstore), and supply chain security (SLSA) is a plus. • Experience with compliance frameworks (SOC 2, PCI-DSS, ISO 27001) is a plus. • Previous experience as an SRE or on Platform/Infrastructure teams is a plus. • Open-source contributions or technical content published in the DevSecOps/cloud security community is a plus.

🏖️ Benefits

• Health care • Dental care • R$1,400 per month on a Caju card (for food and meal allowances, mobility, home office supplies, culture, health, and education) • Life insurance • Childcare assistance • Wellhub (formerly Gympass) • English course: partnership for group classes at R$100 per month • Global Equity Program • Flexible and autonomous work culture • Global distributed team • Home office supplies allowance

Apply Now

Similar Jobs

🕒 3 days ago

Deliverit

1 - 10

🛍️ eCommerce

📦 Logistics

Engenheiro Full-Stack Sênior corrigindo vulnerabilidades em aplicações React e Node.js na Deliver IT. Analisando código, executando scans e fortalecendo práticas DevSecOps.

🗣️🇧🇷🇵🇹 Portuguese Required

JavaScript

Node.js

NoSQL

React

SQL

TypeScript

🕒 3 days ago

ASAAS

501 - 1000

💼 Consulting

🏥 Healthcare

🏨 Hospitality

Analista sênior de riscos e controles de segurança da informação na Asaas, fintech que maximiza a produtividade empresarial com tecnologia. Condução de riscos, controles, TPRM e governança.

🗣️🇧🇷🇵🇹 Portuguese Required

Cloud

🕒 3 days ago

GFT Technologies

10,000+ employees

💼 Consulting

🛡️ Insurance

🔒 Cybersecurity

Senior Cloud Security Engineer securing complex AWS infrastructure for GFT Technologies' regulated financial-services clients. Automating controls, managing vulnerabilities, and supporting compliance audits.

🗣️🇧🇷🇵🇹 Portuguese Required

AWS

Cloud

Terraform

VMware

🕒 4 days ago

Neon

1001 - 5000

💼 Consulting

🛡️ Insurance

💳 Fintech

Engenheiro especialista em segurança cloud liderando redes AWS, firewalls Palo Alto e soluções Zscaler na Neon. Automatização com Terraform e estratégia SASE/Zero Trust para proteger serviços financeiros.

🗣️🇧🇷🇵🇹 Portuguese Required

AWS

Azure

Cloud

Firewalls

Google Cloud Platform

TCP/IP

Terraform

🕒 4 days ago

ROIT

51 - 200

💼 Consulting

⚖️ Legal

☁️ SaaS

Analista de Segurança Ofensiva e Detecção na ROIT, empresa que fortalece sua estrutura de Cybersecurity. Simulando adversários e convertendo resultados em detecção e resposta.

🗣️🇧🇷🇵🇹 Portuguese Required

Cyber Security

Python