Security Engineer

Job not on LinkedIn

🔥 19 hours ago

🇧🇷 Brazil – Remote

💵 $4k / month

⏳ Contract/Temporary

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 1%

infoinfo

🗣️🇧🇷🇵🇹 Portuguese Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Fertil Comunicacao e Marketing Ltda.

Fertil Comunicacao e Marketing Ltda.

11 - 50 employees

Founded 2008

📣 Marketing

📱 Media

🤝 B2B

Marketing • Media • B2B

Fertil Comunicacao e Marketing Ltda. is a Brazilian communication and marketing agency that appears to provide digital marketing, communications, and web presence services. The example text suggests they manage hosted websites and implement security/anti-abuse checks (CAPTCHA-style verification) for site access, indicating they may also handle website administration or hosting-related configurations for clients. Their core focus is on marketing and communications delivered to business clients.

📋 Description

• Execute the technical security scope defined by the Lead Engineer, submitting deliverables for review • Work on production cloud security (AWS and OVH): IAM, VPCs, Security Groups, KMS, secrets, hardening, and public exposure • Manage vulnerabilities end to end: triage, classification (CVSS), owner and deadline assignment, evidence collection, and retesting • Operate SAST, DAST, and SCA tools, distinguishing genuine findings from false positives before creating work items for product teams • Conduct security-focused code reviews, applying the OWASP Top 10 and API Security Top 10 • Implement and maintain security gates in CI/CD pipelines and infrastructure as code • Work on container security, including image builds, registries, and runtime hardening • Write queries and detection rules in a SIEM or log stack and produce the corresponding runbooks • Conduct periodic access reviews, applying MFA, least privilege, and secrets vaults • Automate evidence collection and control validation using Python or Bash • Document what was tested, how it was tested, and what was proven, treating evidence as a deliverable • Report risks and escalate to the Lead anything outside the delegated scope

🎯 Requirements

• Hands-on production cloud security in AWS: IAM and policies, VPCs and segmentation, Security Groups, KMS/secrets, hardening, and public exposure reviews • Linux and networking troubleshooting: TCP/IP, DNS, TLS, VPNs, firewalls, and traffic analysis • Application security (AppSec): practical knowledge of the OWASP Top 10 and API Security Top 10; security-focused code review; operation of SAST, DAST, and SCA tools, with the ability to distinguish genuine findings from false positives • Infrastructure as code and CI/CD: Terraform and pipelines (GitHub Actions, GitLab CI, or equivalent), including the implementation of security gates • Containers: Docker, image builds, registries, and basic runtime hardening • End-to-end vulnerability management: triage, classification (CVSS), owner and deadline assignment, evidence collection, and retesting • Logging and detection: writing queries and rules in a SIEM or log stack (CloudWatch, OpenSearch, Wazuh, Splunk, Sentinel, or similar) and producing runbooks • Identity and access: MFA, least privilege, secrets vaults, and conducting periodic access reviews • Python or Bash scripting for automation, evidence collection, and control validation • Documentation discipline: evidence is a deliverable of the role, not a byproduct • English proficiency for technical reading (documentation, advisories, tools, and consoles) • Maturity to operate under direction: execute the standard defined by the Lead, submit deliverables for review, and escalate anything outside the delegated scope

🏖️ Benefits

• Flexible working hours • Career development plan

Apply Now

Similar Jobs

🕒 3 days ago

Tessera Labs

11 - 50

🤖 Artificial Intelligence

🏢 Enterprise

☁️ SaaS

Senior Product Security Engineer securing Tessera Labs' platform across its lifecycle. Performing threat modeling, penetration testing, code reviews, and security tooling.

AWS

Azure

Cloud

Google Cloud Platform

Kubernetes

SDLC

🕒 August 20

LawnStarter

51 - 200

👥 B2C

🏪 Marketplace

🏠 Real Estate

Lead security for LawnStarter’s AI-powered home-services marketplace across application, cloud, payments, and compliance. Build the security function and lead its first team.

AWS

Cloud

Kubernetes

Laravel

PHP

React

SDLC

TypeScript

🕒 August 11

IPV7

201 - 500

🔒 Cybersecurity

💼 Consulting

Pentester pleno realizando testes de intrusão em aplicações, redes, APIs e nuvens para a IPV7 Tecnologia. Identificação de vulnerabilidades, relatórios técnicos e validação de remediações.

🗣️🇧🇷🇵🇹 Portuguese Required

Android

AWS

Azure

Cloud

DNS

Google Cloud Platform

iOS

Linux

Python

Rust

TCP/IP

Go

🕒 August 6

It4us Cyber Security

51 - 200

🔒 Cybersecurity

📋 Compliance

💳 Fintech

Especialista em Shuffle SOAR desenvolvendo automações, playbooks e integrações para SOC da IT4US, empresa brasileira de cibersegurança. Otimizando investigação e resposta automatizada a incidentes com SIEM, EDR/XDR e Threat Intelligence.

🗣️🇧🇷🇵🇹 Portuguese Required

Firewalls

Python

Splunk

🕒 August 6

It4us Cyber Security

51 - 200

🔒 Cybersecurity

📋 Compliance

💳 Fintech

Especialista em Wazuh implementando e administrando segurança para clientes da IT4US, empresa de cibersegurança. Evoluindo detecção, monitoramento e operações SOC em ambientes Windows e Linux.

🗣️🇧🇷🇵🇹 Portuguese Required

Cloud

Linux

Python

Splunk