Cloud Security Engineer

Jobgether SRL

Brasil

Teletrabalho

BRL 180 000 - 300 000

Tempo integral

Há 3 dias
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Uma candidatura completa num minuto — currículo personalizado e carta de apresentação, prontos a enviar.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Healthcare coverage
Dental care
R$1,400 monthly through Caju card
Life insurance
Childcare assistance
Wellhub membership
English course (R$100/mo)

Resumo da oferta

Jobgether SRL is seeking a Cloud Security Engineer based in Brazil to embed security into software delivery, emphasizing DevSecOps and shift-left practices. You will integrate security controls into CI/CD, lead vulnerability governance, and drive secure container image strategies with minimal disruption to delivery.

The role spans security across GCP infrastructure, container hardening, and software supply chain, with collaboration across engineering, SRE, and platform squads to strengthen

Qualificações

  • 5+ years in Cloud Security Engineering, DevSecOps, or similar.
  • Experience with GCP IAM, networking, Artifact Registry, and org security policies.

Responsabilidades

  • Integrate security controls into CI/CD pipelines (SAST, SCA, container scanning, SBOM, image signing).
  • Lead vulnerability governance with risk-based prioritization and SLAs.
  • Design security controls across GCP infrastructure using Terraform.
  • Promote secure SDLC and shift-left practices with engineering teams.
  • Collaborate with SRE for observability, resilience, and incident response.
  • Conduct targeted penetration testing to validate controls.

Conhecimentos

Cloud Security
DevSecOps
Kubernetes
Terraform
Python
SRE collaboration

Ferramentas

Trivy
Snyk
cosign
Sigstore
Chainguard
Wolfi

Descrição da oferta de emprego

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Cloud Security Engineer based in Brazil.

This role offers the opportunity to establish and strengthen cloud security across a modern, cloud-native technology environment.

You will embed security directly into software development and delivery workflows, with a strong focus on DevSecOps and shift-left practices.

The position combines cloud security engineering, CI/CD security, vulnerability governance, container hardening, and infrastructure protection.

You will serve as a technical reference for engineering, SRE, and platform teams, influencing security standards without direct hierarchical authority.

The role requires balancing strong security controls with the speed and reliability expected from modern software delivery.

You will also contribute to production resilience, incident response, compliance, and the continuous improvement of cloud and software supply chain security.

  • Integrate security controls into CI/CD pipelines, including SAST, SCA, container scanning, SBOM generation, and image signing and verification.
  • Establish security practices that become part of the standard software delivery workflow rather than relying on manual controls at the end of the process.
  • Evaluate, define, and lead the rollout of hardened container images using technologies and approaches such as Wolfi, Chainguard, and distroless images.
  • Reduce attack surface and vulnerabilities in the base container images used by engineering teams.
  • Lead vulnerability management and governance, including risk-based prioritization, remediation SLAs, and follow-up with engineering teams through resolution.
  • Design and implement security controls across GCP infrastructure, including IAM, networking, Artifact Registry, and organization security policies.
  • Work with Infrastructure as Code practices, particularly Terraform, to implement and maintain cloud security controls.
  • Act as a technical security reference for engineering squads, promoting secure development and shift-left practices without unnecessarily slowing delivery.
  • Collaborate with SRE teams on security-focused observability, runtime hardening, resilience, production security posture, and incident response.
  • Conduct targeted penetration testing activities to validate security controls and remediation efforts alongside formal external penetration testing engagements.
  • Support audits and compliance requirements related to CI/CD pipelines, vulnerability management, container images, and cloud security, including SOC 2 and PCI requirements.
  • Establish and promote security standards that can be consistently adopted across technical teams.
Requirements
  • 5+ years of practical experience in Cloud Security Engineering, DevSecOps, Security Engineering, or a closely related discipline, including production environments.
  • Strong hands-on knowledge of Google Cloud Platform, particularly IAM, networking, Artifact Registry, and organization-level security policies.
  • Experience integrating security controls into CI/CD pipelines using GitLab CI, Jenkins, or similar technologies.
  • Practical experience with vulnerability scanning tools such as Trivy, Snyk, Wiz, or comparable solutions.
  • Strong production experience with Docker and Kubernetes, including multi-stage builds, runtime hardening, non-root execution, and dependency management.
  • Knowledge of hardened and minimal container image ecosystems such as Wolfi, Chainguard, and distroless, or a strong willingness to develop deep expertise in these technologies.
  • Solid scripting skills in Python and/or Bash for security automation and control implementation.
  • Strong understanding of secure SDLC practices, OWASP Top 10, and basic threat modeling.
  • Familiarity with SRE practices including observability, reliability, and incident response, with the ability to collaborate effectively with SRE teams.
  • Strong technical communication skills and the ability to influence engineering teams without direct managerial authority.
  • Experience with SBOMs, container image signing, cosign/Sigstore, and software supply chain security such as SLSA is an advantage.
  • Experience with compliance frameworks such as SOC 2, PCI-DSS, or ISO 27001 is preferred.
  • Previous experience in SRE, platform engineering, or infrastructure teams is beneficial.
  • Certifications such as Google Professional Cloud Security Engineer, Certified Kubernetes Security Specialist (CKS), or equivalent are valued.
  • Experience with Chainguard/Wolfi or other minimal-image ecosystems is a plus.
  • Open-source contributions or published technical content related to DevSecOps or cloud security are advantageous.
Benefits
  • Full-time, remote position based in Brazil.
  • Healthcare coverage.
  • Dental care.
  • R$1,400 per month through a Caju card, covering areas such as food and meals, mobility, home-office supplies, culture, health, and education.
  • Life insurance.
  • Childcare assistance.
  • Wellhub membership.
  • Access to an English course through a group-class partnership for R$100 per month.
  • Global Equity Program.
  • Opportunity to work in a globally distributed environment across the Americas.
  • Flexible and autonomous working culture.
  • High-impact technical role with significant influence over cloud security, DevSecOps, and software supply chain practices.
  • Collaboration with engineering, SRE, and platform teams on modern cloud-native infrastructure.

We appreciate your interest and wish you the best!

Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

Senior DevOps & Infrastructure Engineer
Senior DevOps & Infrastructure Engineer

Jobgether SRL • Brasil

Teletrabalho
BRL 240 000 - 360 000
Fully remote opportunity for Brazil
Exposure to AI infrastructure
Cutting-edge tech projects
+4
Staff Cybersecurity Engineer
Staff Cybersecurity Engineer

Shape Digital • São Paulo

Híbrido
BRL 180 000 - 300 000
Profit Sharing
Health and Dental Plan
Flexible Benefit
+10
Engenheiro de Dados GCP Sênior
Engenheiro de Dados GCP Sênior

Jobgether SRL • Brasil

Teletrabalho
BRL 200 000 - 320 000
Remote in Brazil
Seguro médico Porto Seguro
PLR
+4
Sr Cloud Security Engineer
Sr Cloud Security Engineer

Serasa Experian • Brasil

Presencial
BRL 180 000 - 280 000
Hiring: Devops Engineer Id89052
Hiring: Devops Engineer Id89052

1global • Santo André

Presencial
BRL 134 000 - 234 000
Meal allowance (Caju card)
Health insurance
Daycare allowance
+3
Senior DevSecOps Engineer (São Paulo Based)
Senior DevSecOps Engineer (São Paulo Based)

1GLOBAL • São Bernardo do Campo

Presencial
BRL 223 200 - 334 800
CLT contract
Quarterly performance bonuses
Meal allowance
+3
Senior DevSecOps Engineer (São Paulo Based)
Senior DevSecOps Engineer (São Paulo Based)

1GLOBAL • São Paulo

Presencial
BRL 180 000 - 260 000
CLT contract
Quarterly bonuses
Meal allowance paid into Caju card
+3
Senior DevSecOps Engineer - São Paulo Based
Senior DevSecOps Engineer - São Paulo Based

1GLOBAL • São Paulo

Presencial
BRL 327 690 - 655 380
Growth Opportunities
Dynamic Work Environment
Professional Development
+2
Senior GCP DevOps Engineer
Senior GCP DevOps Engineer

Vigil Global • Brasil

Presencial
BRL 250 000 - 400 000
Mentoring and training
UK travel opportunities
Senior/Specialist DevOps (preferably Azure)
Senior/Specialist DevOps (preferably Azure)

Jobgether • Brasil

Presencial
BRL 260 000 - 360 000
Health and dental insurance
Meal and food allowance
Life insurance
+2