Security Engineering Manager, AWS DevSecOps

Rig Globalconsulting

São Paulo

On-site

BRL 220,416 - 330,624

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Rig Globalconsulting seeks a Security Engineering Manager to lead AWS DevSecOps efforts, focusing on identity, endpoint security, and SOC 2 Type 1 readiness. You will design secure AWS architectures, enforce least privilege, and mentor engineers across security disciplines.

Responsibilities include integrating security automation into GitHub CI/CD, conducting vulnerability management with Snyk and SonarQube, and coordinating audits with the security team to strengthen controls and governance.

Qualifications

  • 4+ years of hands-on security engineering, cloud security, or infra security roles.
  • Hands-on AWS security experience: encryption, IAM/least privilege, monitoring.

Responsibilities

  • Design and implement AWS security architecture with encryption and IAM policies.
  • Establish secure configuration standards and continuous monitoring for AWS services.
  • Improve security visibility and reporting on cloud posture and risk trends.

Skills

AWS security
DevSecOps
Identity management
Endpoint security
SOC 2
Security automation
Security reporting
Incident response
Documentation
Collaboration

Tools

GitHub Actions
Snyk
SonarQube
CrowdStrike
SentinelOne
GuardDuty
Config
CloudTrail
Okta
Google Workspace

Job description

Security Engineering Manager, AWS DevSecOps
About the job Security Engineering Manager, AWS DevSecOps

Security Engineering Manager, AWS, DevSecOps, Identity, Endpoint, SOC 2

Employment Type: Full-Time Contractor

Overview

We are seeking a Security Engineering Consultant to support the Security Engineering team in securing our infrastructure. This role will focus on strengthening AWS security architecture, integrating security automation into GitHub and CI/CD workflows, hardening identity and endpoint controls, and leading SOC 2 Type 1 readiness.

What You'll Do
Cloud Security (AWS)
  • Design and implement AWS security architecture, including encryption, IAM policies, and least-privilege access controls.
  • Establish standards for secure configuration and continuous monitoring across AWS services (IAM, GuardDuty, Config, CloudTrail).
  • Improve visibility and reporting on cloud security posture and risk trends.
DevSecOps and Automation
  • Integrate security automation into GitHub workflows and CI/CD pipelines to identify vulnerabilities before code deployment.
  • Implement and maintain security scanning across repositories using tools such as GitHub security features, Snyk, SonarQube, and related solutions.
  • Collaborate with engineering teams to implement secure coding practices and security testing protocols.
Identity and Access Management
  • Manage and optimize Okta identity management, including roles, policies, MFA, and privileged access controls.
  • Strengthen Google Workspace security configuration, access policies, and monitoring practices.
  • Drive reduction of privileged access through role redesign, access reviews, and enforcement of least privilege.
  • Deploy and maintain endpoint security solutions across corporate devices with threat monitoring capabilities (CrowdStrike, SentinelOne, or equivalent).
  • Establish endpoint security standards, enforcement mechanisms, and compliance reporting.
Compliance and Security Program Execution
  • Establish the SOC 2 compliance framework and coordinate audit preparation activities toward SOC 2 Type 1 completion.
  • Build and maintain security documentation, policies, evidence collection processes, and control ownership alignment.
Monitoring, Reporting, and Incident Response
  • Monitor security metrics across cloud, endpoint, and identity systems with regular reporting.
  • Respond to security incidents, conduct root cause analysis, and implement corrective actions to prevent recurrence.
  • Continuously improve detection, alerting, and response workflows through tooling and automation.
Qualifications & Experience
  • 4+ years of hands-on experience in security engineering, product security, or infrastructure security roles (cloud, DevSecOps, identity, endpoint, and compliance).
  • Hands-on AWS security: encryption, IAM/least privilege, monitoring (GuardDuty/Config/CloudTrail).
  • DevSecOps automation in GitHub/CI/CD: scanning, vulnerability management, secure SDLC.
  • Okta + Google Workspace security administration (MFA, roles, access governance).
  • Endpoint security deployment and compliance monitoring (CrowdStrike/SentinelOne or similar).
  • Incident response and root cause analysis; strong collaboration and documentation skills.
  • Strong communication and leadership skills, with experience mentoring engineers and influencing cross-functional teams.

We are committed to providing equal opportunity for qualified applicants to contract positions, regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status. This is a contract opportunity, not a direct employment role.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Delivery Consultant - Cloud Security, Professional Services, Professional Services
Delivery Consultant - Cloud Security, Professional Services, Professional Services

Amazon • São Paulo

On-site
BRL 180,000 - 300,000
Disability accommodations
DevSecOps Engineer
DevSecOps Engineer

Uberall • Brazil

On-site
BRL 240,000 - 420,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

AgileEngine • Brazil

On-site
BRL 456,157 - 608,210
Professional growth
Competitive compensation
Flextime
+1
Delivery Consultant - Cloud Security, Professional Services, Professional Services (AWS)
Delivery Consultant - Cloud Security, Professional Services, Professional Services (AWS)

Amazon • São Paulo

On-site
BRL 120,000 - 210,000
Cloud Security Engineer
Cloud Security Engineer

Bunge • São Paulo

On-site
BRL 100,000 - 130,000
Senior Cloud Infrastructure Engineer ( Governance )
Senior Cloud Infrastructure Engineer ( Governance )

Platform Science, Inc. • Londrina

On-site
BRL 180,000 - 360,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Antisec • Brazil

On-site
BRL 180,000 - 280,000
DevOps / Site Reliability Engineer ID70127
DevOps / Site Reliability Engineer ID70127

AgileEngine • São Bernardo do Campo

On-site
BRL 354,789 - 506,842
Professional growth
Competitive compensation
Exciting projects
+1
Security Engineer (DevSecOps / AppSec)
Security Engineer (DevSecOps / AppSec)

Lever, Inc. • Brazil

Remote
BRL 250,000 - 360,000
Remote work model
30 days paid rest
Health and dental insurance
Cloud Network Security Architect / Engineer
Cloud Network Security Architect / Engineer

Georgia IT, Inc. • Brazil

On-site
BRL 180,000 - 320,000