Senior Information Security Analyst – Cloud Security

Jobtailor

São Paulo

Presencial

BRL 180 000 - 300 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Jobtailor is seeking a Senior Cloud Security Engineer to lead technical security across AWS, Azure and GCP, defining baselines, architectures and governance. You will harden cloud services, enforce least-privilege, and drive DevSecOps integration.

You will support Infra, DevOps and Engineering teams, automate controls with Terraform and scripting, monitor posture, and collaborate with SOC on incidents. LGPD awareness and relevant certifications are valued.

Qualificações

  • Strong experience in Information Security with a focus on Cloud environments.
  • Advanced knowledge of AWS, Azure and GCP; experience with all three is desirable.
  • Experience implementing cloud hardening.
  • Knowledge of IAM, RBAC, identity management, federation and Least Privilege principles.
  • Experience implementing organizational controls such as SCP, Azure Policy, Management Groups, RBAC, and GCP IAM.
  • Knowledge of cloud networking (VPC/VNet, subnets, security groups, NSGs, firewall, VPN, load balancer, private endpoints and WAF).
  • Experience with CSPM tools such as Microsoft Defender for Cloud, AWS Security Hub, Prisma Cloud, Wiz, Lacework, Orca or similar.
  • Knowledge of Infrastructure as Code (Terraform, CloudFormation or Bicep).
  • Experience with automation using Python, PowerShell or shell scripting.
  • Knowledge of DevSecOps practices and integrating security controls into CI/CD pipelines.
  • Familiarity with native cloud security services such as AWS GuardDuty, Security Hub, Config, IAM Access Analyzer, Inspector and CloudTrail; Microsoft Defender for Cloud, Microsoft Sentinel and Azure Monitor; GCP Security Command Center, Cloud Logging, Cloud Armor and IAM.
  • Experience with security frameworks and standards such as CIS Benchmarks, NIST CSF, ISO 27001, MITRE ATT&CK and the Cloud Well-Architected Framework.
  • Knowledge of LGPD (Brazilian Data Protection Law) and cloud compliance best practices.
  • Desirable certifications: AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, CCSP, CISSP, CompTIA Security+, Terraform Associate or Kubernetes certifications (CKA/CKS) considered a plus.

Responsabilidades

  • Act as the technical owner for security of AWS, Azure and GCP environments.
  • Define, implement and maintain security baselines for multi-cloud environments.
  • Design and implement secure architectures following Security by Design, Zero Trust and Least Privilege principles.
  • Perform hardening of cloud services aligning with CIS, NIST and Cloud Well-Architected Framework.
  • Implement and manage governance controls using SCPs, Azure Policy, Management Groups and GCP IAM.
  • Develop guardrails to ensure compliance and prevent insecure configurations.
  • Administer CSPM solutions, performing risk analysis, vulnerability prioritization and remediation tracking.
  • Define IAM standards, implementing least-privilege policies and secure privileged access management.
  • Implement data protection controls, encryption, KMS, secrets management.
  • Support Infra, DevOps and Engineering teams in secure cloud solutions.
  • Automate security controls using Terraform, scripts and automation tools.
  • Integrate security into CI/CD pipelines, promoting DevSecOps.
  • Conduct security assessments, architectural reviews and risk analyses for new cloud projects.
  • Continuously monitor cloud security posture and propose improvements.
  • Collaborate with SOC and Incident Response teams on incidents.
  • Develop metrics, dashboards and executive reports on cloud maturity, compliance and risks.
  • Promote cloud security best practices and guide teams on corporate standards.

Conhecimentos

Cloud security
IAM & RBAC
DevSecOps
IaC automation
CI/CD security
Threat analysis
Security governance
Security architecture
Vulnerability management

Formação académica

Bachelor's degree in IT/CS/Engineering

Ferramentas

Terraform
CloudFormation
Bicep
Python
PowerShell
Shell scripting

Descrição da oferta de emprego

  • Act as the technical owner for security of AWS, Azure and GCP environments, ensuring continuous improvement of cloud security posture.
  • Define, implement and maintain security baselines for multi-cloud environments.
  • Design and implement secure architectures following Security by Design, Zero Trust and Least Privilege principles.
  • Perform hardening of cloud services, ensuring adherence to vendor best practices and frameworks such as CIS Benchmarks, NIST and the Cloud Well-Architected Framework.
  • Implement and manage governance controls using mechanisms such as AWS Service Control Policies (SCP), Azure Policy, Azure Management Groups, GCP Organization Policies and other organizational controls.
  • Develop and maintain guardrails that ensure compliance and prevent insecure configurations in cloud environments.
  • Administer and evolve Cloud Security Posture Management (CSPM) solutions, performing risk analysis, vulnerability prioritization and remediation tracking.
  • Define IAM standards, implementing least-privilege policies, role segregation, identity federation and secure privileged access management.
  • Implement controls related to data protection, encryption, key management (KMS), secrets management and workload protection.
  • Support Infrastructure, DevOps and Engineering teams in building secure cloud solutions.
  • Automate security controls using Infrastructure as Code (Terraform), scripts and automation tools.
  • Integrate security controls into CI/CD pipelines, promoting DevSecOps practices.
  • Conduct technical security assessments, architectural reviews and risk analyses for new cloud projects.
  • Continuously monitor cloud security posture, proposing improvements and evolution plans.
  • Work alongside SOC and Incident Response teams in the investigation and handling of incidents involving cloud environments.
  • Develop metrics, dashboards and executive reports on cloud maturity, compliance and risks.
  • Promote dissemination of Cloud Security best practices and guide technical teams on corporate standards.
Requirements
  • Strong experience in Information Security with a focus on Cloud environments.
  • Advanced knowledge of at least two of the following platforms: AWS, Azure and GCP; experience with all three is desirable.
  • Experience implementing hardening for cloud services.
  • Deep knowledge of IAM, RBAC, identity management, federation and Least Privilege principles.
  • Experience implementing organizational controls such as:
  • AWS Organizations and Service Control Policies (SCP);
  • Azure Policy, Management Groups and RBAC;
  • GCP Organization Policies and IAM.
  • Knowledge of cloud networking (VPC/VNet, subnets, security groups, NSGs, firewall, VPN, load balancer, private endpoints and WAF).
  • Experience with CSPM tools such as Microsoft Defender for Cloud, AWS Security Hub, Prisma Cloud, Wiz, Lacework, Orca or similar.
  • Knowledge of Infrastructure as Code (Terraform, CloudFormation or Bicep).
  • Experience with automation using Python, PowerShell or shell scripting.
  • Knowledge of DevSecOps practices and integrating security controls into CI/CD pipelines.
  • Familiarity with native cloud security services such as:
  • AWS GuardDuty, Security Hub, Config, IAM Access Analyzer, Inspector and CloudTrail;
  • Microsoft Defender for Cloud, Microsoft Sentinel and Azure Monitor;
  • GCP Security Command Center, Cloud Logging, Cloud Armor and IAM.
  • Experience with security frameworks and standards such as CIS Benchmarks, NIST CSF, ISO 27001, MITRE ATT&CK and the Cloud Well-Architected Framework.
  • Knowledge of LGPD (Brazilian Data Protection Law) and cloud compliance best practices.
  • Bachelor's degree in Information Technology, Information Security, Computer Science, Computer Engineering or related fields.
  • Desirable certifications: AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, CCSP, CISSP, CompTIA Security+, Terraform Associate or Kubernetes certifications (CKA/CKS) considered a plus.
Core Competencies

Demonstrates expertise in cloud security management across AWS, Azure, and GCP environments, focusing on implementing security best practices, compliance, and risk management. Proficient in automating security controls and integrating security into CI/CD pipelines while adhering to industry standards and frameworks.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Senior Information Security Analyst, Cloud Security
Senior Information Security Analyst, Cloud Security

Jobtailor • São Paulo

Presencial
BRL 280 000 - 420 000
Cloud Security Engineer
Cloud Security Engineer

Bunge • São Paulo

Presencial
BRL 100 000 - 130 000
Senior Project Security Analyst
Senior Project Security Analyst

Jobtailor • São Paulo

Presencial
BRL 180 000 - 240 000
Cyber Security Specialist
Cyber Security Specialist

Jobtailor • Belo Horizonte

Presencial
BRL 110 000 - 170 000
Senior Analyst – Cloud & Platform Engineering
Senior Analyst – Cloud & Platform Engineering

Jobtailor • Rio de Janeiro

Presencial
BRL 180 000 - 250 000
Especialista em Engenharia de Segurança da Informação
Especialista em Engenharia de Segurança da Informação

Jobtailor • São Paulo

Presencial
BRL 180 000 - 260 000
Information Security Analyst – Junior
Information Security Analyst – Junior

Jobtailor • Vitória

Presencial
Senior IT Support and Infrastructure Analyst
Senior IT Support and Infrastructure Analyst

Jobtailor • São Paulo

Presencial
BRL 180 000 - 300 000
Security Engineering Manager, AWS DevSecOps
Security Engineering Manager, AWS DevSecOps

Rig Globalconsulting • São Paulo

Presencial
Information Security Specialist I
Information Security Specialist I

Jobtailor • Joinville

Presencial
BRL 180 000 - 280 000