- Implement and manage security controls in AWS, including VPC, EC2, S3, RDS, Lambda, IAM, CloudFront, GuardDuty, and Organizations
- Apply CSPM rules and ensure the security of Kubernetes workloads (EKS)
- Remediate vulnerabilities in container images in collaboration with DevOps teams
- Structure and audit permissions based on the principle of least privilege
- Administer AWS Identity Center and implement/manage AWS Secrets Manager
- Lead the containment and root-cause investigation of critical incidents, such as data breaches, phishing, and DDoS attacks
- Integrate security tools with the QRadar SIEM, tuning alerts and reducing false positives
- Operate CrowdStrike Falcon (EDR/CSPM), Qualys, and BitSight
- Orchestrate penetration testing (Red Team) with external providers
- Coordinate vulnerability remediation with development teams
- Create and maintain policies, procedures, and runbooks
- Support regulatory audits, including Central Bank audits, and ensure alignment with the LGPD, CIS Controls, NIST, and OWASP Top 10
- Develop Python/Bash scripts and automate compliance checks, violation alerts, and operational security tasks
- Assess architectural risks during Change Management (GMUD) processes before production deployments
Requirements
- Strong knowledge of AWS architecture, Terraform, Docker, Kubernetes (EKS), and Linux systems administration
- Hands-on experience with CrowdStrike (EDR and CSPM), QRadar SIEM, Qualys, BitSight, AWS Secrets Manager, WAF (Signal Sciences / AWS WAF), and VPN/DNS solutions
- Proficiency in Python and Bash for automating security tasks and log analysis
- Applied knowledge of NIST, CIS Controls, OWASP Top 10, Zero Trust architecture, and LGPD regulations
- Advanced English proficiency (reading, writing, and technical communication)
- Previous experience supporting Financial Sector audits (Central Bank) is a plus
- Industry certifications such as AWS Certified Security – Specialty, Certified Kubernetes Security Specialist (CKS), CISSP, or CompTIA Security+ are a plus
- Experience in the Financial Sector is a plus
Core Competencies
Demonstrates expertise in implementing and managing security controls in AWS, including VPC, EC2, and IAM, while ensuring compliance with regulations such as LGPD and NIST. Proficient in automating security tasks using Python and Bash, and experienced in coordinating vulnerability remediation and incident response.
Highest-signal resume keywords
- AWS Security Management
- Kubernetes Security (EKS)
- Incident Response Leadership
- Python/Bash Automation
- Regulatory Compliance (LGPD, NIST)
ATS Optimization Keywords
Hard Skills
- AWS Architecture
- Terraform
- Docker
- Linux Systems Administration
- Vulnerability Remediation
- Security Policy Development
- Penetration Testing
- Log Analysis
- Security Tool Integration
- Change Management Risk Assessment
Soft Skills
- Collaboration
- Communication
- Problem-Solving
- Leadership
Certifications & Qualifications
- AWS Certified Security – Specialty
- Certified Kubernetes Security Specialist (CKS)
- CISSP
- CompTIA Security+
Industry Keywords
- Financial Sector
- Central Bank Audits
- CIS Controls
- OWASP Top 10
- Zero Trust Architecture
Tools & Technologies
- CrowdStrike Falcon
- QRadar SIEM
- Qualys
- BitSight
- AWS Secrets Manager
- WAF (Signal Sciences / AWS WAF)
- VPN Solutions
- DNS Solutions