GFT Technologies logo
GFT Technologies

As a pioneer for digital transformation GFT develops sustainable solutions across new technologies.

Cloud Security Architect

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 10,001+Since 1987H1B No SponsorCompany SiteLinkedIn

Location

Brazil

Posted

22 days ago

Salary

0

Seniority

Senior

Job Description

Cloud Security Architect

GFT Technologies

• Act as the security architect for public applications hosted on AWS; • Define security standards for edge security, identity, segmentation, observability, and application resilience; • Influence the corporate cloud security strategy, balancing security, scalability, and operational efficiency; • Collaborate with cloud architects and DevOps teams to identify and remediate insecure configurations; • Develop strategies for implementing WAF, CNAPP, and CSPM integrated into the organization’s security framework; • Evaluate new AWS security services and capabilities and translate them into architecture and governance standards; • Establish security guidelines and best practices for software development based on industry frameworks; • Serve as the technical reference for application security during corporate projects; • Work with development teams to integrate security throughout all phases of the SDLC; • Identify, prioritize, and define mitigation strategies for application vulnerabilities; • Integrate security tools, processes, and automations into the DevOps pipeline (DevSecOps); • Define robust authentication and authorization requirements, including privilege and access controls; • Continuously monitor threats, public vulnerabilities, and trends in the security community; • Actively participate in projects, technical forums, and change processes to ensure security by design; • Promote secure design practices and data integrity across users, applications, and infrastructure; • Develop and strengthen a culture of security champions within development teams; • Participate in and lead technical discussions in security forums and meetings; • Build relationships with stakeholders to sustain security initiatives; • Engage in information security projects following leadership guidance.

Job Requirements

  • Experience in cybersecurity with a focus on web application security or security architecture;
  • Experience protecting applications and environments on AWS;
  • Experience in penetration testing, secure code review, and static and dynamic code analysis;
  • Experience identifying and mitigating OWASP vulnerabilities;
  • Familiarity with web application scanning tools;
  • Strong software development background (Java, Python, C#, among others);
  • Experience with web technologies and frameworks (REST, JSON, XML, JavaScript, React);
  • Experience securing internal and third-party APIs;
  • Background in DevOps and public and private cloud environments;
  • Experience implementing and managing Web Application Firewalls (WAF);
  • Knowledge of CNAPP and CSPM;
  • Solid understanding of network and web protocols;
  • Experience with technical documentation;
  • Proven ability to communicate security risks to the business;
  • University degree, preferably in a technical or analytical field;

Benefits

  • Multi-benefit card – you choose how and where to use it.
  • Study grants for undergraduate, graduate, MBA, and language courses.
  • Incentive programs for professional certifications.
  • Flexible working hours.
  • Competitive salaries.
  • Annual performance review with a structured career plan.
  • Opportunity for international career mobility.
  • Wellhub and TotalPass.
  • Private pension plan.
  • Childcare assistance.
  • Health insurance.
  • Dental insurance.
  • Life insurance.

Related Categories

Related Job Pages

More Security Engineer Jobs

Guild logo

Senior Information Security Engineer

Guild

At Guild, we unlock opportunity for America’s workforce through education, skilling, and career mobility.

Full TimeRemoteTeam 1,001-5,000Since 2015H1B Sponsor

Role Description Guild is hiring a Security Engineer. The Information Security team is looking to add a highly motivated and technically inclined individual to work as a Cloud Security Engineer. We are looking for a candidate that is comfortable working in an exciting and fast-paced environment. This individual’s responsibilities will mainly focus on ensuring protection of Guild’s various cloud resources and environments. These efforts will ultimately allow Guild to fulfill its mission while also meeting business objectives and compliance requirements. - Identify security issues and risks with Guild’s systems and environments. - Develop and execute remediation/mitigation plans that provide long-term risk reduction. - Collaborate with cross-functional engineering teams to integrate and advance security standards within a comprehensive enterprise application security program. - Serve as a strategic partner to engineering squads, providing expert guidance on the integration and remediation of findings from SAST, DAST, and SCA tools. - Design and enforce robust security architectures across the company’s AWS ecosystem. - Architect and implement security controls for agentic AI systems, including identity, network, and runtime-level defenses (e.g., sandboxing, policy enforcement). - Develop comprehensive threat models and conduct realistic threat simulations across Guild's offerings, including LLMs, AI agents, and MCP components. - Develop and tune security policy within various security tools and platforms (CNAPP, EDR, Email Gateway, Vulnerability Management, SIEM, etc.). - Maintain SOC-2 compliance and assist with audit/client related requests. - Assist with incident response and investigation activities. - Fulfill regular on-call responsibilities as part of a team rotation. Qualifications - Thorough understanding of Integrated Development Environment (IDE) and Continuous integration / Continuous Delivery (CI/CD) Pipeline tools and processes. - Proven experience with software development methodologies and secure coding practices. - 5+ years of industry experience in security engineering, with meaningful focus on cloud security and application security. - Excellent problem-solving and analytical skills. - Strong communication skills, both written and verbal, for collaborating with technical and non-technical teams. - Ability to work independently, prioritize tasks, and manage multiple security projects simultaneously. Requirements - Solid understanding of LLMs, AI architecture patterns, machine learning models, and related technologies (e.g., MCP, RAG, agentic frameworks). - Experience with container security, kernel-level hardening, and modern isolation techniques. - AWS Certifications. Benefits - Access to low-cost, high-quality health care options through Collective Health and Kaiser (due to coverage limitations, Kaiser is currently only available in CA & CO). - Access to a 401k to help save for the future. - Vacation policy to rest and recharge. - 8 days of fully-paid sick leave, to take the time to heal and or recover. - Family-friendly benefits, including 12 weeks of parental leave for non-birthing parents and 18-20 weeks for birthing parents; 2-week ramp-up period for when employees return from a leave of 6 weeks or more; as well as employer-paid short-term and long-term disability, employer-sponsored life insurance, fertility and caregiving benefits. - Well-rounded wellness benefits including free and low-cost mental health resources and financial wellbeing support services. - Education benefits and tuition assistance to help your future development and growth.

United States
$150K - $180K / year
Clicksign logo

Cloud Security Engineer

Clicksign

Clicksign. O click que muda a sua vida.

Full TimeRemoteTeam 201-500Since 2010H1B No Sponsor

• Implement and evolve security controls in cloud environments, ensuring adherence to best practices and industry standards. • Manage identity and access (IAM), including defining roles, policies, Service Control Policies (SCPs), and secure access controls. • Work with security posture tools (e.g., Config, Security Hub) for monitoring, detection, and remediation of risks. • Support hardening initiatives for cloud infrastructure and Kubernetes (RBAC, network policies, admission controllers). • Define and implement image governance (base images, vulnerability scanners, CVE policies). • Participate in audit and compliance processes, ensuring adherence to regulations and internal controls. • Collaborate on defining cloud architecture standards and guardrails with a security focus. • Work with the team on risk mitigation plans (WAR) and security incident response. • Support FinOps initiatives, balancing security and cost efficiency. • Automate security controls and processes using IaC and CI/CD pipelines.

Brazil
Truelogic Software logo

Senior Vulnerability Researcher

Truelogic Software

Premium boutique software development company that helps brands with big ideas to make a difference in people’s lives.

Full TimeRemoteTeam 501-1,000Since 2004H1B No Sponsor

• Perform security research on web applications, APIs, and complex application workflows. • Identify, validate, and reproduce real-world vulnerabilities in modern applications. • Analyze authentication, authorization, session management, and access control mechanisms. • Translate manual penetration testing techniques into automated detection and exploitation logic. • Develop and refine payloads, exploit strategies, and vulnerability validation methods. • Analyze HTTP traffic, browser behavior, and application flows to uncover security weaknesses. • Collaborate with engineering teams to improve the platform’s automation and offensive security capabilities. • Document findings clearly, including technical details, impact analysis, and reproduction steps.

Mexico
Truelogic Software logo

Senior Vulnerability Researcher - Cybersecurity

Truelogic Software

Premium boutique software development company that helps brands with big ideas to make a difference in people’s lives.

Full TimeRemoteTeam 501-1,000Since 2004H1B No Sponsor

• Perform security research on web applications, APIs, and complex application workflows. • Identify, validate, and reproduce real-world vulnerabilities in modern applications. • Analyze authentication, authorization, session management, and access control mechanisms. • Translate manual penetration testing techniques into automated detection and exploitation logic. • Develop and refine payloads, exploit strategies, and vulnerability validation methods. • Analyze HTTP traffic, browser behavior, and application flows to uncover security weaknesses. • Collaborate with engineering teams to improve the platform’s automation and offensive security capabilities. • Document findings clearly, including technical details, impact analysis, and reproduction steps.

Colombia