Job Closed
This listing is no longer active.
Clicksign. O click que muda a sua vida.
Cloud Security Engineer
Location
Brazil
Posted
81 days ago
Salary
0
Seniority
Senior
Job Description
Cloud Security Engineer
Clicksign
• Implement and evolve security controls in cloud environments, ensuring adherence to best practices and industry standards. • Manage identity and access (IAM), including defining roles, policies, Service Control Policies (SCPs), and secure access controls. • Work with security posture tools (e.g., Config, Security Hub) for monitoring, detection, and remediation of risks. • Support hardening initiatives for cloud infrastructure and Kubernetes (RBAC, network policies, admission controllers). • Define and implement image governance (base images, vulnerability scanners, CVE policies). • Participate in audit and compliance processes, ensuring adherence to regulations and internal controls. • Collaborate on defining cloud architecture standards and guardrails with a security focus. • Work with the team on risk mitigation plans (WAR) and security incident response. • Support FinOps initiatives, balancing security and cost efficiency. • Automate security controls and processes using IaC and CI/CD pipelines.
Job Requirements
- Hands-on experience with cloud security (preferably AWS).
- Experience with tools such as WAF, CloudTrail, and GuardDuty.
- Knowledge of IAM (roles, policies, least privilege, federation).
- Experience with cloud security and compliance tools (Config, Security Hub, or similar).
- Experience with containers and Kubernetes, including security practices (RBAC, network policies).
- Experience with vulnerability scanners and CVE management.
- Knowledge of Infrastructure as Code (Terraform, CloudFormation, or similar).
- Experience with CI/CD and integrating security controls into pipelines.
- Good communication skills and ability to work collaboratively with multidisciplinary teams.
Benefits
- 100% remote work.
- Trust-based culture, results-oriented with plenty of challenge and learning opportunities.
- Autonomy and ownership in a collaborative and empathetic environment.
- Feedback culture and 1:1s with approachable leadership and no micromanagement.
- Comprehensive benefits including: meal/food allowance, childcare support, home office allowance, health coverage, education and culture benefits, Gympass, birthday day off, discounts on therapy and English courses, and other partner benefits.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Vulnerability Researcher
Truelogic SoftwarePremium boutique software development company that helps brands with big ideas to make a difference in people’s lives.
• Perform security research on web applications, APIs, and complex application workflows. • Identify, validate, and reproduce real-world vulnerabilities in modern applications. • Analyze authentication, authorization, session management, and access control mechanisms. • Translate manual penetration testing techniques into automated detection and exploitation logic. • Develop and refine payloads, exploit strategies, and vulnerability validation methods. • Analyze HTTP traffic, browser behavior, and application flows to uncover security weaknesses. • Collaborate with engineering teams to improve the platform’s automation and offensive security capabilities. • Document findings clearly, including technical details, impact analysis, and reproduction steps.
Senior Vulnerability Researcher - Cybersecurity
Truelogic SoftwarePremium boutique software development company that helps brands with big ideas to make a difference in people’s lives.
• Perform security research on web applications, APIs, and complex application workflows. • Identify, validate, and reproduce real-world vulnerabilities in modern applications. • Analyze authentication, authorization, session management, and access control mechanisms. • Translate manual penetration testing techniques into automated detection and exploitation logic. • Develop and refine payloads, exploit strategies, and vulnerability validation methods. • Analyze HTTP traffic, browser behavior, and application flows to uncover security weaknesses. • Collaborate with engineering teams to improve the platform’s automation and offensive security capabilities. • Document findings clearly, including technical details, impact analysis, and reproduction steps.
Senior Vulnerability Researcher – Cybersecurity
Truelogic SoftwarePremium boutique software development company that helps brands with big ideas to make a difference in people’s lives.
• Perform security research on web applications, APIs, and complex application workflows. • Identify, validate, and reproduce real-world vulnerabilities in modern applications. • Analyze authentication, authorization, session management, and access control mechanisms. • Translate manual penetration testing techniques into automated detection and exploitation logic. • Develop and refine payloads, exploit strategies, and vulnerability validation methods. • Analyze HTTP traffic, browser behavior, and application flows to uncover security weaknesses. • Collaborate with engineering teams to improve the platform’s automation and offensive security capabilities. • Document findings clearly, including technical details, impact analysis, and reproduction steps.
Senior Vulnerability Researcher – Cybersecurity
Truelogic SoftwarePremium boutique software development company that helps brands with big ideas to make a difference in people’s lives.
• Perform security research on web applications, APIs, and complex application workflows. • Identify, validate, and reproduce real-world vulnerabilities in modern applications. • Analyze authentication, authorization, session management, and access control mechanisms. • Translate manual penetration testing techniques into automated detection and exploitation logic. • Develop and refine payloads, exploit strategies, and vulnerability validation methods. • Analyze HTTP traffic, browser behavior, and application flows to uncover security weaknesses. • Collaborate with engineering teams to improve the platform’s automation and offensive security capabilities. • Document findings clearly, including technical details, impact analysis, and reproduction steps.

