Cloud Security Engineer
New
J
JobgetherCloud security
Based in BrazilFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years of practical experience in Cloud Security Engineering, DevSecOps, Security Engineering, or a closely related discipline, including production environments.
- Required Skills
- DockerPythonBashGCPKubernetesTerraform
Requirements
- Have 5+ years of practical experience in Cloud Security Engineering, DevSecOps, Security Engineering, or a closely related discipline, including production environments.
- Have hands-on knowledge of Google Cloud Platform, particularly IAM, networking, Artifact Registry, and organization-level security policies.
- Have experience integrating security controls into CI/CD pipelines using GitLab CI, Jenkins, or similar technologies.
- Have practical experience with vulnerability scanning tools such as Trivy, Snyk, or Wiz.
- Have production experience with Docker and Kubernetes, including multi-stage builds, runtime hardening, non-root execution, and dependency management.
- Know hardened and minimal container image ecosystems such as Wolfi, Chainguard, and distroless, or be willing to develop deep expertise in them.
- Have scripting skills in Python and/or Bash for security automation and control implementation.
- Understand secure SDLC practices, OWASP Top 10, and basic threat modeling.
- Be familiar with SRE practices including observability, reliability, and incident response.
- Have technical communication skills and the ability to influence engineering teams without direct managerial authority.
- Experience with SBOMs, container image signing, cosign/Sigstore, and software supply chain security such as SLSA is an advantage.
- Experience with SOC 2, PCI-DSS, or ISO 27001 is preferred; relevant cloud security or Kubernetes security certifications are valued.
Responsibilities
- Integrate SAST, SCA, container scanning, SBOM generation, and image signing and verification into CI/CD pipelines.
- Establish security practices within standard software delivery workflows.
- Evaluate and lead the rollout of hardened container images, reducing attack surface and vulnerabilities in base images.
- Lead vulnerability management, including risk-based prioritization, remediation SLAs, and follow-up with engineering teams.
- Design and implement security controls across GCP infrastructure, including IAM, networking, Artifact Registry, and organization security policies.
- Use Terraform to implement and maintain cloud security controls.
- Advise engineering squads on secure development and shift-left practices.
- Collaborate with SRE teams on security observability, runtime hardening, resilience, production security, and incident response.
- Conduct targeted penetration testing to validate security controls and remediation.
- Support audits and compliance requirements related to CI/CD, vulnerability management, container images, and cloud security.
View Full Description & ApplyYou'll be redirected to the employer's site