Cloud Security Engineer

New
J
JobgetherCloud security
Based in BrazilFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
5+ years of practical experience in Cloud Security Engineering, DevSecOps, Security Engineering, or a closely related discipline, including production environments.
Required Skills
DockerPythonBashGCPKubernetesTerraform

Requirements

  • Have 5+ years of practical experience in Cloud Security Engineering, DevSecOps, Security Engineering, or a closely related discipline, including production environments.
  • Have hands-on knowledge of Google Cloud Platform, particularly IAM, networking, Artifact Registry, and organization-level security policies.
  • Have experience integrating security controls into CI/CD pipelines using GitLab CI, Jenkins, or similar technologies.
  • Have practical experience with vulnerability scanning tools such as Trivy, Snyk, or Wiz.
  • Have production experience with Docker and Kubernetes, including multi-stage builds, runtime hardening, non-root execution, and dependency management.
  • Know hardened and minimal container image ecosystems such as Wolfi, Chainguard, and distroless, or be willing to develop deep expertise in them.
  • Have scripting skills in Python and/or Bash for security automation and control implementation.
  • Understand secure SDLC practices, OWASP Top 10, and basic threat modeling.
  • Be familiar with SRE practices including observability, reliability, and incident response.
  • Have technical communication skills and the ability to influence engineering teams without direct managerial authority.
  • Experience with SBOMs, container image signing, cosign/Sigstore, and software supply chain security such as SLSA is an advantage.
  • Experience with SOC 2, PCI-DSS, or ISO 27001 is preferred; relevant cloud security or Kubernetes security certifications are valued.

Responsibilities

  • Integrate SAST, SCA, container scanning, SBOM generation, and image signing and verification into CI/CD pipelines.
  • Establish security practices within standard software delivery workflows.
  • Evaluate and lead the rollout of hardened container images, reducing attack surface and vulnerabilities in base images.
  • Lead vulnerability management, including risk-based prioritization, remediation SLAs, and follow-up with engineering teams.
  • Design and implement security controls across GCP infrastructure, including IAM, networking, Artifact Registry, and organization security policies.
  • Use Terraform to implement and maintain cloud security controls.
  • Advise engineering squads on secure development and shift-left practices.
  • Collaborate with SRE teams on security observability, runtime hardening, resilience, production security, and incident response.
  • Conduct targeted penetration testing to validate security controls and remediation.
  • Support audits and compliance requirements related to CI/CD, vulnerability management, container images, and cloud security.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now