
Cloud Security Engineer
Posted Sep 28

Posted Sep 28
This is a fully remote position, open to applicants in Brazil.
• Integrate security measures into CI/CD pipelines (SAST, SCA, image scanning, SBOM, image signing/verification), ensuring that security is woven into the delivery process rather than being a manual checkpoint at the end.
• Evaluate, define, and spearhead the deployment of fortified container images (Wolfi/Chainguard, distroless), minimizing the attack surface and addressing CVEs in the base images utilized by Engineering.
• Oversee vulnerability management and governance: prioritize risks based on impact, establish remediation SLAs, and follow up with Engineering teams until resolution.
• Design and implement security protocols within GCP infrastructure (IAM, networking, Artifact Registry, organization policies), in conjunction with Infrastructure as Code (Terraform).
• Act as a technical expert for pipeline and cloud security, advising Engineering squads on secure development methods (shift-left) without hindering delivery speed.
• Collaborate with SRE to enhance observability and resilience through a security perspective (runtime hardening, incident response, production security posture).
• Conduct targeted penetration testing efforts to validate security controls and remediation actions, augmenting formal penetration testing conducted by external vendors.
• Assist with audits and compliance needs (SOC 2, PCI) concerning pipelines, vulnerabilities, and images.
• Integrate security into the software development and delivery lifecycle (DevSecOps).
• Collaborate closely with Engineering, SRE, and Platform teams as a technical authority, without hierarchical oversight.
• 5+ years of expertise in Cloud Security Engineering, DevSecOps, or Security Engineering, with practical experience in production settings.
• Profound knowledge of Google Cloud Platform (GCP), including IAM, networking, Artifact Registry, and organizational security policies.
• Practical experience in incorporating security into CI/CD pipelines (GitLab CI, Jenkins, or similar) and utilizing vulnerability-scanning tools (e.g., Trivy, Snyk, Wiz).
• Production-level experience with Docker/Kubernetes: multi-stage builds, runtime hardening, non-root execution, and dependency management.
• Familiarity with secure/hardened container images (Wolfi, Chainguard, distroless), or a strong desire to specialize in this domain.
• Proficient scripting skills in Python and/or Bash for automating security measures.
• Knowledge of secure development practices (secure SDLC, OWASP Top 10, and basic threat modeling).
• Experience with SRE methodologies (observability, reliability, and incident response) sufficient for effective technical collaboration with the SRE team.
• Exceptional technical communication skills and the capability to influence Engineering squads without direct hierarchical authority.
• Certifications such as Google Professional Cloud Security Engineer, Certified Kubernetes Security Specialist (CKS), or similar are advantageous.
• Prior experience specifically with Chainguard/Wolfi or other minimal container image ecosystems is a plus.
• Familiarity with SBOMs, image signing (cosign/Sigstore), and supply chain security (SLSA) is a plus.
• Experience with compliance frameworks (SOC 2, PCI-DSS, ISO 27001) is a plus.
• Previous roles as an SRE or on Platform/Infrastructure teams is a plus.
• Contributions to open-source projects or published technical content within the DevSecOps/cloud security community is a plus.
• Health care
• Dental care
• R$1,400 per month on a Caju card (for food and meal allowances, mobility, home office supplies, culture, health, and education)
• Life insurance
• Childcare assistance
• Wellhub (formerly Gympass)
• English course: partnership for group classes at R$100 per month
• Global Equity Program
• Flexible and autonomous work culture
• Global distributed team
• Home office supplies allowance
Integrity360
Rackspace Technology
Efficient Computer
Presidio
Get handpicked remote jobs straight to your inbox weekly.