
Information Security Analyst, Mid-Level – DevSecOps
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Brazil.
• Assist the development team in the adoption of DevSecOps and Secure by Design methodologies.
• Design, develop, and improve CI/CD pipelines, integrating security controls into the development workflow.
• Incorporate security tools into pipelines, including SAST, DAST, SCA, and container vulnerability assessment tools.
• Automate security controls and related processes.
• Identify and address vulnerabilities within applications, dependencies, packages, images, and components.
• Aid in the remediation of vulnerabilities identified through security tools, scanners, and technical evaluations.
• Execute security enhancements in AWS environments, encompassing services, configurations, permissions, networks, and resources.
• Evaluate security configurations and suggest improvements for AWS assets.
• Assist in reinforcing the security of systems, servers, containers, and infrastructure elements.
• Facilitate the secure management of secrets, credentials, keys, and certificates.
• Establish controls to prevent the leakage of credentials and sensitive data in source code, pipelines, and development settings.
• Collaborate with developers, DevOps, infrastructure, and security teams to integrate security throughout the development lifecycle.
• Contribute to the development and ongoing enhancement of security standards and best practices for development and cloud platforms.
• Record implemented configurations, processes, standards, and enhancements.
• Professional background in Information Security, DevSecOps, Cloud Security, or related domains.
• Practical experience with AWS.
• Understanding of CI/CD and familiarity with at least one pipeline platform, such as GitHub Actions, GitLab CI/CD, Azure DevOps, Jenkins, or a similar tool.
• Proficient in Git and software development methodologies.
• Knowledgeable in security for Linux systems.
• Familiar with Docker and containerization.
• Experienced in managing secrets, credentials, keys, and certificates.
• Basic to intermediate understanding of IAM and cloud access control.
• Acquainted with SAST, DAST, SCA, and container scanning principles.
• Capable of analyzing security challenges and executing appropriate remediation strategies.
• A collaborative mindset with the ability to work effectively alongside development teams.
• Competitive salary and performance-based bonuses.
• Opportunities for professional development and training.
• Flexible work hours and remote work options.
• Health and wellness programs.
• Inclusive and diverse work environment.
SoftExpert - Software for Excellence
Nasajon Sistemas
AeroVironment
Valon
Get handpicked remote jobs straight to your inbox weekly.