
Lead Security Engineer
Posted Aug 20

Posted Aug 20
This is a fully remote position, open to applicants in Brazil.
• Oversee security comprehensively across the PHP/Laravel and TypeScript/React codebase, AWS infrastructure, payment processes, customer data flows, and compliance posture.
• Define the multi-year security strategy and implement scalable security controls.
• Develop threat models, automated scanning procedures, incident runbooks, standards, playbooks, and hiring criteria.
• Manage application security, encompassing secure SDLC practices, code and design reviews, CI scanning, and vulnerability management.
• Direct cloud and infrastructure security, focusing on AWS posture, IAM, networking, encryption, secrets management, and EKS/Kubernetes hardening.
• Lead efforts in PCI scope mapping, SOC 2 and LGPD compliance readiness, vendor risk assessments, and responses to audit/customer security questionnaires.
• Enhance detection capabilities and spearhead incident response as necessary.
• Establish security scans, review gates, conventions, and evaluations for AI-generated code.
• Collaborate with delivery teams and Cloud & DevOps to facilitate secure shipping as the default practice.
• Plan, recruit, mentor, and lead a small security team within approximately 12–18 months.
• Create a risk register, CI security pipeline, compliance baseline, detection and response program, multi-year roadmap, and business case for initial security hires.
• Hands-on experience in at least three areas: application security, cloud security, compliance, and incident response.
• Profound experience in building and managing security controls across various domains.
• Proficient in utilizing AI tools on a daily basis in security operations.
• Familiarity with threat modeling, secure SDLC, code and design reviews, SAST, secret scanning, dependency scanning, and vulnerability management.
• Proven experience securing AWS infrastructure, including IAM, networking, encryption, secrets management, and EKS/Kubernetes hardening.
• Knowledgeable in PCI scope mapping, SOC 2 and LGPD readiness, vendor risk, and security questionnaire responses.
• Experienced in detection and response, including tools like Datadog, Sentry, AWS signals, incident runbooks, MTTD, and MTTR.
• Capability to establish automated security gates and conventions for AI-generated code.
• Hands-on engineering skills to write scripts, build pipelines, configure AWS guardrails, and implement detections.
• Ability to prioritize risks pragmatically and mitigate them with minimal friction.
• Strong collaborative skills with delivery teams and Cloud & DevOps.
• Understanding of payments and marketplace security.
• Willingness and capability to build and lead a small security team within approximately 12–18 months.
• Take the lead in security initiatives and elevate the standards.
• Competitive cash compensation at the top of the market.
• Fully remote work opportunity (Brazil).
• Contractor (PJ) engagement model.
• Access to AI tools, including Claude Code and the agent stack utilized by engineering.
• No equity offered.
Cloudiax
Cisco
Cisco
Skylight
Get handpicked remote jobs straight to your inbox weekly.