
Security Engineer
Posted 12 hours ago

Posted 12 hours ago
This is a fully remote position, open to applicants in Brazil.
• Implement the technical security tasks outlined by the Lead Engineer, providing deliverables for evaluation.
• Focus on cloud security in production environments (AWS and OVH): IAM, VPCs, Security Groups, KMS, secrets management, hardening, and public exposure assessment.
• Oversee the complete lifecycle of vulnerability management: triage, classification (CVSS), assignment of ownership and deadlines, evidence gathering, and retesting.
• Utilize SAST, DAST, and SCA tools, effectively differentiating real findings from false positives before generating work items for product teams.
• Perform security-centric code reviews, utilizing the OWASP Top 10 and API Security Top 10 standards.
• Establish and uphold security checkpoints within CI/CD pipelines and infrastructure as code practices.
• Engage in container security, which includes image creation, registries, and runtime hardening.
• Develop queries and detection rules within a SIEM or log management system and create corresponding runbooks.
• Carry out regular access reviews, implementing MFA, least privilege principles, and secrets vaults.
• Automate evidence gathering and control validation through Python or Bash scripting.
• Record what was tested, how it was tested, and what was validated, treating the evidence as a deliverable.
• Communicate risks and escalate any issues beyond the assigned scope to the Lead Engineer.
• Practical experience with production cloud security in AWS, including IAM and policies, VPCs and segmentation, Security Groups, KMS/secrets, hardening, and public exposure assessments.
• Proficiency in Linux and networking troubleshooting, covering TCP/IP, DNS, TLS, VPNs, firewalls, and traffic analysis.
• Knowledge of application security (AppSec): familiarity with the OWASP Top 10 and API Security Top 10, security-focused code reviews, and operation of SAST, DAST, and SCA tools, with the capability to distinguish real findings from false positives.
• Experience with infrastructure as code and CI/CD practices: Terraform and pipelines (GitHub Actions, GitLab CI, or equivalent), including the establishment of security gates.
• Understanding of container technology: Docker, image creation, registries, and basic runtime hardening.
• Comprehensive vulnerability management skills: triage, classification (CVSS), assignment of ownership and deadlines, evidence collection, and retesting.
• Logging and detection capabilities: writing queries and rules for a SIEM or log management system (CloudWatch, OpenSearch, Wazuh, Splunk, Sentinel, or similar) and developing runbooks.
• Knowledge of identity and access management: MFA, least privilege, secrets vaults, and conducting periodic access reviews.
• Proficiency in Python or Bash scripting for automation, evidence collection, and control validation.
• Strong documentation skills: treat evidence as a crucial deliverable of the role rather than a secondary outcome.
• Proficient in English for technical reading (documentation, advisories, tools, and consoles).
• Ability to operate under guidance: implement the standards set by the Lead Engineer, provide deliverables for review, and escalate any matters beyond the assigned scope.
• Flexible working hours.
• Career development plan.
Atos
Meridian Bioscience Inc.
Providence
Frontera
Get handpicked remote jobs straight to your inbox weekly.