
SRE Mid-level – Pipeline, Site Reliability Engineer
Posted 20 hours ago

Posted 20 hours ago
This is a fully remote position, open to applicants in Brazil.
• Develop and uphold scalable, secure, and observable CI/CD pipelines within GitLab.
• Execute a "shift-left" security approach by seamlessly integrating scanning tools into developers' workflows without introducing unnecessary obstacles.
• Establish severity baselines and oversee the gradual shift of scanners from "report-only" mode to "blocking" mode.
• Containerize applications utilizing optimized Dockerfiles (including multi-stage and minimal/distroless images) and manage the image lifecycle in the Artifact Registry.
• Set up secure authentication methods between GitLab and GCP using OIDC and Workload Identity Federation.
• Enhance pipeline observability (including execution time, failure rates, and runner costs) while optimizing both performance and costs.
• Document and advocate for DevSecOps practices, acting as a technical reference for product teams.
• Engage in a reliability-focused culture involving SLOs, blameless postmortems, and minimizing toil.
• Practical experience in constructing CI/CD pipelines, preferably with GitLab CI/CD; experience with Bitbucket Pipelines, GitHub Actions, or Jenkins will also be considered relevant.
• In-depth understanding of Docker and image building (including multi-stage, optimization, and container security).
• Familiarity with at least one cloud service provider, with GCP being a significant advantage (including Artifact Registry, IAM, Service Accounts, and Workload Identity).
• Knowledge of DevSecOps practices and scanning tools (including SAST, SCA, and secret detection).
• Proficiency in Bash scripting and at least one programming language (such as Python, Go, or equivalent).
• Experience with Git version control and workflows based on Merge/Pull Requests.
• Additional beneficial experience includes GitLeaks, Semgrep, and/or Trivy; configuration of OIDC and Workload Identity Federation; knowledge of Terraform or Pulumi; experience with Kubernetes/GKE and deployment strategies (such as Cloud Run, GKE, blue-green, canary); integration of AI/LLM tools into engineering workflows; image signing (cosign), SBOM generation, and supply chain security (SLSA); and cloud certifications (such as GCP Professional Cloud DevOps Engineer or equivalent).
• Health and dental insurance
• Meal allowance and/or food voucher
• Wellhub (formerly Gympass)
• Profit-sharing linked to goals and results
• Life insurance
• Conexa (online medical and psychological consultations at no cost)
• Private pension plan
Renesas Electronics
Software Mind
Voltz
Stone & Company
Get handpicked remote jobs straight to your inbox weekly.