What You’ll Be Doing:
- Demonstrated expertise in cloud security architecture across AWS/GCP/Azure, including designing secure, scalable cloud environments with a strong focus on identity, network security, encryption, and compliance best practices.
- Extensive experience conducting security architecture reviews for distributed systems and cloud-native applications, identifying design risks early and recommending secure, scalable architectural patterns aligned with business and engineering goals.
- Perform and lead manual and automated penetration testing across applications, APIs, and cloud services.
- Drive threat modeling and secure architecture reviews across app and infrastructure layers.
- Collaborate with Infra/DevOps on cloud network architecture, including VPC design, security groups, routing, and segmentation.
- Design and advise on cloud-native security controls — IAM hardening, role boundaries, secrets management, least privilege.
- Evaluate and improve Kubernetes and container security posture (runtime, image, and network layers).
- Implement secure-by-default patterns across SDLC, CI/CD, and Infrastructure-as-Code.
- Monitor emerging threats, CVEs, and vulnerabilities relevant to our stack (web, cloud, infra).
- Influence internal security tooling, automation pipelines, and security review processes.
- Serve as a security advisor to engineering, SRE, and product teams across key projects.
What You’ll Bring:
- 8+ years of experience in Application Security, Product Security, or Cloud Security, with a strong focus on securing large-scale cloud-native applications.
- Strong hands-on experience with threat modeling, secure architecture reviews, and pen testing.
- Familiar with OWASP Top 10, STRIDE, and modern security frameworks.
- Experience with tools like Burp Suite, ZAP, Snyk, Metasploit, Semgrep.
- Ability to read and analyze code (e.g., JavaScript, Go, PHP, or Node.js).
- Working knowledge of cloud security principles (preferably AWS).
Preferred Qualifications:
- Experience with multi-tenant SaaS platforms or white-labeled architectures.
- Familiarity with network-level security concepts: VPC design, IAM, zero-trust networks.
- Exposure to container security (Docker, Kubernetes).
- Background in B2B SaaS, especially servicing regulated industries (health, legal, finance).
- Hands-on with IaC security and CI/CD pipelines (e.g., GitHub Actions, Terraform).
🇧🇷 Essa vaga exige inglês. Você está pronto?
A DevSpeak Academy prepara desenvolvedores brasileiros para conquistar vagas internacionais. Domine o inglês técnico com professores que entendem o mundo dev.
Conheça a DevSpeak Academy