Jobgether
Cloud Security Engineer
- Location
- Brazil, BR
- Arrangement
- Remote
- Employment type
- Full-time
- Posted
- 29 September 2026 (yesterday)
Checked yesterdayApplications go to the employer, never to RoleSprint
About this role
Accountabilities: • Integrate security controls into CI/CD pipelines, including SAST, SCA, container scanning, SBOM generation, and image signing and verification.
• Establish security practices that become part of the standard software delivery workflow rather than relying on manual controls at the end of the process.
• Evaluate, define, and lead the rollout of hardened container images using technologies and approaches such as Wolfi, Chainguard, and distroless images.
• Reduce attack surface and vulnerabilities in the base container images used by engineering teams.
• Lead vulnerability management and governance, including risk-based prioritization, remediation SLAs, and follow-up with engineering teams through resolution.
• Design and implement security controls across GCP infrastructure, including IAM, networking, Artifact Registry, and organization security policies.
• Work with Infrastructure as Code practices, particularly Terraform, to implement and maintain cloud security controls.
• Act as a technical security reference for engineering squads, promoting secure development and shift-left practices without unnecessarily slowing delivery.
• Collaborate with SRE teams on security-focused observability, runtime hardening, resilience, production security posture, and incident response.
• Conduct targeted penetration testing activities to validate security controls and remediation efforts alongside formal external penetration testing engagements.
• Support audits and compliance requirements related to CI/CD pipelines, vulnerability management, container images, and cloud security, including SOC 2 and PCI requirements.
• Establish and promote security standards that can be consistently adopted across technical teams.
Requirements:
• 5+ years of practical experience in Cloud Security Engineering, DevSecOps, Security Engineering, or a closely related discipline, including production environments.
• Strong hands-on knowledge of Google Cloud Platform, particularly IAM, networking, Artifact Registry, and organization-level security policies.
• Experience integrating security controls into CI/CD pipelines using GitLab CI, Jenkins, or similar technologies.
• Practical experience with vulnerability scanning tools such as Trivy, Snyk, Wiz, or comparable solutions.
• Strong production experience with Docker and Kubernetes, including multi-stage builds, runtime hardening, non-root execution, and dependency management.
• Knowledge of hardened and minimal container image ecosystems such as Wolfi, Chainguard, and distroless, or a strong willingness to develop deep expertise in these technologies.
• Solid scripting skills in Python and/or Bash for security automation and control implementation.
• Strong understanding of secure SDLC practices, OWASP Top 10, and basic threat modeling.
• Familiarity with SRE practices including observability, reliability, and incident response, with the ability to collaborate effectively with SRE teams.
• Strong technical communication skills and the ability to influence engineering teams without direct managerial authority.
• Experience with SBOMs, container image signing, cosign/Sigstore, and software supply chain security such as SLSA is an advantage.
• Experience with compliance frameworks such as SOC 2, PCI-DSS, or ISO 27001 is preferred.
• Previous experience in SRE, platform engineering, or infrastructure teams is beneficial.
• Certifications such as Google Professional Cloud Security Engineer, Certified Kubernetes Security Specialist (CKS), or equivalent are valued.
• Experience with Chainguard/Wolfi or other minimal-image ecosystems is a plus.
• Open-source contributions or published technical content related to DevSecOps or cloud security are advantageous.
Benefits:
• Full-time, remote position based in Brazil.
• Healthcare coverage.
• Dental care.
• R$1,400 per month through a Caju card, covering areas such as food and meals, mobility, home-office supplies, culture, health, and education.
• Life insurance.
• Childcare assistance.
• Wellhub membership.
• Access to an English course through a group-class partnership for R$100 per month.
• Global Equity Program.
• Opportunity to work in a globally distributed environment across the Americas.
• Flexible and autonomous working culture.
• High-impact technical role with significant influence over cloud security, DevSecOps, and software supply chain practices.
• Collaboration with engineering, SRE, and platform teams on modern cloud-native infrastructure.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Work location
- BR
Related jobs
Ready to make a decision?
This role is either worth your time or it isn’t.
Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.
Nothing is submitted automatically. You choose what happens next.
About this listing
Published on Lever under the board identifier Jobgether, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.
RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.
Published 29 September 2026, last checked yesterday. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.