Skip to content

Open nowPosted 19 days ago

Engenheiro DevSecOps Sênior

Gupy (Portal de Vagas)74,832 open roles

Where
Eldorado do Sul, Rio Grande do Sul, Brazil
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowEngenheiro DevSecOps SêniorGupy (Portal de Vagas) · Eldorado do Sul, Rio Grande do Sul, Brazil
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Gupy (Portal de Vagas)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Gupy (Portal de Vagas) postings stay open a median of 1 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.0%30 days
This job: posted 19 days ago

Gupy (Portal de Vagas) median: 1 days open

The posting

Buscamos uma pessoa DevSecOps Engineer Sênior para atuar na evolução da segurança, automação e confiabilidade da nossa plataforma e do ciclo de desenvolvimento de software. A posição terá atuação transversal junto aos times de Engenharia, Segurança, Infraestrutura e Arquitetura, sendo responsável por definir e implementar práticas de DevSecOps, Secure SDLC e Security by Design, promovendo segurança de forma automatizada e integrada à experiência dos times de desenvolvimento. Esperamos uma pessoa com forte capacidade técnica, autonomia para investigar problemas complexos e habilidade para transformar requisitos de segurança em soluções escaláveis e com baixo atrito para Engenharia.Responsabilidades e atribuiçõesDefinir e evoluir a estratégia técnica de DevSecOps e Secure SDLC.Projetar e implementar controles de segurança integrados aos pipelines de CI/CD.Definir padrões e arquiteturas para automação de segurança ao longo do ciclo de desenvolvimento.Implementar e evoluir soluções de SAST, DAST, SCA, Secret Scanning, Container Scanning e IaC Scanning.Desenvolver ferramentas, integrações e automações internas para segurança.Definir critérios de qualidade e security gates para pipelines de desenvolvimento.Liderar tecnicamente iniciativas de identificação, priorização e remediação de vulnerabilidades.Definir estratégias de Infrastructure as Code (IaC) e segurança da infraestrutura.Implementar e evoluir controles de segurança para containers e ambientes Kubernetes.Definir e implementar controles de segurança para ambientes cloud.Projetar, implementar e evoluir arquiteturas e políticas de Web Application Firewall (WAF).Projetar e evoluir arquiteturas de API Gateway, garantindo segurança, disponibilidade, observabilidade e governança das APIs.Evoluir práticas relacionadas a IAM, RBAC, least privilege, gestão de secrets e segregação de acessos.Implementar mecanismos de observabilidade e monitoramento relacionados à segurança.Apoiar investigações técnicas e processos de resposta a incidentes.Participar de processos de threat modeling e revisões de arquitetura.Definir padrões técnicos, guidelines e boas práticas de segurança para os times de Engenharia.Avaliar riscos técnicos e propor controles proporcionais ao impacto e à criticidade dos sistemas.Atuar como referência técnica em DevSecOps, apoiando e orientando outros profissionais e equipes.Avaliar novas tecnologias e ferramentas relacionadas a segurança, automação e cloud-native security.Requisitos e qualificaçõesLinux e ambientes Unix-like.Git e workflows modernos de desenvolvimento.Arquitetura e implementação de pipelines de CI/CD.GitHub Actions, GitLab CI, Jenkins, Azure DevOps ou tecnologias equivalentes.Docker e segurança de containers.Kubernetes e segurança de ambientes Kubernetes.Infrastructure as Code com Terraform, Ansible ou ferramentas similares.Ambientes cloud como AWS, Azure ou Google Cloud.Segurança de aplicações, OWASP Top 10 e OWASP API Security Top 10.Arquitetura, configuração e operação de soluções de WAF.Arquitetura e operação de API Gateways.Segurança de APIs REST e conhecimento de padrões de autenticação e autorização, como OAuth 2.0, OpenID Connect e JWT.Implementação e operação de ferramentas de SAST, DAST e SCA.Análise de dependências, vulnerabilidades e CVEs.Segurança de imagens de containers e registries.Segurança de Infrastructure as Code.IAM, RBAC e princípios de menor privilégio.Gestão de secrets e credenciais.Observabilidade, logging, métricas e tracing.Automação e desenvolvimento utilizando Python, Go, Bash ou linguagens equivalentes.Fundamentos sólidos de redes, incluindo TCP/IP, DNS, HTTP, TLS e segurança de redes.DiferenciaisConhecimento de arquitetura Zero Trust.Conhecimento de CIS Benchmarks, NIST, OWASP SAMM, ISO 27001, PCI ou frameworks similares.Experiência com estratégias de bot management, proteção contra abuso de APIs e mitigação de ataques DDoS.Informações adicionaisModelo de trabalho: Híbrido (Presencial\Remoto)Disponibilidade para atuar em Eldorado do Sul/RSRefeitório no local;TotalPass;Plano de Saúde & Odonto (via cooperativa);Transporte Fretado;Descontos exclusivos na Panvel;

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Gupy (Portal de Vagas)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Gupy (Portal de Vagas)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Gupy (Portal de Vagas)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.