Skip to content

Open nowPosted 10 days ago

Especialista de Segurança Multi-Cloud

Gupy (Portal de Vagas)74,621 open roles

Where
Barueri, São Paulo, Brazil
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowEspecialista de Segurança Multi-CloudGupy (Portal de Vagas) · Barueri, São Paulo, Brazil
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Gupy (Portal de Vagas)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 10 days ago

The posting

Atuar como Especialista de Segurança Multi-Cloud, sendo responsável por definir, implementar e evoluir a estratégia de segurança dos ambientes em nuvem da organização, garantindo que plataformas, aplicações, dados, APIs, microsserviços e integrações operem de forma segura, resiliente e aderente às exigências regulatórias do setor financeiro. A posição possui caráter estratégico e estruturante, com forte atuação em arquitetura segura, governança cloud, proteção de infraestrutura crítica, gestão de riscos tecnológicos e segurança de ambientes distribuídos. O profissional atuará como referência técnica para iniciativas em cloud e ambientes híbridos, apoiando áreas de Arquitetura, Engenharia, Infraestrutura, DevSecOps, Cyber Security e Produtos, garantindo que a segurança seja incorporada desde a concepção até a operação dos serviços em produção. Buscamos um profissional que combine visão estratégica, profundidade técnica e capacidade de influência para apoiar a evolução da maturidade de Cloud Security da organização.

Responsabilidades e atribuiçõesDefinir e evoluir padrões corporativos de segurança para ambientes AWS, Azure e demais provedores utilizados pela organização. Avaliar arquiteturas sob a ótica de segurança, resiliência e compliance. Participar de iniciativas de Security by Design em novos produtos e projetos. Definir requisitos mínimos de segurança para workloads cloud.Apoiar processos de revisão arquitetural e aprovação de soluções.

Avaliar e apoiar a proteção de ambientes Kubernetes, containers e plataformas distribuídas. Definir controles de segurança para ambientes EKS, AKS e demais serviços gerenciados. Avaliar riscos relacionados a aplicações cloud-native, APIs, serverless e arquiteturas orientadas a microsserviços. Apoiar iniciativas de hardening e redução de superfície de ataque. Definir critérios de proteção para ambientes críticos de negócio.

Definir padrões corporativos de IAM. Evoluir estratégias de autenticação, autorização e acesso privilegiado. Apoiar iniciativas de Zero Trust. Definir controles para federação de identidades, Single Sign-On e MFA. Apoiar revisões periódicas de acessos privilegiados. Definir padrões para gestão de segredos, certificados e chaves criptográficas.

Definir controles para segmentação e isolamento de ambientes. Apoiar a proteção de serviços publicados na internet. Avaliar riscos relacionados a DNS, APIs, WAF, balanceadores, gateways e integrações externas. Definir estratégias de proteção contra ataques de camada de aplicação. Apoiar iniciativas de redução de exposição de ativos críticos.

Estabelecer baselines de segurança para todos os ambientes cloud. Apoiar processos de conformidade e aderência regulatória. Definir métricas e indicadores de segurança cloud. Produzir indicadores executivos para acompanhamento de riscos e evolução da maturidade. Apoiar processos de auditoria interna e externa.

Liderar iniciativas de monitoramento contínuo da postura de segurança em nuvem. Identificar exposições, desvios de configuração e riscos operacionais. Apoiar processos de priorização e remediação de vulnerabilidades. Avaliar riscos relacionados a ativos expostos à internet. Apoiar iniciativas de Continuous Threat Exposure Management (CTEM).

Integrar controles de segurança aos pipelines de desenvolvimento e entrega contínua. Apoiar iniciativas de Infrastructure as Code Security. Definir requisitos mínimos de segurança para automação de infraestrutura. Apoiar iniciativas de compliance contínuo. Promover a adoção de práticas seguras em processos DevOps.

Avaliar riscos relacionados a novas tecnologias, projetos e provedores. Apoiar processos de exceção de risco e planos de remediação. Produzir documentação e evidências para auditorias. Apoiar iniciativas relacionadas à LGPD, BACEN, Open Finance, PCI-DSS e demais normativos aplicáveis. Atuar como referência técnica em temas de segurança cloud perante áreas de negócio e tecnologia.

Requisitos e qualificaçõesExperiência comprovada em:

Cloud Security Architecture; Segurança AWS; Segurança Azure; Gestão de Riscos Tecnológicos; Cloud Networking; Identity & Access Management; Kubernetes Security; Container Security; DevSecOps; Security by Design; Threat Modeling; Cloud Governance.AWS; Azure; Ambientes híbridos e multi-cloud.

IAM e Governança de Identidades; Zero Trust; Cloud Security Posture Management (CSPM); Cloud Native Application Protection Platform (CNAPP); Workload Protection; Network Security; Threat Modeling; Security by Design; Gestão de Vulnerabilidades.

Containers; Kubernetes; APIs; DNS; Balanceadores; WAF; API Gateway; Criptografia aplicada.

GitHub; GitHub Actions; Azure DevOps; Jenkins; Terraform; Infrastructure as Code.

Frameworks e Boas Práticas

CIS Benchmarks; NIST Cybersecurity Framework; MITRE ATT&CK; Cloud Security Alliance (CSA); OWASP Top 10; OWASP API Security Top 10.

Informações adicionaisExperiência no setor financeiro ou fintechs. Conhecimento em Open Finance. Experiência com PIX e meios de pagamento. Experiência com Akamai WAF ou soluções equivalentes. Experiência com Attack Surface Management. Conhecimento em Continuous Threat Exposure Management (CTEM). Vivência em ambientes de alta escala e alta disponibilidade. Experiência com plataformas de API Security. Conhecimento em segurança para Inteligência Artificial e LLMs. Experiência em projetos de transformação e migração para nuvem.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Gupy (Portal de Vagas)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Gupy (Portal de Vagas)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Gupy (Portal de Vagas)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.