- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- hace 7 horas
- Work mode
- In office
- Education
- Bachelor's degree in Computer Science or related fields
- Resume
- Required to apply
Where you'll work
Job description
About the Company
Our client is a software development and digital solutions provider catering to clients in the FinTech, Gaming, and Marketing areas. They have delivered more than 20 innovative products across five international markets, including Brazil, Armenia, Saudi Arabia, and the UAE.
Job Overview
As the company expands its platform presence across these regions, they seek a Security Engineer to integrate security into the software development life cycle (SDLC), protect their cloud-native infrastructure, and assist engineering teams in deploying resilient, compliant, and sustainable applications.
Key Responsibilities
- Incorporate security practices into the SDLC starting from design through deployment, performing threat modeling and risk assessments prior to code release.
- Automate security testing mechanisms within the pipeline, utilizing SAST, DAST, SCA, and Infrastructure as Code (IaC) scanning to identify vulnerabilities early.
- Secure Kubernetes and Docker environments by implementing Role-Based Access Control (RBAC), network policies, and enforcing least-privilege access.
- Develop and maintain security controls within CI/CD pipelines including Jenkins, GitLab CI, GitHub, Azure DevOps, and Bitbucket.
- Protect cloud workloads spanning Azure, AWS, and Google Cloud Platform (GCP) by improving IAM, Multi-Factor Authentication (MFA), and RBAC configurations.
- Analyze security alerts, perform root cause investigations, and support comprehensive incident response.
- Collaborate closely with engineering, DevOps, and quality assurance teams to remediate vulnerabilities and build secure-by-default systems.
- Enhance software supply chain security by managing Software Bill of Materials (SBOMs), dependency scanning, and secret detection.
- Assist in audits and maintain compliance with standards such as ISO 27001, NIST Cybersecurity Framework, and CIS Benchmarks.
- Conduct secure coding workshops and promote security awareness training among development teams.
Required Qualifications and Experience
- Bachelor's degree in Computer Science, Information Security, Engineering, or a closely related discipline.
- A minimum of 5 years' experience in Application Security, Security Engineering, DevSecOps, or Cloud Security roles.
- Proven experience securing web applications, REST APIs, containerized environments, and cloud-native services.
- Hands-on expertise with Kubernetes, Docker, and at least one of the major cloud platforms (Azure, AWS, or GCP).
- Proficiency using SAST, DAST, SCA, and IaC scanning tools within vulnerability management programs.
- Experienced in integrating security into CI/CD workflows with tools like Jenkins, GitLab CI, GitHub Actions, Bitbucket Pipelines, or Azure DevOps.
- Strong understanding of secure development lifecycle principles and threat modeling methodologies.
- Familiarity with security tools such as SonarQube, Trivy, OWASP ZAP, Burp Suite, Nessus, Microsoft Defender, and Wazuh.
- Working knowledge of scripting languages like Python or Bash for automating security tasks.
Benefits and Perks
- Provision of flight ticket and full working visa sponsorship.
- Comprehensive support with visa and work permit documentation processes.
- High-quality equipment including a MacBook and iPhone supplied to employees.
- Competitive salary commensurate with skills and experience.
- Generous leave packages and a supportive work environment.
- A vibrant, inclusive culture focused on employee development and growth.
Recruitment Process
- Initial interview with Human Resources.
- Technical evaluation consisting of a take-home assignment plus two in-depth technical interviews.
- Background verification and checks.
- Final job offer upon successful completion of all stages.