Security Engineer

Há 7 dias


Brasil Avenue Code Tempo inteiro

About The Opportunity

We are seeking a

About The Opportunity

We are seeking a Security Engineer - DevSecOps contractor to support our Product Development teams by maintaining robust security practices and ensuring SOC 2 compliance. This role is key to improving operational efficiency by proactively addressing vulnerabilities, managing infrastructure maintenance, and enhancing internal processes. You will collaborate closely with Engineering, Platform, and InfoSec teams to monitor systems, manage vulnerabilities, maintain infrastructure, and contribute to automation efforts through infrastructure-as-code.

Responsibilities

  • Partner with InfoSec, Platform, and Engineering teams to ensure a strategic security vision is embedded into products and codebases.
  • Vulnerability Management: Triage and review vulnerability and penetration test reports (Tenable, Dependabot, AWS tools). Identify false positives, prioritize issues, and create actionable Jira tickets. Ensure timely remediation in line with SLAs and SOC 2 requirements. Implement code changes when needed to address vulnerabilities.
  • Security Monitoring & Alerting: Maintain and improve AWS alerting pipelines (GuardDuty, Inspector, Config). Monitor, route, and resolve alerts in collaboration with Engineering teams. Enhance observability and logging infrastructure.
  • Software & Infrastructure Maintenance: Perform monthly patching and upgrades for AWS Lambda runtimes, ECS services, VMs, and containers. Coordinate and execute annual backup restoration tests. Manage Dependabot alerts and CVE-driven updates.
  • Infrastructure-as-Code: Maintain and enhance Terraform modules related to security and compliance.

Required Qualifications
  • 3+ years of experience in DevSecOps, infrastructure security, or similar roles.
  • Strong understanding of AWS services (Lambda, ECS, EC2).
  • Hands-on experience with Terraform for infrastructure-as-code.
  • Skilled in vulnerability triage, patch cycle management, and interpreting scan reports.
  • Able to work independently and own recurring operational responsibilities.
  • Comfortable in an agile product development environment.
  • Experience with Go, Bash, and/or JavaScript/TypeScript for code reviews and patching.

Nice To Have Skills
  • Familiarity with SOC 2 compliance and related operational practices.
  • Experience with security tools such as Tenable, AWS GuardDuty, Inspector, and AWS Config.
  • Knowledge of CI/CD tools (e.g., GitHub Actions).
  • Exposure to project tracking tools like Jira.
  • Security certifications (CISSP, CSSLP, CEH, AWS Certified Security Engineer, GCP Professional Cloud Security Engineer).
  • Deep understanding of application and cloud security, emerging threats, vulnerabilities, and best practices.
  • Strong grasp of web application security principles, OWASP Top 10, and secure coding practices.
Seniority level
  • Seniority levelMid-Senior level
Employment type
  • Employment typeFull-time
Job function
  • Job functionInformation Technology
  • IndustriesIT Services and IT Consulting

Referrals increase your chances of interviewing at Avenue Code by 2x

Sign in to set job alerts for "Security Engineer" roles.(Security) Sr Security Engineer - AppSecSoftware Engineer Pleno (Node - Marketplace)(Security) Security Engineer Senior - PerimetroSenior Security Governance and Risk ConsultantSenior Software Engineer - Authentication ( Java / C#)Security Engineer - Remote Work | REF#

We're unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

#J-18808-Ljbffr
  • Cloud Security Engineer

    4 semanas atrás


    Brasil WRS Health Tempo inteiro

    Join to apply for the Cloud Security Engineer role at WRS Health1 day ago Be among the first 25 applicantsJoin to apply for the Cloud Security Engineer role at WRS HealthVoted #1 EHR by PC Mag, WRS Health delivers a fully integrated cloud based EMR and practice management solutions to its clients. We bring solutions to physicians by providing constant...

  • Security Engineer

    3 semanas atrás


    Brasil VTEX Tempo inteiro

    Join to apply for the Security Engineer role at VTEX.About The RoleWe are seeking talented security engineers interested in a career in a defensive area. You will be responsible for building, evolving, and maintaining software to grow our cyber security vision in the company environment. Some of our tools include EDR (Endpoint Detection and Response), XDR...


  • Brasil beBeeSoftware Tempo inteiro R$180.000 - R$200.000

    We're looking for a skilled Software Engineer to join our team. This is an exciting opportunity to work on cloud security blueprints for the Google Cloud Platform, implementing security best practices used by top companies worldwide.A software engineer in this role will contribute to developing deployable and reusable modules and policies that implement and...

  • Sales Engineer

    Há 4 dias


    Brasil Upwind Security Tempo inteiro

    Upwind is a next-generation Cloud Security Platform that leverages runtime context to identify and prioritize critical risks, providing precise insights and efficient cloud security management. Upwind uses runtime data proactively for risk prioritization and posture insights, ensuring teams focus on what truly matters. With industry-leading efficiency and...


  • Brasil beBeeSolution Tempo inteiro US$80.000 - US$120.000

    Cloud Security Engineer Job OverviewThis is a field sales engineering role open to qualified candidates within Brazil.The successful candidate will have the opportunity to work with our team of expert sellers, building meaningful relationships with customers and focusing on their value.Develop a deep understanding of cloud security products and...

  • Security Engineer

    4 semanas atrás


    Brasil VTEX Tempo inteiro

    We are seeking talented security engineers interested in a career in a defensive area. You will be responsible for building, evolving, and maintaining software to grow our cyber security vision in the company environment. Some of our tools are EDR (Endpoint detection and response), XDR (Extended detection and response), logging tools, Threat intel,...

  • SQL Database Engineer Job

    4 semanas atrás


    Brasil Software Engineer Tempo inteiro

    About the Role:We are looking for a SQL Developer to implement, design, maintain, secure, and perform critical financial databases to ensure availability and consistent performance of database platforms.This is an excellent opportunity to be one of the key members of our Engineering team and position yourself for unique career growth opportunities.What...

  • Security Engineer

    Há 3 dias


    Brasil Varsity Tutors, a Nerdy Company Tempo inteiro

    Overview You are an AI-powered Security Engineer responsible for identifying and responding to malicious or suspicious activity across our environment with speed and confidence. This role leads the engineering work behind these capabilities—designing scalable systems to detect threats and trigger automated responses. You will integrate AI into detection...


  • Brasil Netskope Tempo inteiro

    Sr. Staff Data Engineer, Data Security (DLP)Join to apply for the Sr. Staff Data Engineer, Data Security (DLP) role at NetskopeSr. Staff Data Engineer, Data Security (DLP)2 days ago Be among the first 25 applicantsJoin to apply for the Sr. Staff Data Engineer, Data Security (DLP) role at NetskopeGet AI-powered advice on this job and more exclusive...


  • Brasil e-Core Tempo inteiro

    Be yourself, be your bestCombinamos nossa experiência global em indústrias-chave e as últimas tecnologias para ajudar empresas em rápido crescimento e estabelecidas a transformar e acelerar seus modelos de negócios, desenvolver soluções digitais inovadoras, escalar capacidades tecnológicas e sustentar seu crescimento.Conheça a área de Consultoria e...