Analista Pleno CloudSec
Accountabilities Cloud Identity and Access Management: Manage and govern AWS Identity and Access Management (IAM), including creating, reviewing, and maintaining roles, managed and inline policies, and permissions.
Security Governance: Implement and maintain the principle of least privilege, ensuring access rights are appropriately restricted and aligned with organizational security requirements.
Multi-Account Security Management: Configure and maintain security controls across AWS Organizations, Control Tower, and Landing Zone environments, including the implementation and management of Service Control Policies (SCPs).
Access Auditing and Remediation: Conduct regular audits of permissions and access configurations, identify excessive privileges, and implement corrective measures to reduce security exposure.
Security Monitoring and Incident Response: Monitor, investigate, and respond to security alerts and misconfigurations using AWS services such as GuardDuty, Security Hub, CloudTrail, AWS Config, and KMS.
Automation and Process Optimization: Develop scripts, preferably in Python, to automate IAM analysis, security remediation, access reviews, and governance workflows.
Cross-Functional Collaboration: Partner with engineering and infrastructure teams to define secure access policies and implement appropriate controls for new services, applications, and workloads.
Documentation and Standards: Maintain clear documentation of cloud security processes, policies, procedures, and governance guidelines.
Compliance and Auditing: Support internal and external audits and compliance initiatives related to LGPD, ISO 27001, PCI-DSS, CIS Benchmarks, and other relevant security frameworks.
Continuous Improvement: Stay informed about AWS security developments, emerging threats, and industry best practices, recommending improvements to strengthen cloud security and governance.
Requirements
Cloud Computing Experience: Previous hands-on experience with cloud computing environments, preferably AWS, including familiarity with cloud security principles and infrastructure management.
AWS IAM Expertise: Practical experience creating and managing IAM roles and policies, including managed and inline policies, applying Service Control Policies, and administering access across multi-account AWS environments.
Least-Privilege Implementation: Demonstrated understanding of access governance and the ability to apply least-privilege principles to reduce excessive permissions and strengthen security controls.
AWS Security Services: Solid knowledge of AWS IAM, CloudTrail, AWS Config, GuardDuty, Security Hub, and Key Management Service (KMS).
Education: Completed or ongoing bachelor's degree in Computer Science, Information Technology, or a related field.
AWS Certification: An AWS certification is required, such as AWS Certified Security – Specialty, AWS Certified Solutions Architect – Associate, AWS Certified Cloud Practitioner, or an equivalent credential.
Python and Scripting: Familiarity with Python for automating security and governance tasks is an advantage. Knowledge of Bash, Go, or other scripting languages is also desirable.
Infrastructure as Code: Experience with tools such as Terraform or AWS CloudFormation is a plus.
Security and Compliance Frameworks: Familiarity with security standards and regulatory frameworks, including CIS Benchmarks, NIST, ISO 27001, and LGPD, is desirable.
Cloud Security Tools: Experience with Cloud Security Posture Management (CSPM) tools is an advantage.
Multi-Cloud Experience: Exposure to Azure, Google Cloud Platform (GCP), or other cloud environments is beneficial.
Language Skills: Intermediate English proficiency is desirable.
Analytical and Problem-Solving Skills: Strong attention to detail and the ability to investigate security issues, identify root causes, and implement effective solutions.
Collaboration and Communication: Ability to work effectively with technical stakeholders, document security requirements clearly, and contribute to a culture of security awareness and continuous improvement.
Benefits
Performance-Based Compensation: Profit-sharing and results-based bonus program (PLR).
Food and Meal Allowances: Financial support for meals and everyday food expenses.
Healthcare Coverage: Medical and dental insurance plans.
Childcare Assistance: Financial assistance for daycare or babysitting expenses.
Transportation Support: Transportation allowance in accordance with applicable policies.
Wellness Programs: Access to Wellhub and TotalPass fitness and wellness programs.
Employee Assistance Program: Personal support resources through an Employee Assistance Program (EAP).
Financial Protection: Optional private pension and life insurance plans.
Pharmacy Discounts: Access to discounts on eligible pharmacy purchases.
Parental Support: Dedicated pregnancy support program.
Extended Parental Leave: Extended maternity and paternity leave under the Empresa Cidadã program.
Inclusive Workplace: A commitment to diversity, equity, and inclusion, with equal employment opportunities regardless of race, color, religion, gender identity, sexual orientation, nationality, disability, or age.
Professional Development: Opportunities to strengthen cloud security expertise and develop technical skills in a challenging financial technology environment.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1