O SEU PRÓXIMO CAPÍTULO
Cloud Security Engineer
Sobre a vaga
• Own the full lifecycle of security findings and recommendations through triage, remediation, verification, and closure
• Root-cause recurring issues and implement systemic fixes using policy-as-code, automated guardrails, and secure baselines
• Track remediation SLAs and report on risk reduction and posture trends
• Secure and govern authentication flows including OIDC, OAuth 2.0 with PKCE, JWT, and mTLS
• Administer and harden Microsoft Entra ID, including app registrations, Enterprise Application permissions, consent governance, service principals, managed identities, credential hygiene, and least-privilege scoping
• Design, implement, and tune Conditional Access policies
• Build and enforce Azure Policy and Terraform guardrails
• Maintain secure-by-default infrastructure-as-code baselines and detect/remediate configuration drift
• Operate Microsoft Defender for Cloud, improve secure score, remediate recommendations, and manage CSPM
• Contribute to security governance, standards, control definitions, exception handling, and audit evidence
• Secure cloud and SaaS administrative portals
• Strengthen privileged access with MFA, PIM/just-in-time elevation, role minimization, and break-glass procedures
• Apply security controls to AI workloads, services, and agents, including identity, permission scoping, data-exposure, and prompt-injection risks
• 5+ years in cloud security or security engineering, with deep, hands-on Azure experience
• Strong, hands-on Microsoft Entra ID expertise: app registrations, Enterprise Apps, permissions and consent, and Conditional Access
• Solid working knowledge of modern authentication: OIDC, OAuth 2.0 / PKCE, JWT, and mTLS
• Proficiency with Terraform and Azure Policy for policy-as-code and automated guardrails
• Experience with Microsoft Defender for Cloud and cloud security posture management
• A demonstrable track record of root-causing and permanently closing security findings—not just patching them
• Working understanding of AI, AI agents, and AI security considerations
• Advanced English
• Nice to have: Multi-cloud exposure (AWS, GCP)
• Nice to have: Relevant certifications (e.g., Microsoft SC-100, AZ-500, SC-300; CISSP)
• Nice to have: Experience with CI/CD pipeline security, secrets management, and SIEM/SOAR
• Nice to have: Scripting/automation (PowerShell, Python)
• Nice to have: Hands-on experience securing LLM-based or agentic systems in production