Professional focused on Cloud Security solutions and DevSecOps at innovative tech consulting firm Leega. Implementing security for AWS services and integrating security analysis tools.
Responsibilities
Develop and implement AuthN/AuthZ mechanisms for APIs, microservices, and enterprise integrations using mTLS and OAuth2
Design and implement security solutions integrated with the cloud and DevOps pipelines
Automate deployment of security resources and solutions using Infrastructure as Code (IaC) — Terraform and GitHub Actions
Apply and automate hardening for EKS, Istio, Lambda, and infrastructure provisioned via Terraform
Implement security policies and encryption controls for S3, DynamoDB, and other AWS services
Manage digital certificates via ACM and secrets via Secrets Manager
Support development teams in adopting secure patterns and remediating vulnerabilities
Automate security validations and drive continuous improvement
Document technical standards and security best practices
Requirements
Strong experience in AWS Cloud Security, including IAM (RBAC/ABAC), KMS, Secrets Manager, Certificate Manager (ACM), CloudTrail, GuardDuty, WAF, Macie, and Security Hub
Experience developing and implementing security solutions, including building reusable components, automating controls, and securing integrations between systems
Hands-on experience with DevSecOps, integrating SAST, DAST, SCA, IAST, and IaC security into CI/CD pipelines (GitHub Actions)
Knowledge of Authentication and Authorization (AuthN/AuthZ) for APIs and enterprise integrations, using OAuth2, OpenID Connect, JWT, JWE, and mTLS
Experience securing APIs and microservices
Experience with AWS services: API Gateway, Cognito, Lambda, DynamoDB, S3, and Load Balancers (ALB/NLB)
Knowledge of Kubernetes (EKS) and Istio, including mTLS between services, network policies, access control, and workload hardening
Experience with Infrastructure as Code (Terraform), applying policy-as-code, automated validation, and secure configurations
Strong knowledge of cryptography, digital certificates (PKI), TLS/mTLS, and protection of data in transit and at rest
Experience with SDLC/SSDLC and secure development practices
Intermediate/advanced English and Spanish
AWS or security certifications (AWS Security Specialty, Solutions Architect, DevOps Engineer, Security+, or similar) — desirable
Experience with Threat Modeling and MITRE ATT&CK — desirable
Development of internal security frameworks or libraries — desirable
Use of AI applied to security automation and analysis — desirable
Experience in regulated environments (financial sector) — desirable
Benefits
Porto Seguro medical insurance
Porto Seguro dental insurance
Profit Sharing (PLR)
Childcare assistance
Alelo meal and food vouchers
Home office allowance
Partnerships with educational institutions
Support for certifications, including cloud certifications
Enterprise Services Manager leading the Technical Account Management team at Proofpoint. Responsible for maximizing customer value of products and services while ensuring high customer satisfaction.
Information Systems Security Engineer providing technical solutions and support for Department of Defense systems. Leveraging industry knowledge to increase operational efficiencies focusing on classified data systems.
Network Security Architect at Dell influencing security culture and designing secure network environments. Collaborating across teams and developing strategies for modern network security.
Senior Enterprise Security Engineer performing security assessments and threat modeling for Salesforce systems. Collaborating with teams and defining security standards across diverse technology environments.
Fullstack Software Engineer focusing on security to ensure resilience and data protection at health tech company Alan. Involved in building foundational security and authentication systems.
Security Engineer building trust foundations for bare - metal platforms at OpenAI. Designing and operating core security infrastructure for reliable compute platforms across global infrastructure.
Cybersecurity Consultant involved in deploying security tools and supporting compliance projects in Andorra. Working with cross - functional teams to enhance cybersecurity measures and documentation.
Microsoft Success Manager helping partners grow secure, scalable Microsoft practices across ANZ. Championing Microsoft security solutions and supporting partner success strategies in the region.
Assistant AVP overseeing a 5 - member team for Access Management services in Pune and Mumbai, ensuring high standards of service delivery and compliance.
Own global security systems infrastructure for QVC, managing access control and networked security systems across multiple regions. Collaborate with IT to ensure security and technology initiatives meet organizational needs.