Staff Cloud Security Engineer

iFood

Completely RemoteFull TimeInformation Technology
Posted Today

Job description

About the Company

Transform your career with iFood! We are a Brazilian technology company and a reference in Latin America. Through innovative solutions, we connect thousands of restaurants to millions of consumers daily with an average of 100 million monthly orders. Beyond food delivery, we also operate in Market, Pharmacy, and Pet sectors. We also have iFood Pago, our Fintech, which includes iFood Benefits and iFood Pago, the restaurant's bank.

Responsibilities

  • Lead the design and evolution of AWS-first security architectures in a large-scale technological ecosystem.
  • Act as the main technical reference in Cloud Security, partnering with Cloud Platform, SRE, Engineering, Product, Privacy, Compliance, and Architecture teams.
  • Define and maintain reference architectures, paved roads, reusable patterns, and automated controls for AWS environments.
  • Lead architecture reviews and threat modeling for critical cloud-native products, APIs, data pipelines, and Kubernetes workloads.
  • Responsible for the evolution of identity, access, Kubernetes, containers, and network standards.
  • Strengthen cloud detection and response by defining telemetry standards, detection use cases, and automated containment flows.
  • Build and scale security automations through infrastructure as code, policy as code, and secure Terraform modules.
  • Mentor engineers, security specialists, and Security Champions.

Requirements

  • Expert knowledge in AWS security architecture (IAM, Organizations, SCPs, GuardDuty, Security Hub, KMS, etc.).
  • Deep experience with IAM, including least privilege, federated access, and workload identity.
  • Advanced experience in Kubernetes and container security (EKS, ECR, Helm, RBAC, OPA/Gatekeeper).
  • Advanced knowledge of cloud network security (VPC, routing, segmentation, WAF, DDoS protection).
  • Solid experience with threat modeling, CNAPP/CSPM, Terraform, CI/CD, Python, Go, and Bash.
  • Ability to lead technical discussions and influence without formal authority.

Preferred Qualifications

  • Experience designing cross-functional security strategies and posture automation.
  • Experience with multi-cloud environments (AWS and GCP).
  • Experience with AI/ML security integrations and abuse scenario evaluation.
  • Knowledge of ransomware, disaster recovery, and immutable backups.
  • Experience with Zero Trust and shift-left security models.

Skills & tools

AWSKubernetesTerraform

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 01Expert AWS security architecture knowledge
  2. 02Deep IAM experience
  3. 03Advanced Kubernetes and container security
  4. 04Cloud network security expertise
  5. 05Proficiency in Terraform, Python, or Go
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches