Description
On-site position in Florianópolis | 44 hours per week | Competitive salary
**Why join us?**
Dynamox is a high-tech company that develops intelligent vibration, temperature, current, and voltage monitoring solutions, helping maintenance and reliability teams make industry safer, more efficient, and more sustainable.
Today, we are the world’s only maintenance-focused company holding the international certifications ISO 27001, 27701, 27017, and 27018, in addition to ISO 9001.
Beyond well-structured processes, we believe in people. Here, you’ll find an organized, collaborative, and continuous-improvement-oriented environment where learning is encouraged and excellence is part of everyday life. We value those who strive to grow, innovate, and make a difference.
**About the role**:
We are seeking a professional responsible for integrating security across Dynamox’s entire software development lifecycle (SDLC). The focus is ensuring our applications and cloud infrastructure remain resilient, acting as a bridge between Development and SRE teams, automating security checks, and embedding a Security-by-Design culture.
**Key responsibilities**:
* **CI/CD Pipeline Security**: Implement and maintain security analysis tools (SAST, DAST, SCA) integrated into Bitbucket and GitHub workflows;
* **Secure Infrastructure-as-Code (IaC)**: Ensure Terraform-based resource provisioning follows security best practices, with emphasis on Kubernetes (GKE) environments and GCP services;
* **Identity and Secrets Management**: Administer and optimize secrets and permissions (IAM) across the cloud platform and applications, adhering to the principle of least privilege;
* **Monitoring and Response**: Collaborate with the observability team to identify anomalies and critical vulnerabilities using Grafana and Sentry;
* **Threat Modeling**: Support product teams in early identification of risks in new features and microservices architectures;
* **Offensive and Defensive Security**: Conduct vulnerability scans, attack surface analysis, and propose fixes for applications developed in Python, Node.js, and Shell;
* **Security Culture**: Promote secure development practices by educating technical teams about OWASP Top 10 risks and mitigations.
**Technical Requirements**:
* **Cloud Computing**: Solid experience with Google Cloud Platform (GCP);
* **Orchestration and Containers**: Proficiency in Kubernetes (K8s) and Docker;
* **Automation**: Experience using Terraform for infrastructure provisioning;
* **CI/CD**: Knowledge of automation pipelines, preferably Bitbucket Pipelines or GitHub Actions;
* **Development**: Ability to read and audit code in Python and Node.js, plus scripting automation in Shell;
* **Security Fundamentals**: Strong foundation in networking protocols, API (REST) security, and OWASP.
**Nice-to-Have (Desirable)**:
* Experience with monitoring and error-tracking tools (Grafana, Sentry);
* Certifications related to Cloud (e.g., GCP) or Security (e.g., Security+, Network+);
* Experience in microservices architecture and secure inter-service communication.
**Education**: Completed or ongoing undergraduate degree in Electronic Engineering, Mechanical Engineering, Computer Science, IT, or related fields.
**Benefits**:
* **Multi-benefit card**: Flexible card enabling use for meals/food, transportation, leisure, pharmacy, and more — you choose how and where to use it;
* **Health and dental plans**: Health and dental coverage for employees after the probation period;
* **SESI partnership**: Farmasesi and OdontoSesi;
* **Health and wellness**: GoGood and Wellhub partnerships (discounts at gyms and access to nutritionists, psychologists, and other health professionals);
* **Ergonomics support**: In-house physiotherapy/osteopathy services;
* **Professional development**: Financial support for courses, training programs, and certifications;
* **Partnerships**: EBAC and Influx;
* **Financial incentives**: Profit-sharing (PLR), performance bonuses, completion bonuses for training programs, and tenure bonuses;
* **Office comfort and food**: Complimentary fruits and coffee, plus access to Market4u and Dynamarket;
* **Culture and atmosphere**: Monthly social events and a relaxed, no-dress-code environment.