Description
Job Summary:
We are seeking an Information Security professional to enhance M7's security architecture, with a focus on cloud-native environments, DevSecOps, and Application Security.
Key Highlights:
1. Experience working in cloud-native, DevSecOps, and Application Security environments
2. Leading API security architecture aligned with the OWASP API Top 10
3. Building DevSecOps paved roads to accelerate squad delivery
We seek an Information Security professional with strong expertise in cloud-native, DevSecOps, and Application Security environments to support the evolution of **M7's** security architecture.
**What We Expect / Are Looking For:**
* Practical experience in application security, with at least 3 years in production cloud-native environments
* Hands-on experience with multi-account cloud architectures (Organizations, Control Tower, IAM Identity Center)
* Terraform in production — writing and reviewing modules, not just conceptual knowledge
* Integrating security into CI/CD pipelines with automated gates
* Proficiency in Application Security and API Security (OWASP, threat modeling)
* Modern identity: OAuth 2.0, OIDC, SAML, applied Zero Trust
* LGPD applied to digital systems (privacy by design, consent, data subject rights)
**Key Responsibilities:**
* Designing and operating M7's **multi-account Cloud landing zone**, with guardrails codified in Terraform and consumed by product squads
* Integrating security into CI/CD pipelines: SAST, DAST, SCA, IaC scanning, container scanning, and supply chain security (SBOM, artifact signing)
* Building **DevSecOps paved roads** that accelerate squad delivery without compromising security posture
* Leading **API security architecture** aligned with the OWASP API Top 10 and Open Finance/Open Insurance Brazil standards (FAPI, mTLS, consent management)
* Establishing governance for **AI/LLM application security** — prompt injection controls, PII protection in RAG, secure model registry — for Credit and Investment AI projects
* Operationalizing **compliance as code** for CVM, SUSEP, BCB, ANPD, and LGPD, with automated evidence
Acting as the senior technical interface with our MSSP partner for incident detection and response