Senior Information Security Analyst - Cloud Security

Indeed

Company

Job typeFull-time
Workplace typeOnsite
Experience levelNo experience limit
Education levelNo degree limit

Description

Job Summary: We are seeking a Senior Cloud Security Analyst to lead the evolution of cloud security (AWS, Azure, and GCP), acting as the technical reference for defining secure standards and architecture, with a focus on Security by Design and Zero Trust. Key Highlights: 1. Lead the evolution of security in multi-cloud environments (AWS, Azure, GCP) 2. Serve as the technical reference for security standards and architecture 3. An autonomous environment with opportunities for professional growth At Banco ABC Brasil, we believe in the authenticity of each individual. After all, we have our own way of doing things, relating to others, transforming businesses, and building a sustainable future—in an inclusive, respectful, and welcoming manner. Because we genuinely care about people and build authentic relationships based on trust and closeness. If you are passionate about challenges and seek an environment where you can grow professionally—with autonomy to drive major projects and be the protagonist of your career—this is the place for you! With us, you’ll have daily opportunities to work alongside financial market specialists and receive guidance and support from strategic leaders to shape your future and contribute jointly to our growth. **We believe that caring for our employees is the key to success. Therefore, we offer:** * Benefits that truly make a difference * Development options * An inspiring environment **About the role:** We are looking for a Senior Cloud Security Analyst to lead the evolution of security across our cloud environments (AWS, Azure, and GCP), serving as the technical reference for defining standards, governance, hardening, and secure architecture. This person will be responsible for ensuring cloud environments align with security best practices, compliance, and resilience—from designing new architectures through implementing preventive and automated controls. We expect a hands-on professional with strategic vision and deep expertise in multi-cloud security, capable of collaborating closely with Infrastructure, DevOps, Engineering, and Information Security teams to continuously elevate organizational maturity. The primary objective of this position is to establish a robust Cloud Security architecture grounded in Security by Design and Zero Trust, implementing governance controls that reduce risk, standardize cloud platform usage, and ensure compliance with corporate policies and regulatory requirements. Are you ready to join a team that transforms challenges into opportunities? Join us! **Responsibilities and Duties** **Responsibilities and Duties** * Serve as the technical owner for AWS, Azure, and GCP environment security, ensuring continuous improvement of cloud security posture. * Define, implement, and maintain security standards (Security Baselines) for multi-cloud environments. * Design and implement secure architectures following Security by Design, Zero Trust, and Least Privilege principles. * Perform hardening of cloud services, ensuring adherence to vendor best practices and frameworks such as CIS Benchmarks, NIST, and Cloud Well-Architected Framework. * Implement and administer governance controls using capabilities such as AWS SCP (Service Control Policies), Azure Policy, Azure Management Groups, GCP Organization Policies, and other organizational control mechanisms. * Develop and maintain guardrails that ensure compliance and prevent insecure configurations in cloud environments. * Administer and evolve CSPM (Cloud Security Posture Management) solutions, conducting risk analysis, vulnerability prioritization, and remediation tracking. * Define IAM standards, implementing least-privilege policies, role segregation, identity federation, and secure privileged access management. * Implement controls related to data protection, encryption, key management (KMS), secrets management, and workload protection. * Support Infrastructure, DevOps, and Engineering teams in building secure cloud solutions. * Automate security controls using Infrastructure as Code (Terraform), scripts, and automation tools. * Integrate security controls into CI/CD pipelines, promoting DevSecOps practices. * Conduct technical security assessments, architectural reviews, and risk analyses for new cloud projects. * Continuously monitor cloud environment security posture, proposing improvements and evolution plans. * Collaborate with SOC and Incident Response teams in investigating and handling incidents involving cloud environments. * Develop metrics, dashboards, and executive reports on cloud environment maturity, compliance, and risk. * Promote Cloud Security best practices and guide technical teams on corporate standards. **Requirements and Qualifications** **Technical Requirements and Qualifications** * Solid Information Security experience with active involvement in cloud environments. * Advanced knowledge of at least two platforms among AWS, Azure, and GCP; experience across all three is preferred. * Experience implementing hardening for cloud services. * In-depth knowledge of IAM, RBAC, identity management, federation, and Least Privilege principles. * Experience implementing organizational controls such as: * AWS Organizations and Service Control Policies (SCP); * Azure Policy, Management Groups, and RBAC; * GCP Organization Policies and IAM. * Knowledge of cloud networking (VPC/VNET, Subnets, Security Groups, NSG, Firewall, VPN, Load Balancer, Private Endpoints, WAF). * Experience with CSPM tools such as Microsoft Defender for Cloud, AWS Security Hub, Prisma Cloud, Wiz, Lacework, Orca, or similar. * Knowledge of Infrastructure as Code (Terraform, CloudFormation, or Bicep). * Experience automating tasks using Python, PowerShell, or Shell Script. * Knowledge of DevSecOps practices and integrating security controls into CI/CD pipelines. * Knowledge of native cloud security services, including: * AWS GuardDuty, Security Hub, Config, IAM Access Analyzer, Inspector, and CloudTrail; * Microsoft Defender for Cloud, Microsoft Sentinel, and Azure Monitor; * GCP Security Command Center, Cloud Logging, Cloud Armor, and IAM. * Experience with security frameworks and standards such as CIS Benchmarks, NIST CSF, ISO 27001, MITRE ATT&CK, and Cloud Well-Architected Framework. * Knowledge of LGPD and cloud compliance best practices. **Skills** * Analytical mindset and problem-solving orientation. * Ability to define standards and technically influence diverse teams. * Strong communication skills for interaction with technical and business areas. * Architectural vision and focus on continuous improvement. * Collaborative and proactive attitude. **Education** * Bachelor’s degree in Information Technology, Information Security, Computer Science, Computer Engineering, or related fields. **Desirable Certifications** * AWS Certified Security – Specialty * AWS Solutions Architect Professional * Microsoft Certified: Azure Security Engineer Associate * Google Professional Cloud Security Engineer * CCSP * CISSP * CompTIA Security+ * Terraform Associate or Kubernetes (CKA/CKS) certifications will be considered advantageous. **Advantages** * Experience in large-scale multi-cloud environments. * Experience in regulated environments (LGPD, PCI-DSS, ISO 27001, SOC 2). * Knowledge of CNAPP, CWPP, and CIEM. * Experience with Kubernetes (EKS, AKS, GKE) and container security. * Knowledge of Cloudflare, WAF, API Security, and DDoS protection. * Experience with Security as Code, Policy as Code (OPA, Sentinel, or similar), and automated remediation. * Experience with observability tools, SIEM, and Detection Engineering. **Additional Information** * Health Insurance; * Dental Insurance; * Life Insurance; * Profit Sharing Program (PLR); * Performance Bonus (PPR); * Physical, social, and psychological well-being programs; * Meal Voucher; * Food Voucher; * Extended Paternity and Maternity Leave: 20 days paternity leave and 6 months maternity leave; * Childcare/Babysitter Assistance; * Annual Day Off; * Remote Work Allowance; * Remote Work Infrastructure Allowance; * TotalPass; We are ABC Brasil—the multi-bank with over 35 years of history, specializing in financial solutions and empowering major national businesses—combining international solidity with the agility of local, close, and autonomous management. With a comprehensive portfolio of products and services, our focus is on generating real impact for our customers, evolving with the market and adapting to each customer’s needs—always with responsibility, integrity, and mutual trust. This way of relating makes us unique. We believe authentic connections built on respect for differences foster a collaborative, human, and inspiring environment. Here, every person can be themselves—and grow with autonomy and protagonism. **ABC Brasil. The bank for those who are singular.** #EuSouSingular #SouABCBrasil #ABCBrasil

Some content was automatically translated

Posted by

João Silva

Indeed · HR

Location

Similar jobs

Senior Information Security Analyst - Cloud Security by Indeed in 2026 | ok.com