Faster chat, better deals — Get the App

Tech Lead - Information Security (Automation)

Indeed

Company

Job typeFull-time
Workplace typeHybrid
Experience levelMore than 10 years
Education levelNo degree limit

Description

**About Bradesco** Bradesco is one of Brazil's largest financial groups, with a history marked by pioneering spirit and innovation. Through our broadly diversified portfolio of financial products, banking services, and insurance offerings, we contribute to individuals’ aspirations and the sustainable growth of businesses and society. Join our financial ecosystem and impact the experience of millions of people! At Bradesco, we value diversity in all its forms. Therefore, our job openings are open to everyone, regardless of gender, race, sexual orientation, disability, age, or any other characteristic. Learn more at https://banco.bradesco/html/classic/sobre/index.shtm **Responsibilities and Duties** What is our Cyber Security team? We are dedicated to protecting assets, information, and our employees. We proactively identify and mitigate risks, respond rapidly to incidents, and foster a culture of security across the entire organization. Our commitment is to the integrity, confidentiality, and availability of corporate resources, ensuring business continuity and customer trust. Work model: Hybrid — 3 days onsite Unit: Osasco — SP **Your Day-to-Day Responsibilities** As a Cyber Security Specialist I, you will work within the Information Protection Management unit, with the following primary responsibilities: * Lead the architecture, standards, and technical quality of automation and AI-powered security products/platforms in mission-critical multi-cloud environments; * Design and implement secure-by-default security and IaC pipelines (Terraform, CloudFormation/Pulumi), GitOps, policy-as-code, and preventive/detective controls; * Build security integrations via APIs (SIEM, SOAR, CSPM/CNAPP, EDR/XDR, WAF, ITSM) and orchestrated workflows (n8n/Airflow) with automated response; * Design secure AI architectures for SOC/Blue/Purple use cases (RAG, agents/autonomous agents), incorporating guardrails, observability, isolation, MCP, and data governance; * Implement LLM Security by design: mitigation of prompt injection, content validation/filtering, protection against data leakage, context control, and capability limitation; * Define standards for Kubernetes/Container Security (admission, runtime, image signing, supply chain), API Security, WAF/DDoS, encryption, KMS, and secrets management; * Code libraries and automations (Python/PowerShell/Bash), conduct code reviews, perform security testing, define SRE/SLOs, and harden pipelines and runtimes; * Collaborate with Product Managers on technical feasibility, estimations, trade-offs, and roadmaps; contribute to RFPs and vendor validations. **Requirements and Qualifications** What do you need to have or know? * Advanced Cloud Security (AWS/Azure/GCP): IAM, networking, KMS/encryption, logging/auditing, native detection; CSPM/CNAPP, CWPP, CIEM; * Automation & DevSecOps: Terraform/Pulumi/CloudFormation; CI/CD Security (GitHub Actions, GitLab CI, Jenkins); n8n/Airflow; policy-as-code (OPA/Conftest), secret management (e.g., Vault), GitOps (ArgoCD/Flux); * Platforms & Applications: Kubernetes (RBAC, PSP/Pod Security, admission controllers), container runtime, supply chain (SBOM, signatures), API Security (OAuth2/OIDC, mTLS); * AI Applied to Security: Agentic AI, MCP, RAG (vectorization, context controls), LLM Security (prompt injection, jailbreaks, model/data poisoning), MLOps Security (experiment governance, tracking, approval/rollback); * Detection & Response: SIEM/SOAR/EDR/XDR integrations, event normalization, response playbooks, containment automations, Purple Team exercises to validate controls; * Cryptography and Identity: PKI, TLS/mTLS, HSM/KMS, key/secret rotation; Zero Trust, IAM/PAM, segmentation; * Compliance and Frameworks: NIST CSF, CIS, ISO 27001/27017/27018, BACEN, PCI-DSS, SOX, LGPD — translating requirements into technical controls and tests. It will be a differentiator if you have: * Cloud & Advanced Security: AWS Certified Security – Specialty, Azure Security Engineer Associate or SC-200/SC-300/SC-100, Google Professional Cloud Security Engineer, CCSP, CISSP; * Automation & Cloud-Native: GIAC GCSA (Cloud Security Automation), CKS/CKA, HashiCorp Terraform Associate; * Operations/Incident Response (desirable): GIAC GCIA/GCIH/GMON (or equivalents); * AI/ML (desirable): Azure AI Engineer Associate (AI-102), Google Professional Machine Learning Engineer, courses on NIST AI RMF and LLM Security. **What We Offer** At Bradesco, we value health and well-being, offering an extensive portfolio of benefits to all our employees: * PLR or Bonus: Based on position eligibility* * Health Insurance * Dental Insurance * Life Insurance * Food Allowance * Meal Voucher * 13th Food Basket * Total Pass * Commuter Benefit (optional enrollment) * Discounts on products and services from partner companies * Private Pension Plan (optional enrollment, with financial contribution from Bradesco Organization) * Viva Bem Bradesco: health, well-being, and quality-of-life program * Unibrad: Bradesco Corporate University * Fee Waivers: special conditions on various products and services * Childcare or Babysitting Assistance * Extended Paternity Leave of 20 days * Maternity Leave of 180 days, including assisted prenatal and postpartum care

Some content was automatically translated

Posted by

João Silva

Indeed · HR

Location

João Silva

Indeed · HR

Similar jobs

Tech Lead - Information Security (Automation) job by Indeed in 2026 | ok.com