iFood

Staff Cloud Security Engineer

iFood
Apply
1 month ago
Remote, BrazilStaff+

Responsibilities

  • Lead the design and evolution of AWS-first cloud security architectures for platforms, workloads, Kubernetes environments, data flows, and critical services.
  • Act as the primary technical reference for Cloud Security and collaborate with Cloud Platform, SRE, Engineering, Product, Privacy, Compliance, Detection and Response, and Architecture teams.
  • Define reference architectures, paved roads, reusable standards, automated controls, multicloud strategy, IAM, network segmentation, data protection, logging, threat detection, incident readiness, and secure deployment patterns.
  • Lead architecture reviews and threat modeling for cloud-native products, APIs, data pipelines, Kubernetes workloads, event-driven architectures, and AI/ML integrations.
  • Develop standards for least privilege, temporary credentials, Just-in-Time access, workload identity, SCPs, RBAC, admission control, policy as code, secrets management, runtime detection, WAF, DDoS protection, service-to-service security, and blast-radius reduction.
  • Strengthen cloud detection and response through telemetry standards, detection use cases, runbooks, automated containment, and SIEM/SOAR, CNAPP, CSPM, CI/CD, and AWS-native integrations.
  • Build and scale security automation using infrastructure as code, policy as code, detection as code, secure Terraform modules, CI/CD guardrails, event-driven remediation, and self-service mechanisms.
  • Mentor engineers, security specialists, Platform teams, and Security Champions in secure architecture, AWS Security, Kubernetes Security, automation, threat modeling, and post-incident learning.

Requirements

  • Expert-level knowledge of AWS security architecture, including AWS Organizations, IAM Identity Center, SCPs, permission boundaries, IAM Access Analyzer, Landing Zones, CloudTrail, GuardDuty, Security Hub, Config, Inspector, Macie, KMS, Secrets Manager, WAF, Shield, CloudFront, Route 53, VPC, Transit Gateway, PrivateLink, EventBridge, Security Lake, and centralized logging.
  • Deep experience with IAM, including least privilege, federated access, temporary credentials, JIT/JEA, workload identity, privileged-access governance, access reviews, policy design, and remediation of overprivileged roles.
  • Advanced experience securing Kubernetes and containers, especially AWS/EKS, including EKS, ECR, Helm, IRSA or pod identity, RBAC, admission controllers, OPA/Gatekeeper, Kyverno, network policies, secrets management, image scanning, runtime security, and workload isolation.
  • Advanced knowledge of cloud network security, including VPC design, routing, segmentation, ingress and egress controls, security groups, NACLs, DNS, TLS/mTLS, WAF, DDoS protection, CloudFront, service mesh, API gateways, packet analysis, logging, and lateral-movement reduction.
  • Solid experience with secure architecture, threat modeling, cloud detection and response, data protection, vulnerability management, CNAPP/CSPM, policy as code, detection as code, Terraform, CI/CD, Python, Go, Bash, and reusable security automation.
  • Ability to lead technical discussions, influence without formal authority, communicate risks clearly, build consensus across teams, and balance security depth with business speed.
  • Experience designing cross-functional security strategies and automating security posture management across multiple teams.
  • Experience with AWS and GCP or other multicloud environments.
  • Experience securing AI/ML integrations and evaluating AI-related abuse scenarios.
  • Knowledge of ransomware, disaster recovery, immutable backups, Data Bunker architectures, Zero Trust, shift-left security, build-versus-buy decisions, and technical roadmap definition.

Tech Stack

Categories

iFood

About iFood

5,001-10,000 employees

We are a Brazilian tech ecosystem that goes beyond delivery, with 7,000 people shaping the future of convenience by testing, learning, and evolving fast. Unlock more: www.news.ifood.com.br

Contact me