Senior Security Engineer | CloudSec
Gympass (Wellhub) · Remoto
Your wellbeing, our mission. Join a company shaping a healthier world. GET TO KNOW US At Wellhub we're revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company. We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally. Join us in redefining the future of wellbeing! THE OPPORTUNITY We are hiring a Cloud Security Engineer for the InfoSec team in Brazil ! We are looking for an experienced security engineer to lead our cloud security strategy across multi-cloud environments (AWS & GCP). You will drive our Zero Trust architecture, embed a Shift-Left security culture within engineering teams, secure containerized and serverless workloads, and pioneer security controls for emerging Artificial Intelligence deployments—including Agentic AI systems, Model Context Protocol (MCP), Retrieval-Augmented Generation (RAG) architectures, AI guardrails, and mitigations against OWASP Top 10 for LLMs and MITRE ATLAS framework threats. This position is for the Cloud Security team. The Cloud Security Engineer is responsible for designing, implementing, and managing security measures in cloud computing environments to protect data, applications, infrastructure, and services against potential threats and vulnerabilities. YOUR IMPACT Architect and govern cloud security controls across AWS and GCP environments following Zero Trust principles; Embed automated security testing and threat modeling directly into CI/CD pipelines to champion a Shift-Left culture across development teams; Define and execute runtime security, posture management, and compliance for containerized (Kubernetes/EKS/GKE) and serverless architectures; Design and enforce security boundaries and guardrails for AI/LLM deployments, covering RAG architectures, Model Context Protocol (MCP), and Agentic AI workflows; Evaluate and mitigate risks aligned with the OWASP Top 10 for LLMs and the MITRE ATLAS framework for AI systems; You will help to keep our threat intelligence initiatives at a high level; You will be responsible for the security of the cloud platform, ensuring security controls provided by cloud service providers; You need to ensure controls are configured correctly and integrated into the security strategy; You will be responsible for identifying, analyzing and reporting vulnerabilities found in the ecosystem; You will also be responsible for configuring vulnerability management tools; Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life wellness. WHO YOU ARE Solid experience with multi-cloud architecture and security controls in both AWS and GCP; Proven experience implementing Zero Trust posture, least-privilege identity architecture, and micro-segmentation; Strong background in securing containerized environments (Kubernetes, Docker) and serverless technologies (AWS Lambda, Cloud Run, Cloud Functions); Demonstrated expertise in driving Shift-Left initiatives using SAST, DAST, SCA, and IaC security tooling integrated into DevSecOps pipelines; In-depth practical understanding of AI security risks, including OWASP Top 10 for LLMs, MITRE ATLAS framework, prompt injection defense, AI guardrails, Model Context Protocol (MCP) integrations, and securing RAG data pipelines and Agentic AI interactions. You have great communication skills, you are able to communicate with your teammates and stakeholders synchronously and asynchronously, and use English when needed. You know and worked with Identity Provider Platforms (IDPs) such as Azure AD, Keyclock, and Okta and with Cloud Security Posture Management (CSPM); You have a wide understanding of cybersecurity frameworks such as OWASP and Mitre’s ATT&CK.You got the ability to create scripts for automating security tasks. Familiarity with IT service management processes such as incident management and change management. You help your team to collaborate within and with other teams. We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don't match the job description 100%. We welcome your application and will be delighted to explore if you could be a great fit for our team. For this specific role, please note that prior experience in Cloud Security and Infrastructure are mandatory requirements. WHAT WE OFFER YOU With thoughtful benefits, emotional wellbeing resources, and a culture that empowers you to take ownership of your role and your wellbeing, we create an environment where you can thrive in all dimensions of your life. Our flexible benefits program allows you to customize some of the benefits, according to your needs! Our benefits include: WELLHUB: Free Gold+ membership with access to onsite gyms and studios, digital fitness programs, and online wellness resources for meditation, nutrition, mental wellbeing support, and more! Add up to three family members to your plan, ensuring access to wellness for those who matter most to you. WELLZ: A complete emotional wellbeing program with a unique approach. It offers personalized journeys that combine individual therapy sessions (52 per year) and on-demand content. HEALTHCARE: Health, dental, and life insurance. FLEXIBLE WORK: As a Flexible First company, we offer hybrid and remote options to