Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Riachuelo

Senior Information Security Analyst, Cloud Security

Riachuelo

Analista Segurança Informação I Cloud Security ensuring security posture in AWS and Azure environments. Leading incident detection and response while collaborating with architecture teams.

Posted 7/30/2026full-timeSão Paulo • 🇧🇷 BrazilSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Cloud Incident Detection and Response, focusing on AWS and Azure environments, with a strong emphasis on security controls, vulnerability management, and integration of cloud logs into SIEM systems. Proficient in developing security practices using Infrastructure as Code (IaC) and ensuring compliance in regulated environments.

Highest-signal resume keywords
Cloud Incident Detection And ResponseAWS Security Services (S3, Redshift, Glue, Lambda)IaC With Terraform Or CloudFormationIntegration Of Cloud Logs With SIEM (Splunk)Container And Kubernetes Security

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Cloud Security ControlsVulnerability ManagementSecurity HardeningCSPM/CWPPCloud Network SecurityDetection EngineeringTechnical Report WritingRisk AnalysisCompliance ManagementIncident Response
Soft Skills
CollaborationCommunicationProblem-SolvingTechnical Training
Tools & Technologies
AWSAzureSplunkTerraformCloudFormationCloudTrailGuardDutyAzure SentinelDefender For CloudKubernetes
Industry Keywords
Information SecurityRegulated EnvironmentsMulti-Cloud EnvironmentsDevSecOpsMITRE ATT&CK For Cloud

Tech Stack

Tools & technologies
Amazon RedshiftAWSAzureCloudKubernetesSplunkTerraform

About the role

Key responsibilities & impact
  • Lead the Cloud (AWS/Azure) Incident Detection and Response practice for the company, ensuring continuous visibility into the security posture of the environments
  • Develop and maintain security controls in AWS and Azure environments, building baselines for cloud resources and compute functionalities (compute, storage, networking, containers, managed services)
  • Monitor and improve the security posture of AWS data and infrastructure services such as S3, Redshift, Glue, Lambda, Step Functions, VPC and CloudWatch, identifying exposure risks, misconfigurations and misuse
  • Protect cloud workloads, infrastructure and networks, covering containers/Kubernetes, VPC/VNet, segmentation and east‑west traffic
  • Contribute to architecture decisions from a security perspective, including solution design, integration patterns and secure environment organization, in collaboration with Architecture and Engineering teams
  • Develop and maintain security practices in IaC (Terraform or CloudFormation), including template scanning and compliance-as-code policies
  • Perform hardening, vulnerability management and continuous security reviews of cloud environments
  • Develop and operate cloud-specific detection cases (detection engineering), covering anomalous behaviors, insecure configurations and known exploitation techniques
  • Integrate logs and telemetry from cloud services (CloudTrail, Azure Activity Log, GuardDuty, Defender for Cloud, CloudWatch, etc.) into Splunk, ensuring end-to-end detection coverage
  • Participate in risk analyses, troubleshooting and incident response, conducting root cause analysis and containment with integrated work alongside CSIRT/SOC
  • Translate technical findings into clear, actionable business risks, prioritizing remediation by criticality and actual exposure
  • Produce technical and executive reports on security posture, detection gaps and the effectiveness of cloud controls
  • Support governance, compliance and corporate security initiatives for Cloud Services, contributing to the maturity of the program
  • Assist in monitoring, documenting and organizing cloud resources from a security perspective, keeping inventory and posture up to date
  • Work collaboratively with Infrastructure, Cloud, DevOps and Security teams on configuration and implementation of secure solutions
  • Operate in regulated and high‑criticality environments, aligned with industry requirements
  • Participate in training and technical development programs related to cloud technologies and security
  • Contribute to the evolution of the company’s cloud security program, including detection and response automations (SOAR)

Requirements

What you’ll need
  • Bachelor’s degree in Information Security, Computer Science, Engineering, Information Systems or related fields
  • Minimum 5 to 7 years of experience in Information Security, with at least 3 years focused on security, detection or incident response in cloud environments (AWS and/or Azure)
  • Experience in complex, regulated and/or high‑criticality, distributed and/or multi‑cloud environments (retail is a plus)
  • Advanced English for technical reading and interaction with international documentation/forums
  • Cloud incident detection and response (AWS CloudTrail/GuardDuty, Azure Sentinel/Defender for Cloud, or equivalents)
  • Definition and implementation of baselines and security controls for cloud services and resources (compute, storage, networking, containers, managed services)
  • Security of AWS data and infrastructure services (S3, Redshift, Glue, Lambda, Step Functions, VPC, CloudWatch)
  • Hardening and vulnerability management in cloud environments
  • CSPM/CWPP: identification and remediation of misconfigurations and continuous hardening
  • Container and Kubernetes security
  • Cloud network security: VPC/VNet design, segmentation, Transit Gateway/PrivateLink, microsegmentation (e.g., Guardicore)
  • IaC with Terraform or CloudFormation, including security scanning of templates
  • Integration of cloud logs with SIEM (Splunk) and writing detections (SPL)
  • DevSecOps: security in Azure DevOps/GitHub pipelines
  • MITRE ATT&CK for Cloud as a reference for modeling detections

Benefits

Comp & perks
  • Health insurance
  • Dental care
  • Meal or food voucher
  • Telemedicine
  • Gympass
  • Sesc partnership
  • Profit Sharing (PLR)
  • Private pension
  • Group life insurance
  • Pharmacy partnership
  • Educational partnerships
  • Online learning platform
  • Discounts at Riachuelo