Security Engineer
职责包括红队活动:执行Web和移动(iOS、Android、Windows和Mac)应用程序的渗透测试,负责漏洞管理生命周期从识别、修复到报告,主动监控和检测组织内的运营安全风险,对安全事件和技术工具进行技术调查,直接与用户在售前和支持期间沟通安全问题。
加载中...
Stefanini Group is looking for a Senior Infrastructure Security Lead to join our Cyber Security Services Cluster within the Infrastructure Services (INFRA) Division. As a Senior Infrastructure Security Lead, reporting to the client CISO, you will be instrumental in advancing the cybersecurity services and platforms, ensuring they meet the highest standards of governance and effectiveness. You will combine service governance with hands-on security engineering across NDR/MDR, the Microsoft 365 Security stack, and Application Security/DevSecOps, while coordinating with SOC and client technical teams. We are seeking a dedicated professional who is passionate about delivering measurable security outcomes in a dynamic environment.
Job responsibilities: Identify, validate, and remediate security issues, misconfigurations, and vulnerabilities across on-prem, cloud, and M365 environments. Engineer, implement, and continuously improve security controls and hardening for infrastructure and applications. Configure, tune, and manage NDR/MDR/XDR and the Microsoft 365 Security stack; maintain policies, detections, and automations. Lead AppSec/DevSecOps integrations (e.g., SAST/DAST/SCA/secret scanning) into CI/CD and support secure SDLC practices. Conduct security evaluations of infrastructure and applications and drive remediation with accountable teams. Create and maintain runbooks, SOPs, and hardening baselines aligned to CIS/NIST. Evaluate and pilot new security technologies; manage security vendors/MSSPs, SLAs, and roadmaps. Collaborate with SOC, IT, and product teams to implement controls and fixes; ensure clean handovers from build to run.
Key requirements: Demonstrated experience in a comparable position is required. 5+ years of experience in systems engineering (Windows/Linux, networking, cloud/M365), ideally with security-focused responsibilities. Solid experience identifying and mitigating infrastructure and application vulnerabilities, misconfigurations, and exposures; familiarity with secure configuration baselines. Hands-on programming/scripting (e.g., PowerShell, Python, Bash) and DevSecOps practices (CI/CD integration, SAST/DAST/SCA, secrets management; IaC basics a plus). Proven ability to design, implement, and improve security measures across infrastructure and applications (hardening, access control, logging/monitoring). Excellent written and verbal communication skills and the ability to synthesize complex technical topics into clear, actionable guidance. Capability to build effective working relationships with key stakeholders (IT, SOC, development, business, and vendors) and influence without authority. Strong presentation and collaboration skills. Excellent written and verbal communication skills in English. French language skills would be considered a plus. Ability to manage multiple priorities and meet deadlines. High degree of initiative, dependability and ability to work with little supervision. Relevant certifications in Cyber Security (e.g., CISSP, CISM, etc.) are preferred. Very proficient in MS tools: Excel, PowerPoint, visio, pj.
Global Tech Consulting Company All in One. Stefanini is a Brazilian multinational company with 38 years of experience and presence in 41 countries. With more than 35,000 employees, we co-create solutions for a better future, driving digital transformation with a focus on real results. We operate in an integrated way through 7 specialized business units: Consulting (Technology and Business Agility), Analytics & AI, Banking & Payments, Cybersecurity, Manufacturing 4.0, and Digital Marketing. We are a group that breathes collaboration and offers a dynamic environment where you will learn by doing, grow alongside the team, and have space to contribute with ideas and projects.
注册并登录后即可查看
职责包括红队活动:执行Web和移动(iOS、Android、Windows和Mac)应用程序的渗透测试,负责漏洞管理生命周期从识别、修复到报告,主动监控和检测组织内的运营安全风险,对安全事件和技术工具进行技术调查,直接与用户在售前和支持期间沟通安全问题。
关于该职位 V-Thru正在寻找Senior SRE/DevOps工程师,以构建和扩展我们的基础设施和部署系统,随着我们的QCommerce平台的成长。该职位将拥有生产系统的可靠性、可观测性和自动化,与我们的工程团队紧密合作,加速交付,同时保持高可用性。
我们正在构建一个安全的企业 HashiCorp Boundary 平台,需要一名 Lead Platform/Infrastructure Engineer 来推动在 AWS 和 Azure 上的交付和云连接。您将制定可重用的平台标准...
加入我们的布加勒斯特开发中心,并成为我们开明、进步和专业的团队的一员。在这个角色中,您将为我们的世界知名客户工作。首席安全办公室(CSO)由首席信息安全办公室(CISO)和企业安全单元组成。CISO组织确保我们的客户信息的安全。