Serve as the technical reference for perimeter security;
Define and evolve secure architectures for application and API exposure;
Provide technical leadership for initiatives involving Firewalls, Proxies, WAF/CDN, and API protection;
Perform advanced troubleshooting in critical production environments;
Develop and refine protection policies and strategies;
Identify architectural risks and propose structural improvements;
Act as a bridge between Infrastructure, Development, SOC, and Cloud teams;
Reduce operational dependencies through automation and standardization;
Help translate technical risks into business impact;
Ensure support and stability of critical, high-availability environments;
Prepare technical reports and strategic presentations for leadership;
Requirements
Degree in Engineering, Cybersecurity, Computer Science, Information Systems, or related fields;
Solid experience in network and perimeter security architecture;
Advanced knowledge of TCP/IP and DNS;
Experience with Firewalls (Fortinet, Cisco Firepower, or similar), including architecture design, traffic inspection, policy configuration, and segmentation;
Experience with WAFs and CDNs (Cloudflare, Akamai, or similar), including tuning, analysis, and false-positive mitigation in high-criticality environments;
Experience in advanced troubleshooting of traffic and applications;
Knowledge of application and API exposure architectures;
Experience with public cloud environments (AWS or similar);
Ability to define, document, and evolve security architectures;
Experience making technical decisions weighing risk, impact, and business considerations;
High technical autonomy;
Ability to make architectural decisions;
Act as a technical reference for the team;
Critical thinking and a solution-oriented approach to complex problems;
Good communication with technical and business stakeholders;
✨Preferred:
Experience with application security (OWASP Top 10);
Knowledge of API security (OWASP API Top 10) and API protection solutions;
Knowledge of bot and abuse mitigation (rate limiting, bot management);
Experience with Zero Trust and access segmentation;
Knowledge of IPS/IDS, DDoS mitigation, and Proxy solutions;
Experience with Linux;
Experience with automation (Python, Terraform, API-based integrations);
Experience with observability tools and traffic analysis;
Advanced English.
Tech Stack
AWS
Cloud
DNS
Firewalls
Linux
Python
TCP/IP
Terraform
Benefits
15 days of paid leave;
Clude Saúde (online medical consultation platform);
Birthday day off + gift;
Partnership with AWS;
Language assistance;
TotaPass (benefits platform);
Support for further education and certification (Postgraduate/MBA and AWS certification);