
Cyber Engineer - Protect
- Lisboa
- Permanente
- Horário completo
- Act as a Cyber Engineer in a DevSecOps team collaborating with the Security Operations Centre, Cyber Governance teams and global business unit stakeholders on the design, deployment and management of core security tooling focusing on risk reduction
- Work to implement security tools and capabilities based on the level of risk identified
- Establish clear understanding and documentation of processes related to cyber security tooling
- Leverage security automation tooling and develop playbooks and workflows based on operational use cases
- Support the implementation of security controls for IT platforms and applications to ensure adherence to business objectives, regulatory requirements and cyber security policies
- Ensure the deployment of security tools is achieved with minimum impact to business
- Maintain detailed knowledge of emerging threats, risks, technical innovations and security capabilities
- Implement and manage CWPP and CSPM tools to monitor and enforce security policies across cloud environments (AWS, Azure, GCP, Alibaba, OCI).
- Conduct risk assessments and vulnerability management for cloud workloads, ensuring proper controls are in place.
- Perform cloud security assessments, identify misconfigurations, and recommend remediation actions.
- Automate security controls and integrate cloud security into CI/CD pipelines.
- Collaborate with DevOps and infrastructure teams to improve cloud security architecture and posture.
- Conduct incident response and troubleshooting for cloud-based security incidents.
- Experience working in a Security Engineering or Security Operations capacity within a DevOps team in an enterprise organisation
- Knowledge of NIST 800-53, ISO 27001, CIS & SOC 2 security frameworks and standards
- Ability to generate high-quality solution documentation
- Knowledge of security incident response and ITIL service methodology
- Experience in working in an environment using Agile frameworks
- Minimum of 2-3 years of experience in cloud security, with hands-on experience in CWPP and CSPM tools (e.g., Prisma Cloud, Cloud Conformity etc.)
- Strong understanding of cloud platforms (AWS, Azure, GCP, Alibaba, OCI) and cloud-native security controls.
- Experience in cloud security best practices, threat modelling, and risk management.
- Familiarity with automation tools (Terraform, Ansible, etc.) and integration into security workflows.
- Experience with container security and Kubernetes.
- Certifications in cloud security AWS Certified Security Specialty, Certified Cloud Security Professional - CCSP, CCSK etc are desirable
- Able to present technical security information to a non-technical audience