Cybersecurity Analyst III (CloudSec/SRE)
MB | Mercado BitcoinSão Paulo, São Paulo, Brazil
Type
Full-time
Work setup
On-site
Experience
Mid
Posted
8 days ago
What security roles in crypto pay
64 salaries · our own dataMost security roles in crypto pay between $145k and $268k, with a median of $202k.
As a Cybersecurity Analyst III at MB | Mercado Bitcoin, you serve as a technical leader for the CloudSec team with a strong platform engineering profile. You operate, evolve, and harden the company's cloud infrastructure, uniting reliability and security by treating guardrails, automation, and incident response as integral parts of the engineering cycle, not as a separate layer or obstacle. You work in a high-volume transactional environment at massive scale and under heavy regulatory requirements, so your architecture and automation decisions directly impact risk, availability, cost, and technical compliance.
What you'll do
- Design, automate, and operate preventive and reactive security controls in GCP (IAM, VPC Service Controls, KMS, Org Policies, GKE/Kubernetes hardening) across cloud architecture.
- Build and maintain secure modules and Security-as-Code policies using Terraform and Terragrunt to enable automated detection, response, and remediation in the infrastructure.
- Harden CI/CD pipelines and the software supply chain through SAST and SCA security testing.
- Manage and optimise network edge policies (Cloudflare WAF, bot mitigation, DDoS mitigation) and engage directly in Detection Engineering and infrastructure incident response.
- Partner with product, data, and engineering teams to build secure "Paved Roads" and embed security into critical architectures including microservices, data flows, and AI initiatives.
What you bring
- Consolidated experience as an SRE, Platform Engineer, or Cloud Security professional in high-scale, high-availability environments.
- Practical mastery of GCP in production (IAM, advanced networking, KMS, GKE/Kubernetes).
- Hands-on Infrastructure as Code expertise using Terraform in modular, automated environments.
- Development and automation skills to create internal tools, remediation scripts, and robust API integrations.
- Experience with monitoring and logging tools for correlating security and availability events.
- Practical knowledge of WAF operation and security rules at the application/edge layer.
- Understanding of CSPM and CWPP ecosystems for continuous posture management and workload protection.
- Technical negotiation skills to discuss trade-offs between availability, security, delivery speed, and cost.
- Strong communication with technical teams (developers, SREs) and non-technical stakeholders, acting as a facilitator and business partner.
- Systems thinking that emphasises solving problems at root cause through scalable automation, rejecting manual and bureaucratic processes.
- Proactive ownership to identify posture gaps, propose resilient architectures, and execute end-to-end implementations.
Nice to have
- Experience with large-scale messaging ecosystems such as Kafka (topic operation and security).
- Multi-Cloud experience with additional knowledge of AWS or Azure.
- Cloud security or architecture certifications such as Google Professional Cloud Security Engineer or AWS Certified Security - Specialty.
- Hands-on expertise with CSPM tools.
