Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Creditas

Staff Security Engineer

Creditas

. Serve as an architecture and engineering authority across Cloud, Network, Endpoint, CSIRT, CTI, and SOC .

Posted 9/22/2026full-timeSão Paulo • BrazilLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive expertise in Defensive Security, focusing on detection engineering, incident response, and cloud security across AWS, GCP, and Azure environments. Capable of leading technical teams, enhancing security operations through automation, and translating threat intelligence into actionable strategies.

Highest-signal resume keywords
Defensive Security ExpertiseDetection EngineeringCloud Security (AWS, GCP, Azure)Incident Response LeadershipInfrastructure as Code (IaC)

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Detection DevelopmentIncident ResponseCloud SecurityNetwork SecurityEndpoint SecurityProgramming (Python, Go)AutomationMetrics Tracking (MTTD, MTTR)MITRE ATT&CK MappingCyber Threat Intelligence
Soft Skills
Technical MentorshipInfluencing Without Authority
Tools & Technologies
SOARCI/CD PipelinesEDR/XDRAutomation Tools
Industry Keywords
SOCIncident ResponseDetection EngineeringCloud-Native EnvironmentsMicroservicesContainers

Tech Stack

Tools & technologies
AWSAzureCloudGoogle Cloud PlatformPythonGo

About the role

Key responsibilities & impact
  • Serve as an architecture and engineering authority across Cloud, Network, Endpoint, CSIRT, CTI, and SOC
  • Design and evolve the detection engineering strategy, defining use cases, coverage, and SOC logic
  • Prioritize signal fidelity and noise reduction over alert volume
  • Structure and enhance playbooks, automation, and technical incident response capabilities
  • Act as the senior technical escalation point for critical incidents and lead root-cause-focused postmortems
  • Define defense architecture for AWS, GCP, or Azure environments, networks, and endpoints
  • Embed controls directly into infrastructure through Infrastructure as Code (IaC) and version-controlled policies
  • Guide the Cyber Threat Intelligence program, translating threat intelligence into actionable detections and risk prioritization
  • Eliminate repetitive manual work through SOAR, detection-as-code pipelines, integrations, and AI applied to defense
  • Define and track metrics such as MTTD, MTTR, detection coverage, and dwell time
  • Technically develop engineers across the six areas and establish the standard for technical excellence in Defensive Security
  • Serve as a technical liaison with Platform Engineering, AppSec, IAM, and GRC, translating risks for leadership and business stakeholders

Requirements

What you’ll need
  • Solid senior-level experience in Defensive Security / Blue Team, with hands-on experience in more than one area, including SOC, incident response, detection engineering, cloud, network, or endpoint security
  • Strong alignment with an AI-First culture, using AI to automate security detection, response, analysis, or operations
  • Deep technical expertise in detection engineering and SOC operations, including detection development, tuning, and coverage strategy, such as MITRE ATT&CK mapping
  • Proven experience leading end-to-end incident response, from containment through root-cause analysis
  • Strong knowledge of cloud security (AWS, GCP, or Azure), including control architecture, logging, and detection in cloud-native environments
  • Solid knowledge of network and endpoint security in modern environments, including microservices, containers, and EDR/XDR
  • Proficiency in at least one programming language, such as Python, Go, or a similar language
  • Experience with IaC and CI/CD pipelines applied to security
  • Familiarity with Cyber Threat Intelligence and its practical application to defense prioritization
  • Track record of serving as a technical authority and mentor, influencing without relying on hierarchical authority
  • Availability for hybrid work, with attendance at the office in the Morumbi area of São Paulo once a month for four consecutive days

Benefits

Comp & perks
  • Health insurance (Alice)
  • Dental insurance (SulAmérica)
  • Wellz: 100% free therapy sessions
  • Wellhub: access to gyms and studios
  • Creditas Endurance: incentive program for high-impact sports
  • Pharmacy benefit (Univers)
  • Life insurance (Porto Seguro)
  • Birthday day off
  • Extended parental leave: 6 months for birth parents and 35 days for non-birth parents
  • Family Care: support program for maternity and paternity
  • Childcare assistance
  • Assistance for dependents with disabilities (PwD)
  • SESC: access to facilities for you and your dependents
  • Meal allowance (VR): flexible benefits card (Creditas Card)
  • Payroll-deducted loans (Creditas Benefícios)
  • Salary advances (Creditas Benefícios)
  • Insurance discounts (Minuto Seguros)
  • Access to exclusive financial education content in the Creditas app
  • PPR: profit-sharing program
  • Educational and professional development incentives
  • Flexible work model
  • Free bicycle parking at the office
  • Partner parking at the office (subject to internal availability)