Rooted
Back to jobs
SK
Open role

Skyone

Cloud Security Engineer

São Paulo, Brazil· REMOTE

Hacker+ signal

About the role

You are responsible for how identity and access are configured across the company's cloud accounts: which roles exist, what each one can reach, and what happens when a service has more permission than it needs. The work is a mix of auditing existing configuration, writing infrastructure-as-code guardrails, and investigating unusual access patterns. Most serious issues in cloud environments come from permissive policies rather than software vulnerabilities.

What you will do

  • Audit IAM boundaries and cut the permissions nothing uses
  • Write the infrastructure guardrails as code
  • Investigate anything that looks like lateral movement

What they ask for

  • Real experience with AWS, Azure or GCP identity models
  • Terraform or an equivalent, used in anger
  • Can read a policy document and find what it accidentally allows

Nice to have

  • Kubernetes
  • Detection engineering
  • Cloud certifications

What applying with Rooted means

This role accepts applications with Rooted context. Instead of sending only a resume, you can attach a verifiable credential with your proofs, rank, and technical evidence.

Your application includes your Rooted credential: rank, verified proofs, and supporting evidence.

You can read this role without an account. To apply you need a Rooted credential.

This role is curated by Rooted. Rooted is not the hiring company unless explicitly stated. The hiring company is Skyone. Confirm the final details with the original source or during the application process.

Posted 2026-08-13