Information Security Specialist I

Jobtailor

Joinville

Presencial

BRL 180 000 - 280 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Jobtailor in Joinville is seeking an experienced Information Security lead to define and evolve controls, support ISMS, and promote secure-by-design practices across technology and business units. You will conduct risk analyses, support audits, and drive security initiatives aligned with regulatory requirements and IPO readiness where applicable.

You will collaborate with infrastructure, development, privacy and compliance teams, ensuring robust authentication, encryption, and incident response

Qualificações

  • Bachelor’s degree in Information Security, Computer Science, Information Systems, Computer Engineering, Software Engineering or related fields.
  • Solid experience in corporate Information Security, with work in governance, risk management, compliance, security architecture or security applied to systems and applications.
  • Practical and demonstrable knowledge of ISO 27001, ISO 27002, NIST Cybersecurity Framework, NIST Secure Software Development Framework (SSDF), risk management, security controls and audit processes.
  • Experience creating, implementing or supporting policies, standards, processes, evidence and Information Security controls, with the ability to support internal and external audits and environments with high governance requirements.
  • Experience in secure development, application security or AppSec, including concepts such as OWASP, review of security requirements, vulnerability management, hardening, environment segmentation, security testing and integration of security practices into the development lifecycle.
  • Experience assessing risks and security requirements for new systems, vendors, integrations, cloud services, enterprise applications and technology transformation projects.
  • Technical knowledge of security tools and disciplines such as IAM/IGA, MFA, SSO, log management, SIEM, endpoint protection, vulnerability management, encryption, access control, incident response and security in hybrid/cloud environments.
  • Experience supporting governance and compliance processes in complex corporate environments, preferably with exposure to readiness projects for audits, regulated markets, IPOs or environments with strong traceability and internal control requirements.
  • Advanced English for technical reading, interaction with vendors, understanding standards, frameworks, documentation and audit materials.

Responsabilidades

  • Define, implement and evolve Information Security controls, ensuring adherence to corporate policies, regulatory requirements and industry frameworks, with focus on risk management, data protection, operational continuity and reducing the attack surface.
  • Conduct cyber risk analyses of systems, applications, integrations, vendors, projects and significant changes, proposing treatment plans, compensating controls, prioritization criteria and monitoring indicators to support technical and executive decision-making.
  • Support the structuring, maintenance and evolution of the Information Security Management System (ISMS), including policies, standards, procedures, evidence, audit trails, controls and preparation for internal and external audits and regulatory/corporate readiness initiatives, including IPO contexts.
  • Lead technical secure development and DevSecOps initiatives, establishing secure-by-design and secure-by-default standards, performing architecture reviews, defining security requirements for applications, and promoting use of SAST, DAST, SCA, vulnerability management, hardening, environment segregation and validation of requirements prior to production.
  • Participate in information security incident response, supporting detection, containment, eradication, recovery, investigation, lessons learned and continuous improvement of processes, interfacing with infrastructure, applications, architecture, privacy, compliance teams and executive leadership as needed.
  • Technically evaluate new solutions, vendors and services from security, privacy and architecture perspectives, ensuring compliance with minimum requirements such as strong authentication, encryption, log management, auditability, vulnerability management, access controls, regulatory compliance and secure development practices.
  • Produce and present executive and technical materials on risks, maturity, action plans, compliance deviations, remediation status and the evolution of the security roadmap, supporting committees, audits, governance reviews and strategic forums within the organization.
  • Promote the dissemination of a security culture across technology and business teams, supporting training, defining standards, providing technical guidance on projects, strengthening processes and embedding security and privacy from the conception of initiatives.

Conhecimentos

Advanced English for technical reading
Security governance & compliance
Secure development / AppSec
Risk assessment & controls
Incident response knowledge

Formação académica

Bachelor’s degree in Information Security, Computer Science, Information Systems, Computer Engineering, Software Engineering or related fields

Ferramentas

IAM/IGA
MFA
SSO
SIEM
Vulnerability management
Encryption

Descrição da oferta de emprego

Responsibilities
  • Define, implement and evolve Information Security controls, ensuring adherence to corporate policies, regulatory requirements and industry frameworks, with focus on risk management, data protection, operational continuity and reducing the attack surface.
  • Conduct cyber risk analyses of systems, applications, integrations, vendors, projects and significant changes, proposing treatment plans, compensating controls, prioritization criteria and monitoring indicators to support technical and executive decision-making.
  • Support the structuring, maintenance and evolution of the Information Security Management System (ISMS), including policies, standards, procedures, evidence, audit trails, controls and preparation for internal and external audits and regulatory/corporate readiness initiatives, including IPO contexts.
  • Lead technical secure development and DevSecOps initiatives, establishing secure-by-design and secure-by-default standards, performing architecture reviews, defining security requirements for applications, and promoting use of SAST, DAST, SCA, vulnerability management, hardening, environment segregation and validation of requirements prior to production.
  • Participate in information security incident response, supporting detection, containment, eradication, recovery, investigation, lessons learned and continuous improvement of processes, interfacing with infrastructure, applications, architecture, privacy, compliance teams and executive leadership as needed.
  • Technically evaluate new solutions, vendors and services from security, privacy and architecture perspectives, ensuring compliance with minimum requirements such as strong authentication, encryption, log management, auditability, vulnerability management, access controls, regulatory compliance and secure development practices.
  • Produce and present executive and technical materials on risks, maturity, action plans, compliance deviations, remediation status and the evolution of the security roadmap, supporting committees, audits, governance reviews and strategic forums within the organization.
  • Promote the dissemination of a security culture across technology and business teams, supporting training, defining standards, providing technical guidance on projects, strengthening processes and embedding security and privacy from the conception of initiatives.
Requirements
  • Bachelor’s degree in Information Security, Computer Science, Information Systems, Computer Engineering, Software Engineering or related fields.
  • Solid experience in corporate Information Security, with work in governance, risk management, compliance, security architecture or security applied to systems and applications.
  • Practical and demonstrable knowledge of ISO 27001, ISO 27002, NIST Cybersecurity Framework, NIST Secure Software Development Framework (SSDF), risk management, security controls and audit processes.
  • Experience creating, implementing or supporting policies, standards, processes, evidence and Information Security controls, with the ability to support internal and external audits and environments with high governance requirements.
  • Experience in secure development, application security or AppSec, including concepts such as OWASP, review of security requirements, vulnerability management, hardening, environment segmentation, security testing and integration of security practices into the development lifecycle.
  • Experience assessing risks and security requirements for new systems, vendors, integrations, cloud services, enterprise applications and technology transformation projects.
  • Technical knowledge of security tools and disciplines such as IAM/IGA, MFA, SSO, log management, SIEM, endpoint protection, vulnerability management, encryption, access control, incident response and security in hybrid/cloud environments.
  • Experience supporting governance and compliance processes in complex corporate environments, preferably with exposure to readiness projects for audits, regulated markets, IPOs or environments with strong traceability and internal control requirements.
  • Advanced English for technical reading, interaction with vendors, understanding standards, frameworks, documentation and audit materials.
Core Competencies

Demonstrates expertise in Information Security controls, risk management, and compliance with industry standards such as ISO 27001 and NIST frameworks. Proficient in secure development practices, incident response, and governance processes within complex corporate environments.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Junior Information Security Analyst
Junior Information Security Analyst

Jobtailor • Rio de Janeiro

Presencial
BRL 100 000 - 140 000
Information Security Analyst I
Information Security Analyst I

Jobtailor • Porto Alegre

Presencial
BRL 120 000 - 180 000
Junior Information Security Analyst
Junior Information Security Analyst

Jobtailor • São Paulo

Presencial
BRL 120 000 - 180 000
Cybersecurity Assistant
Cybersecurity Assistant

Jobtailor • Vitória

Presencial
BRL 80 000 - 120 000
Information Security Manager
Information Security Manager

Jobtailor • Barueri

Presencial
BRL 180 000 - 300 000
Information Security Analyst – Junior
Information Security Analyst – Junior

Jobtailor • Vitória

Presencial
Information Security Analyst (Mid-level)
Information Security Analyst (Mid-level)

Jobtailor • São Paulo

Presencial
BRL 120 000 - 240 000
Mid-Level Information Security Analyst
Mid-Level Information Security Analyst

Jobtailor • São Paulo

Presencial
BRL 90 000 - 150 000
Senior Information Security Analyst – Blue Team
Senior Information Security Analyst – Blue Team

Jobtailor • São Paulo

Presencial
BRL 180 000 - 280 000
Senior Information Security Analyst – Cloud Security
Senior Information Security Analyst – Cloud Security

Jobtailor • São Paulo

Presencial
BRL 180 000 - 300 000