Description
Job Summary:
An Information Security professional responsible for monitoring, incident response, vulnerability management, and implementation of security controls to strengthen the digital environment.
Key Highlights:
1. Proactive security operations and incident response
2. Vulnerability management, penetration testing, and system hardening
3. Focus on compliance with LGPD and ISO 27001
**Key Responsibilities:**
* Monitor and correlate security events, proactively identifying and responding to incidents;
* Investigate incidents, conduct forensic analysis, and contain ongoing threats;
* Implement and administer security controls (firewall, antivirus, SIEM, SOAR, IDS/IPS, WAF, etc.);
* Perform vulnerability assessments, penetration tests, and system hardening, prioritizing and driving remediation;
* Manage access and user roles in critical systems, ensuring data security;
* Support the SOC with threat intelligence, IOC integration, and continuous detection improvement;
* Assess risks in systems and projects, ensuring compliance with standards such as LGPD and ISO 27001;
* Review and ensure enforcement of information security policies and procedures;
* Collaborate with internal departments (IT, Legal, Compliance) and clients to enhance security;
* Conduct awareness campaigns (e.g., phishing) for employees and clients;
* Prepare technical and executive reports on the security posture;
* Participate in audits, improvement initiatives, and tool validation;
* Provide technical support to analysts, promoting hands-on development;
* Document processes and procedures per quality guidelines.
**Requirements:**
Technical or undergraduate degree in progress or completed in fields such as Information Security, Computer Science, Information Systems, or related disciplines.
Minimum of 3 years of experience in Information Security, including security monitoring, vulnerability management, incident response, and security control implementation.
**Work Schedule:**
Monday to Friday, 9:00 AM to 6:00 PM. On-site format. CLT employment.
Certifications (Mandatory):
ISO 27001 Foundation; and
CompTIA Security+; or
CompTIA Pentest+; and
CompTIA CySA+; or
CEH – Certified Ethical Hacker
Employment Type: Full-time CLT
Compensation: R$3.567,79 – R$6.785,47 per month
Benefits:
* Health insurance
* Company-provided mobile phone
* Commercial partnerships and discounts
* Meal allowance
* Transportation allowance
Work Location: On-site