Description
Job Summary:
An Information Security professional to manage maturity, policies, risks, and incidents, operating across infrastructure and governance.
Key Highlights:
1. Comprehensive Information Security and Risk Management (ISO 27001, 31000)
2. Technical and operational expertise in infrastructure and information security
3. Vulnerability management, business continuity, and governance
**1\. Information Security Management**
* Conduct Information Security maturity assessments based on ISO 27001 and related standards;
* Develop, review, and maintain corporate security policies, standards, and procedures;
* Coordinate and monitor security action plans, ensuring compliance with internal standards and frameworks;
* Perform risk analyses based on ISO 31000, produce reports, and prioritize mitigation measures;
* Support LGPD compliance, including privacy risk analysis, contract reviews, and third-party assessments;
* Support audit and certification processes by responding to evidence requests and implementing corrective controls;
* Design and deliver security awareness campaigns and best-practice training for users.
**2\. Technical and Operational Activities in Infrastructure and Security**
* Monitor, investigate, and respond to security incidents in collaboration with infrastructure, network, and systems teams;
* Conduct technical analyses on servers and workstations to identify vulnerabilities, incidents, and non-conformities;
* Apply corrective and preventive measures directly within managed environments (patches, hardening, blocks, security updates, etc.);
* Support monitoring tool operations (Zabbix, GLPI, SIEM, antivirus, firewall, etc.);
* Manage access rights, permissions, and identity policies (AD, MFA, IAM, PAM), ensuring alignment with corporate policies;
* Participate in the implementation and validation of new security and infrastructure solutions;
* Prepare technical reports documenting executed corrective and preventive actions.
**3\. Vulnerability and Continuity Management**
* Conduct vulnerability scans and analyses using tools such as Tenable, Qualys, Rapid7, or equivalents;
* Classify and prioritize vulnerabilities based on severity, assessing business impact and risk;
* Support disaster recovery (DRP) and business continuity (BCP) planning;
* Track remediation plans, ensuring corrections are applied and documented.
**4\. Stakeholder Engagement and Governance**
* Serve as the technical liaison between the client and internal company departments;
* Attend operational and governance meetings, presenting security metrics and status updates;
* Support clients in compliance activities, audits, and internal investigations;
* Prepare and present executive security reports, including risk analysis, incident summaries, and recommendations;
* Conduct internal workshops and training sessions on information security and cyber defense.
### **Employment Type:**
CLT
### **Required Knowledge and Skills:**
HandsOn, Infrastructure, Information Security, VulnerabilityManagement, Governance, CloudSecurity
### **Benefits:**
Health Insurance, Dental Insurance, Meal Voucher, Transportation Voucher, Life Insurance, OnHappy
### **Department:**
Corporate