Description
Job Summary:
Information Security professional to support the strategic development of the area, with focus on Red and Blue Team.
Key Highlights:
1. Hands-on involvement in Red and Blue Team activities
2. Development of a strategic Information Security roadmap
3. Primary technical reference in information security
Description: Prerequisites:* Reside in São Paulo or Rio de Janeiro;
* Completed undergraduate degree;
* Intermediate to advanced English proficiency will be assessed;
* Experience in Information Security, with involvement in Red and/or Blue Team activities;
* Technical knowledge of network security (including firewalls), operating systems, and web applications;
* Practical experience with cloud security (AWS is a strong plus);
* Familiarity with security frameworks such as MITRE ATT\&CK, NIST, and OWASP Top 10;
* Ability to automate security tasks using scripting languages (e.g., Python, Shell);
* Experience with EDR/XDR (Endpoint Detection and Response) tools (e.g., SentinelOne or equivalents) is desirable;
* Offensive security certifications (e.g., OSCP, OSCE) and/or defensive security certifications (e.g., GCIH, GCFA, CISSP) are desirable;
* Experience implementing DevSecOps culture is desirable;
* Experience in malware analysis and digital forensics is desirable;
Main Challenges:* Develop DMS’s strategic Information Security roadmap, planning the area’s evolution, adoption of new tools, and team expansion;
* Perform hands\-on work across defense (Blue Team) and attack (Red Team) domains, serving as the primary technical reference in information security.
Blue Team (Defense):
* Monitor cloud environments (AWS) and internal systems for malicious activity;
* Manage the incident response plan, conducting investigations and mitigating security events;
* Implement and administer security tools such as SIEM, EDR, and IDS/IPS;
* Conduct vulnerability management, tracking remediation of identified flaws;
* Ensure compliance with security best practices and regulations, including LGPD.
Red Team (Attack):
* Conduct penetration testing and ethical hacking on applications, especially Cockpit and customer portals;
* Simulate attacks such as phishing and social engineering to strengthen employee awareness;
* Analyze architectures of new systems to identify security flaws during the design phase;
* Produce detailed vulnerability reports with clear recommendations and action plans.
2511060202271851920