Description
Job Summary:
We are seeking a proactive professional to conduct risk assessments, manage security incidents, and implement solutions, actively contributing to information security.
Key Highlights:
1. Lead information security and incident management.
2. Assess risks and implement security solutions.
3. Support internal audits and regulatory compliance.
**We are looking for someone who dares to lead with us.**
**Responsibilities:**
* Conduct risk, threat, and vulnerability assessments.
* Evaluate and perform hardening configuration reviews.
* Respond to and analyze security incidents (incident handling), including identification, investigation, containment, and resolution.
* Develop, maintain, and update incident response playbooks.
* Support the team in daily activities related to internal audit, compliance, etc.
* Assess and analyze security requirements for existing systems and new projects, firewall rules, and define new requirements as needed.
* Respond to tickets and analyze security-related risks, troubleshoot issues involving security tools, policies, rules, and firewall configurations.
* Define security policies and conduct user profile reviews.
* Participate in internal security awareness campaigns, contributing to material creation and communication with employees.
* Design, implement, and maintain security solutions, defining associated processes and controls.
* Respond to breaches or threats and take corrective and preventive actions to avoid future incidents.
* Monitor internal logs and network traffic to proactively investigate suspicious activities and anomalies.
* Communicate\-with client teams to discuss security measures and provide information about the designed system.
**Requirements:**
* Completed undergraduate degree in Information Security or Information Technology;
* Minimum 5 years of experience in Information Security.
* Knowledge of network security, cybersecurity protection solutions, technical and operational controls, operating systems, and cloud solutions.
* Security frameworks and methodologies, such as ISO 27001, NIST, and OWASP.
* Knowledge of regulatory compliance standards (e.g., PCI, SOX).
* Practical experience with SOC.
* Availability to work night shifts from 10:00 PM to 6:00 AM.
* English / Advanced / Writing / Speaking.
**Skills:**
* Integrity and discretion.
* Commitment/engagement.
* Results-oriented.
* Strong interpersonal skills.
* Critical/analytical thinking.
* Maintain strong communication skills for interaction with internal and external teams.
* Teamwork, providing support to analysts across diverse activities.
* Familiarity with IT controls and audit processes.
**Preferred Qualifications:**
* Certifications such as ISO/IEC 27001, CEH, CCSP, CISSP, ISFS, Security\+, PDPF.
* Knowledge / Solutions: (Antivirus, Burp Suite, WAF, Firewall, SIEM, QualysGuard, AWS, Azure or Google Cloud, general security tools).
* Map security risks and define web application/application architectures.
**Additional Information:**
* For your health, we offer **medical and dental assistance** with no co-payment for exams and consultations.
* Want more well\-being? We offer **Gympass** and **Zenklub** (with two free sessions per month) to help you care for your physical and mental health.
* When hunger strikes, use our meal benefit **Caju** to shop at any supermarket or restaurant.
* Love to travel? Here, we have **Férias \& Co**, a benefit that helps make your dream vacation possible.
* Have children? Count on our **childcare allowance**.
* Growing family? We offer **MomCare**, a flexible monetary incentive post-maternity leave for new Datunian mothers.
* To personalize your workspace, count on our **home office allowance**.
* Want to invest in your professional development? We partner with several renowned educational institutions to offer you discounts of up to 70% on **undergraduate**, **postgraduate**, **MBA**, **language**, and many other courses!
**To learn about all our benefits, visit the homepage of our careers page.**