Senior Information Security Analyst

Company
Description
Job Summary: An Information Security professional to manage maturity, policies, risks, and incidents, operating across infrastructure and governance. Key Highlights: 1. Comprehensive Information Security and Risk Management (ISO 27001, 31000) 2. Technical and operational expertise in infrastructure and information security 3. Vulnerability management, business continuity, and governance **1\. Information Security Management** * Conduct Information Security maturity assessments based on ISO 27001 and related standards; * Develop, review, and maintain corporate security policies, standards, and procedures; * Coordinate and monitor security action plans, ensuring compliance with internal standards and frameworks; * Perform risk analyses based on ISO 31000, produce reports, and prioritize mitigation measures; * Support LGPD compliance, including privacy risk analysis, contract reviews, and third-party assessments; * Support audit and certification processes by responding to evidence requests and implementing corrective controls; * Design and deliver security awareness campaigns and best-practice training for users. **2\. Technical and Operational Activities in Infrastructure and Security** * Monitor, investigate, and respond to security incidents in collaboration with infrastructure, network, and systems teams; * Conduct technical analyses on servers and workstations to identify vulnerabilities, incidents, and non-conformities; * Apply corrective and preventive measures directly within managed environments (patches, hardening, blocks, security updates, etc.); * Support monitoring tool operations (Zabbix, GLPI, SIEM, antivirus, firewall, etc.); * Manage access rights, permissions, and identity policies (AD, MFA, IAM, PAM), ensuring alignment with corporate policies; * Participate in the implementation and validation of new security and infrastructure solutions; * Prepare technical reports documenting executed corrective and preventive actions. **3\. Vulnerability and Continuity Management** * Conduct vulnerability scans and analyses using tools such as Tenable, Qualys, Rapid7, or equivalents; * Classify and prioritize vulnerabilities based on severity, assessing business impact and risk; * Support disaster recovery (DRP) and business continuity (BCP) planning; * Track remediation plans, ensuring corrections are applied and documented. **4\. Stakeholder Engagement and Governance** * Serve as the technical liaison between the client and internal company departments; * Attend operational and governance meetings, presenting security metrics and status updates; * Support clients in compliance activities, audits, and internal investigations; * Prepare and present executive security reports, including risk analysis, incident summaries, and recommendations; * Conduct internal workshops and training sessions on information security and cyber defense. ### **Employment Type:** CLT ### **Required Knowledge and Skills:** HandsOn, Infrastructure, Information Security, VulnerabilityManagement, Governance, CloudSecurity ### **Benefits:** Health Insurance, Dental Insurance, Meal Voucher, Transportation Voucher, Life Insurance, OnHappy ### **Department:** Corporate
Posted by

João Silva
Indeed · HR


