Information Security Engineering Specialist

Company
Description
Job Summary: Work in Information Security Engineering, designing, implementing, and evolving technical security controls for corporate and cloud environments. Key Highlights: 1. Responsible for Security by Design, DevSecOps, and cloud security. 2. Defines security requirements and standards for new projects and applications. 3. Implements security controls for Azure, OCI, and SaaS environments. Work in the Information Security Engineering area, responsible for designing, implementing, sustaining, and evolving technical security controls that support corporate environments, applications, integrations, cloud platforms, and the organization’s digital transformation initiatives. The professional will ensure adoption of Security by Design, DevSecOps, data protection, cloud security, identity management, continuous monitoring, and integration of security controls into the corporate solutions’ lifecycle. Define security requirements and standards for new projects, applications, and integrations. Participate in technical vendor and solution certification processes. Conduct technical risk assessments and define compensating controls. Develop security recommendations for on-premise, cloud, and hybrid environments. Implement Security by Design and Zero Trust practices. Define and implement security controls for Azure, OCI, and SaaS environments. Implement segmentation policies, system hardening, identity management, and workload protection. Work on Cloud Security Posture Management (CSPM) initiatives. Support application migration and modernization projects to the cloud. Implement encryption controls, sensitive data protection, and secret management. Support LGPD initiatives, information classification, and protection of health-related data (PHI). Define controls for data retention, disposal, masking, and anonymization. Integrate corporate platforms with SIEM. Build detection use cases. Develop correlations, security rules, and indicators. Support incident investigations and threat hunting activities. Preferably possess hands-on experience with the following technologies or equivalents: Google SecOps (SIEM) Microsoft Defender CrowdStrike CyberArk Netskope Gigamon Azure Key Vault Active Directory / Entra ID Corporate WAFs Check Point Forcepoint Requirements: Minimum of 5 years in Information Security. Experience in large-scale corporate environments. Experience in regulated environments (healthcare, financial, or insurance sectors is a plus). Application security (OWASP Top 10). DevSecOps. Cloud Security (Azure, AWS, or OCI). IAM, SSO, MFA, and Zero Trust. SIEM and security monitoring. Vulnerability management. Operating system and platform hardening. API security. Containers and Kubernetes. Cryptography and data protection. TCP/IP networking and security protocols. CISSP CCSP CISM CRISC CompTIA Security+ Microsoft Azure Security Engineer Associate (AZ-500) Microsoft Cybersecurity Architect (SC-100) Google Professional Cloud Security Engineer OCI Security Professional CCNP Security Check Point CCSA / CCSE * Behavioral Competencies: Ability to act consultatively with business units. Analytical and investigative mindset. Strong communication skills with both technical and executive teams. Ownership and accountability mindset. Ability to lead multidisciplinary projects. Risk-based prioritization capability. * Differentiators: Experience in healthcare environments and protection of health-related data (PHI). Participation in solution certification processes. Knowledge of NIST CSF, ISO 27001, CIS Controls, and MITRE ATT&CK. Experience conducting Security Assessments of vendors. Experience in Cloud Security and Zero Trust programs.
Posted by

João Silva
Indeed · HR






