




Job Summary: We are seeking a Mid-level Information Security professional to structure and enhance our cybersecurity posture, with strategic involvement in defining guidelines and hands-on execution. Key Highlights: 1. Strategic participation in defining guidelines 2. Practical engagement with technical and management teams 3. Focus on increasingly secure and resilient environments We are expanding and looking for a Mid-level Information Security professional to support the structuring and evolution of cybersecurity at Arista Digital. This role will involve strategic participation in defining guidelines, as well as practical collaboration with technical and management teams, ensuring our environments become increasingly secure and resilient. **Responsibilities** * Implement and maintain information security policies, processes, and controls. * Support initiatives for compliance with the LGPD (data subject rights, data breaches, responsibilities). * Respond to customer and supplier security assessments. * Interpret penetration test reports and support vulnerability remediation. * Collaborate with the development team on DevSecOps practices. * Recommend security best practices for tokens, cryptography, anonymization, and environment segmentation. * Develop security architecture documentation (applications, data, networks, logs). * Conduct security and privacy awareness training. * Establish security log auditing and monitoring processes. * Lead incident response alongside the technical team and support business continuity planning. **Requirements** * Proven experience in Information Security or Cybersecurity (mid-level/senior). * Knowledge of frameworks such as ISO 27001, NIST, OWASP. * Experience with cloud security (AWS, GCP, or Azure). * Familiarity with DevSecOps, secure CI/CD, and vulnerability management. * Strong communication skills for interaction across diverse areas (end users, technical staff, and managers). **Preferred Qualifications** * Certifications such as ISO 27001, LGPD, CISSP, CISM, CompTIA Security\+. * Experience with SIEM, IAM, and monitoring tools. * Experience with incident response and business continuity.


