Chief Information Security Officer, CISO

Posted Sep 15

This is a fully remote position, open to applicants in Brazil.

📋 Description

• Define, execute, and continuously refine the corporate Information Security strategy.

• Lead and nurture Security Engineering, SOC, GRC, Application Security, Blue Team, and Red Team operations.

• Oversee Governance and Risk Management, including cyber risk evaluations and mitigation tracking.

• Ensure adherence to BACEN Resolution No. 4,893, LGPD, PCI DSS, ISO 27001, ISO 22301, and Open Finance standards.

• Supervise SOC capabilities for incident detection, response, containment, and recovery.

• Spearhead security initiatives across cloud environments, Zero Trust models, and critical infrastructure.

• Integrate DevSecOps, SAST, DAST, threat modeling, and secure code review throughout the software development lifecycle.

• Convey cybersecurity risks to the Board and C-level executives.

• Manage relationships with regulators, auditors, certification bodies, and key stakeholders.

• Design and sustain security awareness and cultural programs.

• Assess, choose, and oversee security vendors and strategic partners.

• Create, test, and enhance Business Continuity and Disaster Recovery Plans.


⛳️ Requirements

• Proven experience in Information Security and in executive or senior leadership roles.

• Background in fintechs, digital banks, financial institutions, or companies under the Central Bank of Brazil's regulation.

• Bachelor's degree in Computer Science, Engineering, Information Systems, or related fields.

• Expertise in cloud security, particularly AWS, and in highly available distributed architectures.

• In-depth knowledge of ISO 27001, NIST Cybersecurity Framework, CIS Controls, and MITRE ATT&CK.

• Hands-on experience with SOC operations, SIEM platforms, EDR, Threat Intelligence, and incident response.

• Strong grasp of DevSecOps, application security, SAST, DAST, and threat modeling.

• Technical proficiency to engage in architectural discussions with Engineering and Platform teams.

• Experience in securing APIs, microservices, and mission-critical digital ecosystems.

• Awareness of Generative AI risks, including Shadow AI, sensitive information leakage in LLMs, and prompt engineering-based attacks.

• Capability to establish policies, controls, and guidelines for the secure use of AI tools.

• Familiarity with AI/ML applications for fraud detection, behavioral analytics, and SOAR.

• Excellent communication skills with Boards, Executive Committees, auditors, regulators, and risk committees.

• Ability to influence decisions in matrix organizations and multidisciplinary teams.

• Demonstrated success in building, developing, and retaining high-performing technical teams.

• Competence in balancing security rigor, regulatory compliance, agility, and business growth.

• Practical knowledge of core financial domains such as lending, payments, credit cards, open finance, fraud prevention, merchant acquiring, or investment services is a plus.

• CISSP and CISM certifications are preferred.


🏝️ Benefits

• Competitive salary aligned with market standards.

• Remote work opportunities — wherever you are, you’re part of the team!

• Home office allowance provided through a monthly deposit in the RecargaPay app.

• Health and dental plans without co-pay.

• Life insurance coverage.

• Flexible meal allowance (via Flash).

• TotalPass membership to support your health and wellness.

People also viewed

WorkOS1 day ago

Product Security Engineer

US flagUnited States, +1 more countryFull-timeCybersecurity / Security Engineer$175k – $275k/year
ApplyView job
Fortive1 day ago

Information Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Brown and Caldwell1 day ago

Cybersecurity, OT-IT Security Consultant

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$129k – $212k/year
ApplyView job
Galileo1 day ago

IT and Security Generalist

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$110k – $120k/year
ApplyView job
Mercor1 day ago

Cybersecurity Practitioner – SOC, Incident Response, Detection, AppSec

US flagUnited States OnlyFreelanceCybersecurity / Security Engineer$125 – $175/hour
ApplyView job
Peek1 day ago

Security and Compliance Analyst

MX flagMexico OnlyFull-timeCybersecurity / Security Engineer$80k – $90k/month
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers