
Chief Information Security Officer, CISO
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in Brazil.
• Define, execute, and continuously refine the corporate Information Security strategy.
• Lead and nurture Security Engineering, SOC, GRC, Application Security, Blue Team, and Red Team operations.
• Oversee Governance and Risk Management, including cyber risk evaluations and mitigation tracking.
• Ensure adherence to BACEN Resolution No. 4,893, LGPD, PCI DSS, ISO 27001, ISO 22301, and Open Finance standards.
• Supervise SOC capabilities for incident detection, response, containment, and recovery.
• Spearhead security initiatives across cloud environments, Zero Trust models, and critical infrastructure.
• Integrate DevSecOps, SAST, DAST, threat modeling, and secure code review throughout the software development lifecycle.
• Convey cybersecurity risks to the Board and C-level executives.
• Manage relationships with regulators, auditors, certification bodies, and key stakeholders.
• Design and sustain security awareness and cultural programs.
• Assess, choose, and oversee security vendors and strategic partners.
• Create, test, and enhance Business Continuity and Disaster Recovery Plans.
• Proven experience in Information Security and in executive or senior leadership roles.
• Background in fintechs, digital banks, financial institutions, or companies under the Central Bank of Brazil's regulation.
• Bachelor's degree in Computer Science, Engineering, Information Systems, or related fields.
• Expertise in cloud security, particularly AWS, and in highly available distributed architectures.
• In-depth knowledge of ISO 27001, NIST Cybersecurity Framework, CIS Controls, and MITRE ATT&CK.
• Hands-on experience with SOC operations, SIEM platforms, EDR, Threat Intelligence, and incident response.
• Strong grasp of DevSecOps, application security, SAST, DAST, and threat modeling.
• Technical proficiency to engage in architectural discussions with Engineering and Platform teams.
• Experience in securing APIs, microservices, and mission-critical digital ecosystems.
• Awareness of Generative AI risks, including Shadow AI, sensitive information leakage in LLMs, and prompt engineering-based attacks.
• Capability to establish policies, controls, and guidelines for the secure use of AI tools.
• Familiarity with AI/ML applications for fraud detection, behavioral analytics, and SOAR.
• Excellent communication skills with Boards, Executive Committees, auditors, regulators, and risk committees.
• Ability to influence decisions in matrix organizations and multidisciplinary teams.
• Demonstrated success in building, developing, and retaining high-performing technical teams.
• Competence in balancing security rigor, regulatory compliance, agility, and business growth.
• Practical knowledge of core financial domains such as lending, payments, credit cards, open finance, fraud prevention, merchant acquiring, or investment services is a plus.
• CISSP and CISM certifications are preferred.
• Competitive salary aligned with market standards.
• Remote work opportunities — wherever you are, you’re part of the team!
• Home office allowance provided through a monthly deposit in the RecargaPay app.
• Health and dental plans without co-pay.
• Life insurance coverage.
• Flexible meal allowance (via Flash).
• TotalPass membership to support your health and wellness.
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.