
Information Security Architecture
Posted Sep 4

Posted Sep 4
This is a fully remote position, open to applicants in Brazil.
• Develop and execute security architectures leveraging Defense in Depth and Zero Trust principles.
• Evaluate the risks associated with new integrations, hybrid settings, multicloud scenarios, and SaaS offerings; provide technical assessments and document remaining risks.
• Lead threat modeling initiatives utilizing STRIDE, DREAD, OWASP Top 10, and MITRE ATT&CK frameworks.
• Ensure the integration of Security by Design and Privacy by Design throughout the software development lifecycle.
• Design and audit Identity Access Management (IAM) and Privileged Access Management (PAM) solutions, encompassing SSO, MFA, OIDC, SAML 2.0, RBAC, and secure credential management strategies.
• Validate DevSecOps practices and incorporate SAST, DAST, SCA, Infrastructure as Code (IaC) Security, and Secrets Detection controls within CI/CD pipelines.
• Establish encryption standards for data both in transit and at rest, while supporting Hardware Security Module (HSM) processes and cryptographic key management.
• Ensure adherence to Brazil’s LGPD, Banking Secrecy laws, PCI DSS, and regulations from the Central Bank of Brazil, including CMN Resolution 4,893, BCB Resolution 85, and CMN Resolution 5,274.
• Act as the technical lead for impact assessments, access management, penetration testing, and security evaluations.
• Authorize systemic cybersecurity risks.
• Collaborate with technical and business teams to influence pivotal information security decisions.
• Proficiency in Zero Trust Security Frameworks and Architecture (NIST SP 800-207).
• Familiarity with NIST SP 800-53.
• Knowledge of OWASP ASVS 4.0, MASVS, MASTG, and API Security Top 10.
• Understanding of CIS Controls.
• Expertise in Application Security Architecture.
• Experience in Vulnerability Management.
• Proficiency with CrowdStrike Falcon, Trend Micro Vision One, and QualysGuard.
• Familiarity with IBM Security Guardium and Securiti.ai.
• Experience with CyberArk, BeyondTrust, and Keycloak.
• Knowledge of Guardsquare (DexGuard, iXGuard, ThreatCast) and MobSF.
• Familiarity with Palo Alto NGFW, Prisma Access, Zscaler, Cloudflare WAF, and Apigee X.
• Proficiency with MITRE Caldera, Burp Suite Professional, Cobalt Strike, MISP, Shodan, and ANY.RUN.
• Experience with Microsoft Entra ID, Entra Connect, and Intune.
• Familiarity with Splunk, Splunk Enterprise Security, and Wazuh.
• Relevant information security certifications and knowledge aligned with the position's requirements.
• Ability to work remotely while being employed under Brazil’s CLT regime.
• Flexible benefits card – choose how and where to use it.
• Scholarships for undergraduate, graduate, MBA, and language courses.
• Certification incentive programs.
• Flexible working hours.
• Competitive salaries.
• Annual performance evaluations with a structured career development plan.
• Opportunities for international career advancement.
• Wellhub and TotalPass.
• Private pension plan.
• Childcare assistance.
• Medical insurance.
• Dental insurance.
• Life insurance.
• A safe, diverse, and inclusive workplace.
• A culture of development and growth fostered by Continuous Scaled Learning.
CrowdStrike
Triumph Enterprises, Inc.
LaunchDarkly
Staffbase
Get handpicked remote jobs straight to your inbox weekly.