
Information Security Coordinator – AppSec
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Brazil.
• Oversee the daily operations of the team by delegating tasks based on seniority, monitoring deliveries, and eliminating technical and organizational obstacles.
• Act as a technical advisor and mentor, aiding in individual development plans and career advancement.
• Ensure management is kept informed about priorities, risks, and results.
• Convert the security roadmap into an actionable work plan that effectively balances governance, offensive security, and incident response.
• Establish, sustain, and enhance a controls program adhering to NIST CSF, NIST SP 800-53, and CIS Controls v8, facilitating audits and compliance.
• Coordinate and/or conduct penetration tests, red team activities, and threat hunting, assessing integrations with third-party services, APIs, attack surfaces, and both internal and external environments, while tracking remediation efforts.
• Assist engineering in embracing shift-left methodologies, security in CI/CD, IaC security, Cloudflare and AWS WAFs, containers, cloud platforms, and vulnerability management.
• Monitor performance indicators and assist in reporting to management.
• Operate CSPM (Wiz) and SAST/SCA pipelines to investigate exposed tokens, vulnerable APIs, and open buckets, providing telemetry for risk matrices.
• Plan and conduct tabletop exercises with technical and business teams.
• Consult with engineering, product, and business teams, steering discussions towards effective governance.
• Manage relationships with penetration testing partners and vendors by structuring schedules, scopes, and ensuring execution quality.
• Generate reports and metrics using Looker and data visualization tools, translating technical information into business implications and emphasizing critical risks.
• A bachelor’s degree in Technology, Information Security, Engineering, or a related discipline.
• 5–7 years of experience in information security in specialist, coordination, or similar positions.
• Experience in leading or coordinating technical personnel or teams.
• Demonstrated expertise in technical domains of Information Security, preferably in Yellow or Red Team roles.
• Proficient in NIST CSF, NIST SP 800-53, and/or CIS Controls v8.
• Experience in penetration testing, red team operations, vulnerability exploitation, and familiarity with MITRE ATT&CK.
• Independent proficiency with basic to intermediate SQL for auditing data lakes and databases, tracing privileges, hunting for PII, and identifying logical vulnerabilities.
• Hands-on experience with DevSecOps, CI/CD, SAST/DAST/SCA, IaC security, containers, and cloud platforms such as AWS/Azure/GCP.
• Experience in data discovery/classification and identifying PII in both relational and non-relational databases and BI tools, with an emphasis on LGPD (Brazilian data protection law).
• Familiarity with DLP and network/traffic posture, including Zscaler, proxies, or CASB.
• Knowledge of tools and frameworks addressing generative AI security risks, such as NIST AI and ISO 42001.
• Understanding of the strategic application of AI for automation, dashboards, and metric extraction.
• Experience in conducting or facilitating tabletop incident response exercises.
• A completed bachelor’s degree is essential; certifications such as CISSP, OSCP, CEH, GCIH, CRISC, or equivalents are advantageous.
• Food and/or meal voucher (Flash)
• SulAmérica health and dental plan
• Commuter allowance for on-site and hybrid positions
• Extended maternity and paternity leave
• Childcare assistance
• Partnerships with Wellhub and Zenklub for employee wellbeing and mental health
• Education assistance
• Discounts on airline tickets
• Partnership for pet health insurance
• Access to Arco educational materials for employees’ children
• Partnerships for MBA and postgraduate programs
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.