
Information Security Coordinator
Posted Jul 30

Posted Jul 30
This is a fully remote position, open to applicants in Brazil.
• Establish and uphold policies, frameworks, risk appetite, and discipline metrics, ensuring they align with business goals.
• Take responsibility for the effectiveness of the control portfolio: IAM, EDR/NDR/IDS, DLP, encryption, hardening, and vulnerability management, delegating execution to operational teams and driving results.
• Ensure a robust incident response capability: manage the contracted SOC, maintain up-to-date playbooks, conduct periodic exercises, oversee crisis communication, and implement a lessons-learned cycle.
• Oversee technical compliance with LGPD (Brazilian Data Protection Law): legal bases, consent, DPIA (Data Protection Impact Assessment), managing data subject rights, and data retention, acting as the liaison with the CISO/DPO.
• Ensure due diligence and security clauses with vendors and promote secure development practices (SAST/DAST, DevSecOps, API security) in collaboration with the Information Security Architecture function.
• Develop a training program, conduct phishing drills, and launch awareness campaigns, utilizing behavioral metrics to demonstrate progress in security culture.
• Define security and privacy requirements, standards, and acceptance criteria that the organization must adhere to, ensuring their application in projects alongside the Information Security Architecture function.
• Manage certifications and audits (ISO 27001 and ISO 27701, when applicable), ensuring timely evidence and remediations with support from operational teams.
• Plan and oversee the discipline's budget: partner contracts, tools, training, and projects, prioritizing based on risk and return.
• Be accountable at the executive level for SOC/CSIRT and MSS contracts (renewals, scope, penalties), backed by the technical governance provided by the Advanced Support & Continuous Improvement function.
• Bachelor's degree in Information Security, Information Technology, Information Systems, Computer Science, Computer Engineering, or related fields.
• Extensive experience in Technology, particularly in Information Security and in leadership or coordination roles managing teams and consultancies/vendors.
• Comprehensive experience across the discipline: governance, security operations, IAM, incident response, privacy/LGPD, and compliance.
• Experience in managing security contracts and vendors (SOC, CSIRT, MSS).
• Familiarity with audits and certifications (ISO 27001; ISO 27701 desirable) and frameworks such as NIST CSF and CIS Controls.
• Proficient in budget management and prioritizing investments based on risk.
• Mature executive-level communication skills: reporting to the board, participating in committees, and interfacing with the CISO/DPO.
• Postgraduate degree or specialization in Information Security, Cybersecurity, IT Governance, Risk Management, or related areas (desirable).
• Certifications: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, CDPO, or equivalents (desirable).
• Previous experience in hybrid operational structures (lean internal team + partners) (desirable).
• Familiarity with the EOS method (L10, scorecard, rocks) or similar management models (desirable).
• Experience securing cloud and hybrid environments (desirable).
• Meal or Food Allowance – to keep you energized.
• Medical and Dental Coverage – because health is a priority.
• Life Insurance – for your security and peace of mind.
• Birthday Day Off – to enjoy your special day.
• Profit Sharing – if the company earns, you earn too!
• Transportation Voucher – to commute to the office.
• Holiday Bonus – a special year-end bonus to help with holiday expenses.
• Zenklub – supporting mental and emotional health, including consultations with nutritionists.
• Wellhub – to balance body and mind with physical activities.
• OnHappy – to enjoy weekends, holidays, or vacation time!
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.