
Senior Information Security Engineer
Posted Sep 29

Posted Sep 29
This is a fully remote position, open to applicants in Brazil.
• Act as a Senior Information Security Engineer
• Take independent charge of ISO 27001 compliance initiatives, encompassing audit preparations and certification upkeep
• Oversee and enhance security platforms, including SIEM, MDR, DLP, and IAM
• Direct vulnerability management efforts and manage penetration testing operations
• Evaluate security risks linked to third parties and AI tools, assuming responsibility for findings and recommendations
• Resolve intricate security challenges independently and achieve outcomes without close oversight
• Implement cloud security principles and utilize relevant tools
• Assess security risks specific to AI, such as data leakage, training models with customer data, API security, Shadow AI, and supply chain vulnerabilities
• Support the governance of AI tools with respect to the EU AI Act and ISO 42001
• Significant experience in information security, especially within enterprise or operational settings
• Proven track record of independently managing ISO 27001 compliance programs, including audit preparation and certification management
• Demonstrated ability in managing and optimizing security platforms like SIEM, MDR, DLP, and IAM
• Experience in leading vulnerability management initiatives and coordinating penetration testing efforts
• Familiarity with assessing security risks related to third parties and AI tools, with a clear sense of ownership over findings and recommendations
• History of autonomously addressing complex security issues and delivering effective results without close supervision
• Comprehensive understanding of cloud security principles and tools
• Strong practical knowledge of NIST, ISO 27001, CSA, GDPR, and UK data protection laws
• Solid practical insight into AI-specific security risks, including data leakage, training models with customer data, API security, Shadow AI risks, and supply chain vulnerabilities
• Practical awareness of the EU AI Act and its impact on AI tool governance within organizations
• Expertise in security testing methodologies, encompassing vulnerability scanning, penetration testing, and red teaming
• CISSP, CISM, or equivalent certification (preferred)
• Experience within a regulated industry or a compliance-focused environment (preferred)
• Knowledge of the governance requirements of ISO 42001 or the EU AI Act (preferred)
• The support you need to achieve professional success
• Collaborative and innovative work environment
Integrity360
Rackspace Technology
Efficient Computer
Presidio
Get handpicked remote jobs straight to your inbox weekly.