
Senior Security Engineer
Posted Jun 24

Posted Jun 24
This is a fully remote position, open to applicants in Brazil.
• Create and execute a strategic vision for information security that aligns with business goals, focusing on the continuous enhancement of processes and controls in the area.
• Oversee contracts, assets, and services associated with information security, ensuring they operate at peak efficiency.
• Establish information security standards and policies to safeguard information assets and facilitate business continuity.
• Ensure compliance with relevant regulations and adherence to industry best practices.
• Work in partnership with technology teams to define and implement effective security integration strategies throughout the development lifecycle, from design to operation.
• Analyze and respond to information security incidents, identify threats and vulnerabilities, and develop initiatives to prevent or mitigate them.
• Direct risk management, threat modeling, and impact assessments for new products, features, and partnerships.
• Spearhead a training and enablement program to cultivate a robust security culture throughout the organization.
• Assist with internal and external audits.
• Assess and track security KPIs, keeping leadership apprised of the maturity of the information security program.
• Address requests and support the provision of the company's ISMS information to clients and other stakeholders as necessary.
• Over 5 years of experience in leading information security projects, ideally within technology companies and startups.
• A strategic mindset, focused on data and risk, with an emphasis on business impact, risk management, and a practical approach.
• Experience performing ISO 27001 assessments.
• Strong expertise in cloud security, especially with GCP and AWS.
• Familiarity with information security standards, frameworks, and best practices, including application security testing (AST), NIST, CIS, ISO 27001, and OWASP.
• Background in secure development and understanding of security engineering.
• Knowledge of DevSecOps best practices and methodologies.
• Understanding of software development and coding.
• Experience in critical scenarios and supporting regulatory compliance (e.g., LGPD / ANPD).
• Health insurance
• Paid leave
• Training and professional development
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.