83 Empregos para Cism - Brasil
Information Security Manager
Publicado há 2 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Information Security Manager
We are one of the largest technology-driven Audit, Consulting, Tax, Strategy, and Transaction services in the world. With a presence in over 150 countries, here you will have the opportunity to experience exceptional experiences that only EY can offer, with global reach, an inclusive culture, and technology to become your best version.
Are you seeking a position that allows you to demonstrate your skills, experience, and ability to solve complex problems in information security? This position is an opportunity to embed information security in a strategic investment by the EY Tax practice, aimed at enabling innovation and disruptive new services.
#TechEY
Technology is at the heart of what we do and deliver at EY. EY All In global strategies are powered by multi-cloud capabilities, bringing the latest technical capabilities to EY internal and external clients. In doing so, we are empowering teams to execute locally by globally enabling them with a strong technology core. Our business has just embarked on an ambitious growth strategy, and the EY Global Information Security team is looking to hire a resource based in São Paulo, Brazil, to support that growth. The EY Global Information Security team helps clients harness the power of emerging technologies and is expanding its global footprint. The Super Regions (Canada and LATAM) align client needs and innovative ideas with existing platforms, capabilities, and technology expertise to provide new technology solutions. Working closely with our client engagement teams in Canada and LATAM and with our technologists across the world, the EY security consulting practice supports digitally-enabled services that take advantage of leading technologies in concert with EY’s broad industry-specific experience and professional services knowledge. This allows clients to fundamentally re-imagine their Digital Practices throughout their business process lifecycles. The EY InfoSec Consulting team helps EY and their clients improve the efficiency of their business functions through new security tools and capabilities. In addition, you will represent the best of EY’s technology and thinking in our global technology team.
Skills and Attributes for Success
Significant working security experience and knowledge in the design, implementation, and operation of security controls in one of the following areas:
• Agile & DevOps Methodologies – Experience as a contributing member of a balanced team within an Agile development or DevOps environment;
• Application Security - Experience with the design of security controls for multi-tier business solutions, including the design of application-level access and entitlement management, data tenancy and isolation, encryption, and logging. Working familiarity with REST API and microservices architecture;
• Cloud Security – Technical understanding of virtualization, cloud infrastructure, and public cloud offerings, as well as experience designing security configuration and controls within cloud-based solutions in Microsoft Azure, Google GCP, Amazon AWS, and other vendors;
• Infrastructure Security – Experience with the integration of common infrastructure security technologies and solutions into business solution architectures, including the integration of identity & access management, intrusion detection and prevention, security monitoring, and data encryption solutions;
• Identity and Access Management - Experience in design and integration of identity and access management based on Active Directory and Federation technologies.
To qualify for the role, you must have experience in
Extensive experience in implementing, advising on, and consulting about security configurations across complex IT architectures, including cloud environments (primarily Microsoft's, but also including a range of IaaS, PaaS, and SaaS offerings from multiple vendors) and on-premises solutions. In-depth knowledge of IT system architecture concepts and cloud technologies, along with associated technologies such as Identity and Access Management (IAM), network security, firewalls, software development best practices, systems auditing, system hardening, and other security principles as outlined in ISO27001, OWASP, and related security standards. Proficiency in interpreting security reports (SAST and DAST) and testing outcomes for applications, providing advice on necessary corrections and security measures based on policies and non-functional requirements. A degree in Computer Science or a related field. Excellent communication skills, fluency in English (knowledge of Spanish is an advantage), and the ability to collaborate with stakeholders ranging from developers and architects to business leaders and EY's clients.
Ideally, you’ll also have
It is preferred that candidates possess additional working security experience and knowledge in one or more of the following areas:
• Operational Security – Experience in defining operational models and procedures for business solutions, including the operation and maintenance of infrastructure and application security controls.
• Information Security Standards – Knowledge of common information security standards such as: ISO 27001/27002, NIST CSF, FEDRAMP, CSA, and CIS Controls.
• Cloud security certifications such as AZ-300 Azure Architect Technologies.
• Product Management – Working with a broader business team on aspects of security that affect all phases, from concept to design to implementation and then operational support.
What we look for
We are looking for a leader with a passion for information security and the ability to apply their knowledge to new and emerging technologies that are supporting the growth strategy of a global professional services firm.
Requirements:
· Advanced degree in Computer Science or a related discipline, or equivalent work experience;
· Professional certifications such as CISSP, CCSP, CISM, or equivalent security certifications;
· Fluent in English and Spanish.
· Certifications: CISSP, CCS, CISM, or similar;
· Although not required, it is preferred that candidates possess additional working security experience and knowledge in one or more of the following areas:
· Previous working experience in Big 4 or big consulting firms;
· Operational Security – Experience;
· Occasional travel.
Key Responsibilities:
· This position is a leading role in designing, developing, and accessing all aspects of security for market-leading regional and global systems based primarily on Cloud technologies. As a security consultant for the regions, you will be an individual contributor capable of supporting multiple project teams operating in the latest technologies of Cloud-based, Agile developed systems, using automated deployment from CI/CD pipelines. In other words, it is not just an audit or oversight role, but one that requires detailed participation in the design, implementation, and certification of security controls across solutions. This requires knowledge of various IT system architecture and Cloud technology, as well as supporting technologies such as IAM, network security, AI, user account management, audit and logging, and other security concepts as outlined in ISO27001/2, OWASP, and related regional security standards. Also, the successful candidate should have knowledge of 3rd party security assessments and applicability of SOC2 and SOC2 reports, and concepts of vendor risk management.
#J-18808-LjbffrInformation Security Manager
Publicado há 2 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Information Security Manager
We are one of the largest technology-driven Audit, Consulting, Tax, Strategy, and Transaction services in the world. With a presence in over 150 countries, here you will have the opportunity to experience exceptional experiences that only EY can offer, with global reach, an inclusive culture, and technology to become your best version.
Are you seeking a position that allows you to demonstrate your skills, experience, and ability to solve complex problems in information security? This position is an opportunity to embed information security in a strategic investment by the EY Tax practice, aimed at enabling innovation and disruptive new services.
#TechEY
Technology is at the heart of what we do and deliver at EY. EY All In global strategies are powered by multi-cloud capabilities, bringing the latest technical capabilities to EY internal and external clients. In doing so, we are empowering teams to execute locally by globally enabling them with a strong technology core. Our business has just embarked on an ambitious growth strategy, and the EY Global Information Security team is looking to hire a resource based in São Paulo, Brazil, to support that growth. The EY Global Information Security team helps clients harness the power of emerging technologies and is expanding its global footprint. The Super Regions (Canada and LATAM) align client needs and innovative ideas with existing platforms, capabilities, and technology expertise to provide new technology solutions. Working closely with our client engagement teams in Canada and LATAM and with our technologists across the world, the EY security consulting practice supports digitally-enabled services that take advantage of leading technologies in concert with EY’s broad industry-specific experience and professional services knowledge. This allows clients to fundamentally re-imagine their Digital Practices throughout their business process lifecycles. The EY InfoSec Consulting team helps EY and their clients improve the efficiency of their business functions through new security tools and capabilities. In addition, you will represent the best of EY’s technology and thinking in our global technology team.
Skills and Attributes for Success
Significant working security experience and knowledge in the design, implementation, and operation of security controls in one of the following areas:
• Agile & DevOps Methodologies – Experience as a contributing member of a balanced team within an Agile development or DevOps environment;
• Application Security - Experience with the design of security controls for multi-tier business solutions, including the design of application-level access and entitlement management, data tenancy and isolation, encryption, and logging. Working familiarity with REST API and microservices architecture;
• Cloud Security – Technical understanding of virtualization, cloud infrastructure, and public cloud offerings, as well as experience designing security configuration and controls within cloud-based solutions in Microsoft Azure, Google GCP, Amazon AWS, and other vendors;
• Infrastructure Security – Experience with the integration of common infrastructure security technologies and solutions into business solution architectures, including the integration of identity & access management, intrusion detection and prevention, security monitoring, and data encryption solutions;
• Identity and Access Management - Experience in design and integration of identity and access management based on Active Directory and Federation technologies.
To qualify for the role, you must have experience in
Extensive experience in implementing, advising on, and consulting about security configurations across complex IT architectures, including cloud environments (primarily Microsoft's, but also including a range of IaaS, PaaS, and SaaS offerings from multiple vendors) and on-premises solutions. In-depth knowledge of IT system architecture concepts and cloud technologies, along with associated technologies such as Identity and Access Management (IAM), network security, firewalls, software development best practices, systems auditing, system hardening, and other security principles as outlined in ISO27001, OWASP, and related security standards. Proficiency in interpreting security reports (SAST and DAST) and testing outcomes for applications, providing advice on necessary corrections and security measures based on policies and non-functional requirements. A degree in Computer Science or a related field. Excellent communication skills, fluency in English (knowledge of Spanish is an advantage), and the ability to collaborate with stakeholders ranging from developers and architects to business leaders and EY's clients.
Ideally, you’ll also have
It is preferred that candidates possess additional working security experience and knowledge in one or more of the following areas:
• Operational Security – Experience in defining operational models and procedures for business solutions, including the operation and maintenance of infrastructure and application security controls.
• Information Security Standards – Knowledge of common information security standards such as: ISO 27001/27002, NIST CSF, FEDRAMP, CSA, and CIS Controls.
• Cloud security certifications such as AZ-300 Azure Architect Technologies.
• Product Management – Working with a broader business team on aspects of security that affect all phases, from concept to design to implementation and then operational support.
What we look for
We are looking for a leader with a passion for information security and the ability to apply their knowledge to new and emerging technologies that are supporting the growth strategy of a global professional services firm.
Requirements:
· Advanced degree in Computer Science or a related discipline, or equivalent work experience;
· Professional certifications such as CISSP, CCSP, CISM, or equivalent security certifications;
· Fluent in English and Spanish.
Desirable:
· Certifications: CISSP, CCS, CISM, or similar;
· Although not required, it is preferred that candidates possess additional working security experience and knowledge in one or more of the following areas:
· Previous working experience in Big 4 or big consulting firms;
· Operational Security – Experience;
· Occasional travel.
Key Responsibilities:
· This position is a leading role in designing, developing, and accessing all aspects of security for market-leading regional and global systems based primarily on Cloud technologies. As a security consultant for the regions, you will be an individual contributor capable of supporting multiple project teams operating in the latest technologies of Cloud-based, Agile developed systems, using automated deployment from CI/CD pipelines. In other words, it is not just an audit or oversight role, but one that requires detailed participation in the design, implementation, and certification of security controls across solutions. This requires knowledge of various IT system architecture and Cloud technology, as well as supporting technologies such as IAM, network security, AI, user account management, audit and logging, and other security concepts as outlined in ISO27001/2, OWASP, and related regional security standards. Also, the successful candidate should have knowledge of 3rd party security assessments and applicability of SOC2 and SOC2 reports, and concepts of vendor risk management.
#J-18808-LjbffrInformation Security Manager
Publicado há 11 dias atrás
Trabalho visualizado
Descrição Do Trabalho
O EBANX é uma fintech global fundada em 2012 com a missão de ser o principal parceiro de pagamentos em mercados em ascensão. Com tecnologia e infraestrutura própria, aliadas a um profundo conhecimento sobre o mercado da América Latina, o EBANX permite que essas empresas se conectem a centenas de métodos de pagamento em diferentes países da região. E vai além, criando resultados para as empresas e experiências de compra simples para os consumidores.
Desde o início da nossa jornada, temos uma importante missão: dar acesso. E isso não diz respeito apenas aos nossos produtos e serviços, mas atravessa tudo aquilo que somos e fazemos. Acreditamos que só é possível inovar com a diversidade, por isso valorizamos diferenças de gênero, raça, nacionalidade, deficiência, orientação sexual, religião e idade. A pluralidade é o que torna o nosso Sonho Grande possível.
Nós somos os ebankers e nós estamos mudando a maneira como as pessoas compram, se conectam e vivem globalmente. Topa fazer história com a gente?
Como Gerente de Segurança da Informação sua missão será de desenvolver e implementar políticas, metodologias e controles de Segurança da Informação .
Você também será responsável por:
- Liderar o time de Infosec, buscando o desenvolvimento dos ebankers;
- Conduzir e aprimorar nosso Sistema de Gestão de Segurança da Informação;
- Manter e garantir nossas certificações incluindo PCI-DSS e ISO 27001;
- Conduzir o gerenciamento de privacidade dentro da área de Segurança da Informação e em sinergia com as demais áreas da empresa;
- Garantir a correta conscientização dos ebankers em Segurança e Privacidade com melhoria continua do processo estabelecido;
- Gerenciar KPIs e métricas de Segurança da Informação;
- Prover através dos corretos frameworks a medição de maturidade de segurança, bem como acompanhar os planos para evolução destes indicadores;
- Atuar em conjunto com todas as áreas da empresa entendendo suas necessidades e endereçando pontos de segurança.
Principais requisitos da posição:
- Experiência em gestão de projetos, com habilidade de planejar, gerenciar e manter projetos complexos que atinjam diversas áreas da companhia;
- Conhecimento da família de padrões ISO / IEC 27000, PCI-DSS e BACEN;
- Conhecimento em COBIT e NIST SP 800;
- Conhecimento em riscos de Segurança da Informação;
- Experiencia anterior em liderança e formação de times;
- Inglês avançado (leitura, escrita e fala).
- Orientação a resultados;
- Certificações em Segurança;
- Espanhol.
O que o EBANX oferece:
- Um ambiente super desafiador e com muitas oportunidades de crescimento;
- Escritório casual, e um dress code flexível;
- Aulas de Espanhol, Inglês e Português (para não nativos);
- WAVES: Programa de metas e resultados;
- EBANX Play – Programas de Saúde (Gympass, e-Sports, SESC);
- Jornada semi flexível (8 horas por dia, de segunda a sexta-feira);
- Vale-refeição/Vale-alimentação;
- Vale transporte se necessário;
- EBANX Education: Possibilidade de auxílio financeiro na graduação e pós graduação;
- EBANX Skills: Possibilidade de fazer cursos e treinamentos ligados com a área de atuação;
- EBANX Flexible: Day Off dos meses de fevereiro a novembro, Birthday Day Off e Rest up month, um mês de licença remunerada a cada três anos de EBANX.
- EBANX Family: Auxílio creche, licença estendida aos cuidadores e programa de apoio a gestantes e crianças;
- EBANX Health: Plano de Saúde e Plano Dental (SulAmérica), com subsídio para dependentes, e subsídio de medicamentos para ebankers;
- Seguro de Vida: Seguro de Vida 100% custeado pelo EBANX
- Hello ebanker: Orientações psicológicas, legais ou financeiras;
- Blue Club: Descontos exclusivos para ebankers em panificadoras, restaurantes, cursos, lojas e mais!
Information Technology Security Manager
Ontem
Trabalho visualizado
Descrição Do Trabalho
Atividades:
Buscamos alguém com experiência consolidada em gestão de infraestrutura, segurança cibernética e coordenação de equipes.
Principais responsabilidades: Liderar projetos de TI, garantindo qualidade, prazo e alinhamento com as prioridades do negócio.
Planejar e executar estratégias de segurança da informação, com foco em proteção de dados e compliance.
Supervisionar infraestrutura — servidores, redes, cloud — com visão de escalabilidade e alta disponibilidade.
Gerenciar fornecedores e prestadores de serviços de TI.
Ser um elo entre a TI e demais áreas, facilitando comunicação e cultura digital.
Requisitos obrigatórios: Experiência comprovada como gestor de TI ou segurança da informação (como no perfil buscado).
Sólido conhecimento em frameworks de segurança (ISO 27001, NIST, etc.
).
Habilidade em arquiteturas cloud (AWS, Azure ou GCP).
Comunicação clara para interlocução com executivos e stakeholders.
Inglês avançado (leitura e conversação técnica).
Diferenciais desejáveis: Certificações como CISSP, CISM, CRISC ou similares.
Experiência em ambiente regulamentado (financeiro, saúde, consultorias globais).
Experiência prévia em NGOs ou think-tanks internacionais seria um plus.
Come be Magenta!
Dias da Semana: Não Informado
Horário / Período: Não Informado
Os interessados devem se candidatar através do portal Caderno Nacional #J-18808-Ljbffr
Sr. Manager, Business Information Security Officer (BISO)
Publicado há 14 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Job Title:
Sr. Manager, Business Information Security Officer (BISO)Job Description
Concentrix Corporation is seeking a Brazil Business Information Security Officer to join the Global Security team reporting to the CNX MET GEO Business Information Security Officer – Insider Risk and Compliance team.The Brazil Business Information Security Officer (BISO) focuses on proactively identifying security and compliance issues/risks to business operation processes in various accounts, drives in executing the controls to deter, detect and mitigate security and insider risks - including establishing capability and mechanisms to monitor and audit information and data protection of both Concentrix and clients as well as compliance level of each process and relevant control item as deployed in the operational environment, The country BISO drives proactively to enhance the fraud and compliance prevention culture and risk-free environment in Concentrix as well as identifies issues that would include but not limited to physical and logical security, data privacy, KPI, CSAT, inbound/outbound calls manipulation, information leakage, etc. impacting business. Typical activities include but are not limited to Risk Management – risk identification, risk assessments, support in development of risk action plans, risk closures, supporting investigations - case documentation, written first-hand reports, involve in-person or remote interview of persons of interest and working outside normal business hours etc., Governance and metrics, Executive presentations, Collaboration with all teams/ departments. Achieves results through direct interaction as well as influencing other internal groups or persons to achieve results.
Qualifications:
• 7 to 10 years of experience working in risk and compliance management, internal security controls, internal/external security assessment or audit, internal or cyber incident investigations.
Advanced English Level is a MUST, Spanish will be a plus
• Bachelor's/ Masters’ Degree in Information Technology or relevant areas.
• CISA certified or willing/able to certify within 12 months of employment.
• Experience in the BPO industry working in quality, security compliance or delivery strongly preferred.
• Deep understanding of BPO Business Operation and CRM services delivery processes.
• Understanding fraud, process non-compliance and incident investigations as well as various risks in the BPO industry.
• Ability to identify performance and opportunity gaps.
• Detail oriented with excellent analytical and critical thinking skills.
• Ability to effectively communicate findings to senior team members with appropriate recommendation and action plan raised to address the gaps in an effective & efficient manner.
BISO Responsibilities:
• Drive the highest Integrity and Ethical standards across the staff and the accounts in scope.
• Provide governance to operations management team and Quality Assurance team for effective and efficient surveillance and monitoring towards pro-active security and business process non-compliance issue identification.
• Collaborate with respective supporting functions/departments (IT, HR, Facility, Legal, DPO, etc.) to address relevant security issues/risks.
• Perform internal audit/assessment on regular basis based on different business process compliance management and risk control mechanisms in different accounts to ensure the full compliance as per relevant standard and identify potential issues/risks.
• Work closely with the operation team to get all identified non-compliance items fixed in a timely manner to drive for closure and proactively propose and deploy extra preventive controls where appropriate.
• Establish and execute a robust methodology for periodic reviews aiming to highlight the gaps that exist in the operational processes.
o Analyze operational data to identify trends, root causes of business issues, and/or opportunities.
o Provide recommendations for corrective and preventive actions and suggest improvements to the processes.
o Review and report the results and present to management team.
• Ensure partnership with accounts management team for Proactive Compliance Risk Management – identification, assessment, risk action planning, and closures.
• Coordinate and support Global Security Assessments (GSAs) - a holistic assessment (technology, HR, operations, finance, etc.) of risks being faced by delivery operations and No Notice Inspections (NNIs) conducted against the specific accounts in scope.
• Participate and involve in assigned investigations.
• Conduct incidents analytics for assigned areas within the defined timelines.
• Drive incidents to closure in a timely manner as required.
• Document learnings from incidents and circulate to relevant stakeholders Work with Client Risk Control Team directly as the security SPOC from CNX.
• Conduct employee awareness and assist in developing training materials and where necessary assist in specific training.
Accountability:
• Ensure the security and business process compliance in various accounts to meet business and client expectation.
• Continuously improve the compliance level driven by operational requirement and business growth.
• Partner/support the country BISO with the completion of various security programs/initiatives in the concerned accounts driven by Insider Risk and Compliance team, including but not limited to the GSA and NNI.
• Monitor assigned areas of risk ownership ensuring closures are tracked and presented to required stakeholders.
• Lead and manage the internal review work to achieve the efficiency, effectiveness, and timeliness.
• Establish governance and cadence as enforced per guidelines.
• Ensure assigned education sessions are conducted in a timely manner.
Location:
BRA SAO PAULO Rua Tagipuru, 906 Barra FundaLanguage Requirements:
Time Type:
Full time2025-09-30If you are a California resident, by submitting your information, you acknowledge that you have read and have access to the Job Applicant Privacy Notice for California Residents
#J-18808-LjbffrInformation Security Engineer
Publicado há 7 dias atrás
Trabalho visualizado
Descrição Do Trabalho
4 days ago Be among the first 25 applicants
Array Technologies, Inc. is a global leader in solar energy solutions – and we have been for over 30 years! Our dramatic growth is creating incredible opportunities on our dynamic, innovative and
creative team. Are you self-motivated, highly-skilled and possess previous Cyber Security / Information Security experience?
Would you love to play a key role in advancing the clean energy revolution? Join the company that is leading the way!
What you’ll do:
The engineer will be a key member in maturing the IT and OT Security organization. They will be part of a global security team that provides support for all areas of Information Security. A successful candidate will have experience with and/or strong interest in becoming a subject matter expert in multiple Security disciplines. These include Zero Trust Architecture, Application and Cloud Security, IAM and/or Data Protection/DLP. Additionally, the engineer will be a point of escalation for investigating and remediating potential threats. The engineer will continuously be apprised of emerging technologies, threats, attacks, and countermeasures and recommend enhancements based on industry best practices. You will:
- Design, document, test, maintain, and provide issue resolution recommendations for security solutions related to Zero Trust tools, secure software development, cloud, access, authentication/directory services, email, and/or endpoint security.
- Work with various departments to design, implementation, and maintain IAM policy.
- Contribute to the development and maintenance of Zero Trust Architecture and SASE tools.
- Partner with Dev teams to define, execute, and continuously improve our secure software development processes.
- Partner with IT and Product teams to assess, document and develop Cloud Security best practices.
- Participates in security incident response activities, conducts technical investigation of security-related incidents and conducts post-incident digital forensics to identify causes and recommend future mitigation strategies.
- Identifies security vulnerabilities/issues, performs risk assessments, and evaluates remediation alternatives.
- Contributes to the development and maintenance of information security architecture.
- Collaborates with other IT teams such as infrastructure and application development in the protection of the company’s IT assets including network, servers, applications, and 3rd party service providers.
- Contributes to the development of ongoing information security policies and procedures, and ensures such policies and procedures are put into practice in the day-to-day operations of the company’s technology environment.
The qualifications you must have:
- Some Experience with IAM, SASE, SSDLC, SIEM/SOAR, EDR, EPP
- Knowledge of Cybersecurity architectures and methodologies (OWASP, Github Advanced Security, Azure DevOps, Zero Trust, NIST, Defense in depth, Kill-Chain, etc.)
- Knowledge of Secure Cloud Architecture, Vulnerability Management, and Incident Response
- Familiar with Data Loss Prevention (DLP), Data Protection, and Disaster Recovery
- Familiar with network/security (IDS/IPS, firewalls, DNS, DHCP)
- Technical knowledge of Microsoft and Linux
Our preferred qualifications:
- Cyber Security certifications.
- 5-10 years of IT industry experience with 3-5 years of those in a role directly related to information security and IT compliance disciplines such as app security, cloud security, IAM, DLP, SASE, etc.
- Strong subject matter expertise in one or more of technical disciplines such as IT infrastructure, applications development and/or information security.
- Familiarity with information security disciplines such as privacy protection and data loss prevention.
- Strong experience in managing cybersecurity incidents and event response.
- Awareness of industry standards such as ISO, NIST as they relate to information security and protection of privacy.
- Experience with NERC-CIP standard and polices a plus.
- Experienced in executing privacy compliance initiatives in response to global privacy regulations such as GDPR and LGPD would be an asset.
- Knowledge of national and international regulatory compliances and frameworks such as ISO, NIST, and SOX.
Array Technologies, Inc. offers equal employment opportunity without regard to race, color, gender, age, creed, sex, religion, national origin, disability (physical or mental), marital status, citizenship, ancestry, sexual orientation, gender identity and gender expression, or any other legally protected status.
Seniority level- Seniority level Associate
- Employment type Full-time
- Job function Engineering and Information Technology
- Industries Renewable Energy Equipment Manufacturing
Referrals increase your chances of interviewing at Array Technologies by 2x
Cyber Security Analyst Junior (SOC) - Campinas/SPWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrInformation Security Analyst
Publicado há 11 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Sobre Moray:
A Moray nasceu com a missão de revolucionar o manejo das culturas agrícolas, reduzindo o uso de insumos e as perdas de produtividade, da planta individual à fazenda inteira. Nos inspiramos nas práticas agrícolas do Império Inca, que já há mil anos operavam com inteligência planta a planta. Hoje, unimos ciência, dados e robótica a um compromisso simples e poderoso: fazer bem-feito, com quem vive o campo.
Sobre Moray:
A Moray nasceu com a missão de revolucionar o manejo das culturas agrícolas, reduzindo o uso de insumos e as perdas de produtividade, da planta individual à fazenda inteira. Nos inspiramos nas práticas agrícolas do Império Inca, que já há mil anos operavam com inteligência planta a planta. Hoje, unimos ciência, dados e robótica a um compromisso simples e poderoso: fazer bem-feito, com quem vive o campo.
Nossas soluções otimizam o manejo no campo com precisão, sustentabilidade e impacto real.
Desde o início, contamos com a SLC Agrícola como cliente-âncora e parceira estratégica. Essa parceria moldou nosso jeito de trabalhar: com consistência, respeito e entrega de valor real.
Como Information Security Analyst, você vai:
- Auxiliar na implementação e evolução de controles de segurança baseados em uma adaptação do framework CIS Controls, adaptando-os à realidade da empresa;
- Avaliar riscos e propor soluções práticas e escaláveis para mitigar vulnerabilidades;
- Apoiar a definição e implementação de políticas e procedimentos de segurança para criar a postura de segurança da companhia;
- Realizar hardening de sistemas Linux e componentes de infraestrutura em nuvem e on-premisses;
- Trabalhar na proteção e monitoramento do ambiente AWS (IAM, S3, EC2, VPC, CloudTrail, etc.);
- Colaborar na configuração e manutenção de controles de segurança no Microsoft 365, Atlassian e Entra ID (antigo Azure AD);
- Trabalhar na definição e principalmente implantação de estratégias de backup, resposta a incidentes e continuidade de negócios;
- Participar da análise e implantação de ferramentas de SIEM e automação de segurança;
- Apoiar auditorias internas e externas e auxiliar na resposta a questionários de segurança de clientes, quando necessário.
- Experiência anterior em segurança da informação, especialmente com foco em ambientes cloud e sistemas Linux;
- Conhecimento dos principais conceitos do framework CIS Controls e/ou NIST;
- Experiência prática com AWS (IAM, S3, EC2, CloudTrail, Security Hub, GuardDuty, etc.);
- Familiaridade com Microsoft 365, Entra ID e seus recursos de segurança e compliance;
- Domínio de sistemas operacionais Linux (hardening, logs, firewall, usuários);
- Conhecimento de redes e protocolos (TCP/IP, DNS, VPNs, VLANs e VPN);
- Capacidade de redigir documentos técnicos, políticas e procedimentos;
- Perfil analítico, proativo, com boa comunicação e organização.
- Experiência em ambientes híbridos (cloud + on-premises);
- Conhecimento ou experiência em SIEM open source;
- Familiaridade com práticas de DevSecOps e automação de segurança.
- Remoto com disponibilidade para eventuais visitas ao datacenter (colocation);
- Disponibilidade para viajar.
Get notified about new Information Security Analyst jobs in São Paulo, São Paulo, Brazil .
Analista de Segurança da Informação Jr. (Blue Team/Resposta a Incidentes) Analista de Segurança da Informação Júnior Programa de Talentos da Redbelt Security - #RedTalent Assistente de Segurança da Informação (Cultura e Conscientização) Analista de Segurança da Informação Junior | SOC Analista de Segurança da Informação Pleno Analista de Segurança da Informação - N1 Analista de Segurança da Informação Jr (AppSec) Analista de Segurança da Informação - N2 Analista de Segurança da Informação Junior | MSS Banco de Talentos - Estágio em Segurança da Informação Analista de Segurança da Informação Pleno Pessoa Estagiária | Tecnologia - Security Project Analista de Segurança da Informação (Gestão de Vulnerabilidades) Analista de Segurança da Informação/Gestão de Acessos Analista de Segurança da Informação Sênior - Conscientização Analista de Segurança da Informação Junior - SP #J-18808-LjbffrSeja o primeiro a saber
Sobre o mais recente Cism Empregos em Brasil !
Information Security Specialist
Publicado há 11 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Join to apply for the Information Security Specialist role at DNV
3 days ago Be among the first 25 applicants
Join to apply for the Information Security Specialist role at DNV
Get AI-powered advice on this job and more exclusive features.
About Us
We are the independent expert in assurance and risk management. Driven by our purpose, to safeguard life, property, and the environment, we empower our customers and their stakeholders with facts and reliable insights so that critical decisions can be made with confidence.
About Us
We are the independent expert in assurance and risk management. Driven by our purpose, to safeguard life, property, and the environment, we empower our customers and their stakeholders with facts and reliable insights so that critical decisions can be made with confidence.
As a trusted voice for many of the world’s most successful organizations, we use our knowledge to advance safety and performance, set industry benchmarks, and inspire and invent solutions to tackle global transformations.
About The Role
As an Information Security Specialist in DNV Energy Systems, you will become part of a dedicated and collaborative team striving for operational excellence and continuous improvement in information security. The role reports directly to the Head of Section Information Security and supports the implementation of robust security practices across our business globally. Our team operates with a strong sense of trust, shared responsibility, and mutual support. We expect each team member to apply their expertise while remaining flexible and ready to support colleagues when circumstances require it. This collaborative approach helps us maintain continuity, resilience, and focus in a dynamic environment.
In this role, you will contribute to strengthening both the information security maturity and culture within DNV Energy Systems by working closely with internal stakeholders, colleagues across other DNV Business Areas, and, when relevant, external partners. Your objective is not only to identify risks and report on compliance but to actively contribute to resolving issues - by either offering direct support or by facilitating connections to ensure effective and timely outcomes. A customer-oriented mindset and strong interpersonal skills are therefore essential.
Your work will span advisory and operational tasks, including security reviews, audits, performance monitoring, and project delivery. You will also present results and insights to both leadership and peers. Most of the work will be conducted virtually, with regular in-person attendance at your local office expected. Flexibility is required to collaborate across time zones, with some international travel required, although limited in line with DNV’s sustainability commitments.
Responsibilities
The successful candidate will be inventive, comfortable working in a quick-turnaround, deadline-driven environment, and adept at managing multiple projects and assignments simultaneously. Responsibilities of the Information Security Specialist will include:
- Supporting the implementation of global and regional systems and improvement plans and contributing ideas to improve information security performance.
- Providing competent and professional information security advice on operational risks to all levels.
- Developing the information security capabilities of the organisation, improving risk awareness and providing specialist support to line management.
- Information security performance monitoring and reporting, including supporting external audits and undertaking audits as part of our internal audit programme.
Work Life Balance
We offer flexible working arrangements and a supportive culture that values work-life balance. DNV fosters an inclusive, respectful, and collaborative environment. Employees are encouraged to join professional and social networks that promote engagement across functions and geographies.
Career and Development
We believe in lifelong learning and provide extensive opportunities for professional development. You will be encouraged to broaden your competence and grow in line with both personal ambitions and the evolving needs of the team.
At DNV, you will be part of a purpose-driven organization committed to safeguarding life, property, and the environment. Our values - We Care, We Share, We Dare - guide how we work with one another and with our customers.
By joining DNV you become part of a world-leading company whose purpose is to safeguard life, property, and the environment. You will also be part of a culture where our values “we care, we share, we dare” characterize how we act towards each other, and our customers and perform our work.
About You
What we are looking for:
We are looking for a professional with a T-shaped competence profile - someone who combines deep technical expertise with a broad understanding of organizational and operational contexts. A background in software development or systems engineering is highly valued. Beyond competence, we expect all team members to embrace a mindset of lifelong learning , with a willingness to adapt, contribute, and grow continuously in alignment with team and business priorities.
Requirements
- Master’s degree in a relevant discipline.
- Recognized professional information security certification (e.g., CISSP, CISM).
- Minimum 4–5 years of experience in an information security role within a complex, operational business environment.
- Proven ability to contribute to and manage projects across multiple stakeholders and business units.
- Strong communication skills, with the ability to clearly convey complex issues to diverse audiences, including senior leadership.
- Demonstrated ability to work independently while building trust-based relationships across departments and regions.
- ISO 9001 or ISO 27001 auditor qualification is an advantage.
We consider this as a global role, and our new team member can work from anywhere; however, this person should be based in a region with a DNV office, as our Global DNV model is hybrid (3 days a week in the office). Seniority level
- Seniority level Not Applicable
- Employment type Full-time
- Job function Information Technology
- Industries Public Safety
Referrals increase your chances of interviewing at DNV by 2x
Get notified about new Information Security Specialist jobs in Greater Buenos Aires .
Autonomous City of Buenos Aires, Buenos Aires Province, Argentina 1 month ago
Network Security Engineer - Information SecurityAutonomous City of Buenos Aires, Buenos Aires Province, Argentina 2 weeks ago
Data Privacy & Information Security Analyst (GRC – Governance, Risk and Compliance) Data Privacy & Information Security Analyst (GRC – Governance, Risk and Compliance) Sr Info Security Risk Analyst I - (Hiring Across Multiple Regions) Security Analyst - Identity Infrastructure Sr. Security Compliance Analyst - US ClientWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrInformation Security Analyst
Publicado há 11 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Symplicity is a global leader in SaaS solutions, empowering organizations and individuals to achieve their goals.
We are committed to providing secure, privacy-conscious services across four distinct companies operating on diverse technology stacks and cloud platforms (AWS, Azure, and OCI). Join us in shaping the future of secure and compliant technology .
We are seeking an Information Security Analyst/Specialist to join our growing team. Reporting to the Information Security Officer (ISO) and Data Privacy Officer (DPO), you will play a pivotal role in ensuring Symplicity meets its compliance requirements while maintaining its commitment to privacy and security.
What You’ll Do:- Compliance and Audit Support : Assist in conducting security and privacy audits aligned with standards such as ISO 27001, SOC 2 Type II, NIST 800-53, GDPR, LGPD, and others. Collaborate with ISO and DPO to address audit findings, implement corrective measures, and maintain certification readiness. Collect and analyze compliance data to support continuous improvement.
- Vulnerability Management : Identify, assess, and prioritize vulnerabilities across environments. Collaborate with IT teams for remediation. Monitor and report on vulnerability trends and remediation status.
- Security Operations : Support the implementation and management of security tools like SSO, MFA, MDM, and endpoint protection. Perform log analysis and contribute to configuration management. Design and deliver security awareness programs.
- Cross-Team Coordination : Work with teams across the four companies to harmonize security initiatives, ensuring adherence to policies and best practices.
- Project Management (Preferred) : Assist in managing security and compliance projects, facilitating collaboration and ensuring timely delivery.
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Advanced English
- 2–4 years of experience in information security, compliance, or related roles.
- Familiarity with frameworks like ISO 27001, SOC 2, NIST 800-53, GDPR, LGPD.
- Experience with vulnerability management tools and practices.
- Knowledge of security technologies such as SSO, MFA, MDM.
- Strong analytical skills, especially in log analysis and configuration management.
- Excellent organizational and communication skills.
- Ability to collaborate effectively across diverse teams.
- Project management experience or certifications (e.g., PMP, CAPM).
- Experience with multiple cloud providers (AWS, Azure, OCI).
Salary: R$3.500 - R$.200 per month
Benefits for Symper Employees:
- Health Insurance (Bradesco Saúde): National coverage, private room, dependents covered. Monthly discount of R$ 00.00.
- Dental Insurance (Caixa Odonto): Discounts and reimbursements, coverage for various dental services.
- VR/VA - FlashCard : R 1.000 benefit including meal and flexible benefits.
- Credit released on the 1st of each month.
- Wellhub (Gympass) : Access to health and well-being resources for employees and dependents.
- English Program : Language classes to develop skills and foster team interaction.
- Birthday Off : A day off during your birthday month.
- Global Experience : Opportunities to collaborate worldwide.
- Educational Assistance : Support for further education, subject to approval.
- Work Environment : Modern office, top equipment, leisure areas, no dress code.
- Company Culture : Collaborative, innovative, inclusive, valuing diversity and autonomy.
At Symplicity, we lead in employability solutions, supporting over 30 million students worldwide. We are proud to be a Great Place To Work certified company!
#J-18808-LjbffrInformation Security Analyst
Publicado há 11 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Na Topaz, a tecnologia nos une e a evolução nos conecta!
Em nossa organização, estamos totalmente comprometidos em contribuir para soluções financeiras que tornem a indústria um lugar seguro, acessível e dinâmico. Queremos alcançar diferentes partes do mundo com nosso amplo ecossistema de soluções tecnológicas. Por isso, convidamos você a fazer parte dessa equipe!
Além disso, temos ótimos benefícios para você! Sabemos que, juntos, alcançaremos o sucesso, então se candidate e faça parte desse grande time.
Responsabilidades e atribuições
Seu dia a dia na Topaz:
- Prever e padronizar procedimentos de recuperação de dados e de resposta a invasões;
- Monitorar continuamente as redes da empresa e cliente;
- Gerar relatórios periódicos sobre os resultados obtidos com as ações de segurança;
- Atuação ativa e execução técnica voltada a sustentação das soluções de segurança;
- Análises de vulnerabilidades;
- Mapeamento de riscos e implementação de solução para a segurança de ambientes;
- Implementação de ferramentas de segurança cibernética;
- Analise de novas tendências de segurança de dados;
- Realização de testes de falhas e respostas;
- Realização de constantes levantamentos e diagnósticos de possíveis riscos existentes;
- Atendimento ao cliente para instalar, operar e atualizar softwares e plataformas de proteção virtual.
Requisitos:
- Conhecimento em Sistemas operacionais;
- Lógica de programação;
- Redes de computadores;
- Consultas básicas em banco de dados;
- Conhecimento básico em servidores de aplicações e banco de dados;
- Virtualização;
- Atuar com base na Metodologia de Gestão de Serviços de TI (ITIL);
- Superior cursando ou Tecnólogo em Ciências da Computação, Sistema de Informação e cursos afins;
- Capacidade de realizar análises e consolidação de dados;
- Disponibilidade para viagens pelo Brasil - eventualmente;
- Conhecimento em Inglês ou Espanhol técnico (diferencial)
- Conhecimento em combate e prevenção a fraudes (diferencial);
- Conhecimento em desenvolvimento Web e Mobile (diferencial);
Tenha em mente esses benefícios que irão melhorar sua experiência na Topaz!
- Saúde e Bem-estar: Porque pensamos em nossas equipes, oferecemos diferentes planos de saúde, focados em promover o bem-estar na organização.
- Desenvolvimento pessoal e profissional: Estamos em constante evolução. Por isso, oferecemos ambientes, programas e políticas que garantem o espaço e as oportunidades necessárias para vocêRota de carreira.
- Flexibilidade e tempo livre: Aqui você encontrará o tempo necessário para recarregar as energias, além de poder desfrutar de um dia de folga no seu aniversárioModalidade de trabalho híbrido.
- Convênios: Oferecemos diferentes convênios e descontos
Elias Fausto, São Paulo, Brazil 3 weeks ago
MOTIVA l ANALISTA DE SEGURANÇA DA INFORMAÇÃO SÊNIORIndaiatuba, São Paulo, Brazil 12 minutes ago
Louveira, São Paulo, Brazil 12 minutes ago
Analista de seguranca da informacao senior Analista de Segurança da Informação PlenoIndaiatuba, São Paulo, Brazil 21 hours ago
Analista Administrativo 1 - Segurança do Trabalho #J-18808-Ljbffr