7 Empregos para Certified ethical hacker - Curitiba
Information Security Manager
Publicado há 25 dias atrás
Trabalho visualizado
Descrição Do Trabalho
O EBANX é uma fintech global fundada em 2012 com a missão de ser o principal parceiro de pagamentos em mercados em ascensão. Com tecnologia e infraestrutura própria, aliadas a um profundo conhecimento sobre o mercado da América Latina, o EBANX permite que essas empresas se conectem a centenas de métodos de pagamento em diferentes países da região. E vai além, criando resultados para as empresas e experiências de compra simples para os consumidores.
Desde o início da nossa jornada, temos uma importante missão: dar acesso. E isso não diz respeito apenas aos nossos produtos e serviços, mas atravessa tudo aquilo que somos e fazemos. Acreditamos que só é possível inovar com a diversidade, por isso valorizamos diferenças de gênero, raça, nacionalidade, deficiência, orientação sexual, religião e idade. A pluralidade é o que torna o nosso Sonho Grande possível.
Nós somos os ebankers e nós estamos mudando a maneira como as pessoas compram, se conectam e vivem globalmente. Topa fazer história com a gente?
Como Gerente de Segurança da Informação sua missão será de desenvolver e implementar políticas, metodologias e controles de Segurança da Informação .
Você também será responsável por:
- Liderar o time de Infosec, buscando o desenvolvimento dos ebankers;
- Conduzir e aprimorar nosso Sistema de Gestão de Segurança da Informação;
- Manter e garantir nossas certificações incluindo PCI-DSS e ISO 27001;
- Conduzir o gerenciamento de privacidade dentro da área de Segurança da Informação e em sinergia com as demais áreas da empresa;
- Garantir a correta conscientização dos ebankers em Segurança e Privacidade com melhoria continua do processo estabelecido;
- Gerenciar KPIs e métricas de Segurança da Informação;
- Prover através dos corretos frameworks a medição de maturidade de segurança, bem como acompanhar os planos para evolução destes indicadores;
- Atuar em conjunto com todas as áreas da empresa entendendo suas necessidades e endereçando pontos de segurança.
Principais requisitos da posição:
- Experiência em gestão de projetos, com habilidade de planejar, gerenciar e manter projetos complexos que atinjam diversas áreas da companhia;
- Conhecimento da família de padrões ISO / IEC 27000, PCI-DSS e BACEN;
- Conhecimento em COBIT e NIST SP 800;
- Conhecimento em riscos de Segurança da Informação;
- Experiencia anterior em liderança e formação de times;
- Inglês avançado (leitura, escrita e fala).
- Orientação a resultados;
- Certificações em Segurança;
- Espanhol.
O que o EBANX oferece:
- Um ambiente super desafiador e com muitas oportunidades de crescimento;
- Escritório casual, e um dress code flexível;
- Aulas de Espanhol, Inglês e Português (para não nativos);
- WAVES: Programa de metas e resultados;
- EBANX Play – Programas de Saúde (Gympass, e-Sports, SESC);
- Jornada semi flexível (8 horas por dia, de segunda a sexta-feira);
- Vale-refeição/Vale-alimentação;
- Vale transporte se necessário;
- EBANX Education: Possibilidade de auxílio financeiro na graduação e pós graduação;
- EBANX Skills: Possibilidade de fazer cursos e treinamentos ligados com a área de atuação;
- EBANX Flexible: Day Off dos meses de fevereiro a novembro, Birthday Day Off e Rest up month, um mês de licença remunerada a cada três anos de EBANX.
- EBANX Family: Auxílio creche, licença estendida aos cuidadores e programa de apoio a gestantes e crianças;
- EBANX Health: Plano de Saúde e Plano Dental (SulAmérica), com subsídio para dependentes, e subsídio de medicamentos para ebankers;
- Seguro de Vida: Seguro de Vida 100% custeado pelo EBANX
- Hello ebanker: Orientações psicológicas, legais ou financeiras;
- Blue Club: Descontos exclusivos para ebankers em panificadoras, restaurantes, cursos, lojas e mais!
Information Security Team Leader
Publicado há 5 dias atrás
Trabalho visualizado
Descrição Do Trabalho
At EBANX, you’ll help expand access to payments and technology in some of the world’s most dynamic markets. We’re a unicorn-status fintech , AI-powered , and scaling fast across 29 countries and counting .
Our platform connects leading global companies to more than 1 billion consumers , enabling seamless cross-border payments where it matters most. We build with purpose, move with speed, and create solutions that are both innovative and inclusive.
If you’re looking to be part of a company that’s transforming the future of payments with clarity , ambition , and real-world impact — we’d love to meet you.
In the IT Ops team, we take care of the infrastructure that keeps EBANX running every day. We ensure that employees have the best experience with devices, networks, and systems, providing fast, secure, and efficient support so nothing gets in the way.
- Lead and develop a high-performing InfoSec team focused on Governance and Awareness;
- Oversee the implementation, maintenance, and continuous improvement of ISO/IEC 27001, 27701, 27018, and PCI DSS compliance frameworks;
- Coordinate internal and external security assessments, audits, and the execution of remediation plans;
- Define, monitor, and report on key security metrics and service-level agreements (SLAs);
- Drive the creation and delivery of company-wide security awareness programs, phishing simulations, and training initiatives;
- Ensure alignment between InfoSec policies and EBANX’s business processes, internal controls, and legal/regulatory obligations;
- Collaborate with cross-functional teams (Legal, Risk, HR, Engineering, etc.) to embed security practices into business operations;
- Manage operational routines, handle incidents, support change requests, and ensure governance of ongoing activities;
- Track and report on the team’s progress, resource planning, KPIs, and strategic initiatives;
- Support the onboarding of new services and contracts, ensuring security requirements are embedded from day one;
- Foster a security-first mindset through influence, engagement, and continuous improvement culture;
- Solid experience in leading teams , with proven ability to motivate, coach, and develop people.
- Deep knowledge in Information Security Governance and Compliance , including risk management, internal controls, and security frameworks.
- Hands-on experience with global standards and certifications such as ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27018, and PCI DSS.
- Strong communication skills , capable of engaging both technical and non-technical stakeholders.
- Proven track record managing audits, assessments, and external regulatory demands.
- Analytical mindset with a business-oriented approach , connecting security decisions with strategic goals.
- Experience designing and running awareness programs that go beyond checklists and truly shift culture.
- Advanced English — you’ll often interact with international stakeholders.
- Information Security certifications such as ISO/IEC 27001 Lead Implementer/Auditor .
- Experience working in global or multicultural environments , with distributed teams and international operations.
- Familiarity with SOX controls , data privacy frameworks, and third-party risk management.
- Knowledge of cloud security standards (e.g., AWS, GCP, Azure) and secure development practices.
- Hands-on experience with awareness platforms (e.g., KnowBe4, Wombat, MetaCompliance) and phishing simulation tools.
- Experience implementing metrics dashboards and KPIs for InfoSec programs.
- Previous involvement in security incident response , including coordination and post-incident reviews.
- Passion for building a security culture , storytelling, and engaging people in non-technical areas.
- Experience using Artificial Intelligence (AI) or Machine Learning to automate governance processes , enhance risk analysis, streamline controls management, or improve compliance monitoring.
EBANX offers:
- WAVES Program: Annual bonuses based on the company’s performance.
- Meal/Food Allowance: Credit provided on a flexible benefits card.
- EBANX Education: Financial support for undergraduate, graduate, and MBA programs to support your professional growth.
- EBANX Skills: Budget dedicated to workshops, courses, and certifications to encourage your continuous development.
- Language Classes: Spanish, English, and Portuguese lessons for your personal and professional development.
- EBANX Health: Comprehensive medical and dental plans fully covered for the employee, plus subsidies for dependents to take care of your and your family’s well-being.
- EBANX Family: Childcare assistance, extended parental leave for caregivers, and support programs for pregnant employees and children.
- Life Insurance: Fully paid by EBANX.
- Transportation: Parking assistance or transportation vouchers, depending on your needs.
- EBANX Flexible: A special day off on your birthday, semi-flexible working hours (8 hours/day, Monday to Friday), and year-end recess between Christmas and New Year’s without affecting your vacation days.
- EBANX Play: Well-being program including access to Wellhub, e-Sports, and partnerships with SESC.
- Blue Club: Exclusive discounts at bakeries, restaurants, stores, courses, and more.
Follow us on LinkedIn and check out our Instagram to learn more about the #ebanxlife.
#LI-ONSITE
#LI-TC1
Create a Job Alert
Interested in building your career at EBANX? Get future opportunities sent straight to your email.
Apply for this jobFirst Name *
Last Name *
Preferred First Name
Email *
Phone
Resume/CV
Enter manually
Accepted file types: pdf, doc, docx, txt, rtf
Enter manually
Accepted file types: pdf, doc, docx, txt, rtf
LinkedIn Profile
Privacy Notice * Select.
By applying for jobs at EBANX, you declare that you have read our Privacy Notice and agree to the use of your data by EBANX. *
Your agreement with our Notice is fundamental for EBANX to take all the necessary steps to start the application process, such as contacting you, scheduling and conducting interviews, and registering you as a candidate in our systems.
EBANX will store your data for the duration of the application process and, after it has ended, for a further 5 years. If you wish to have your data deleted before then, please contact EBANX via our Privacy Portal.
Level of English * Select.
Level of Spanish * Select.
Work Location Availability * Select.
Demographic Information * Select.
We believe it is possible to create a diverse, equal and inclusive environment. That is why we have prepared a questionnaire that addresses demographic issues by collecting sensitive personal data. The information collected is part of our efforts to monitor our evolution, so filling it out is optional , but we invite you to do so. Filling in or refusing to provide these details will in no way affect your hiring process, but it will help us to get to know the people who apply to EBANX better. Check out this link for more information to support your decision on whether or not to provide consent for the processing of this data.
By selecting the "Agree" option in this section, you register your free, express, informed, and unequivocal expression of awareness about the processing of sensitive data and consent to the processing of this data. This means that you agree to the legal entity EBANX Ltda., CNPJ / , headquartered at Rua Marechal Deodoro, 630, Praça San Marco, CEP , Centro, Curitiba, PR, processing your personal data under the terms listed.
You declare yourself a person (select the option that best defines your race/skin color): * Select.
Select which gender identity you identify with: * Select.
Select which sexual orientation you identify with: * Select.
Are you a person with a disability? * Select.
If you are a person with a disability and you answered yes in the previous question, please indicate what disability you have: * Select.
Are you eligible to work in the country of the job position you are applying to? * Select.
#J-18808-LjbffrSpecialist II, Business Information Security Officer (BISO)
Publicado há 25 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Join to apply for the Specialist II, Business Information Security Officer (BISO) role at Concentrix
Specialist II, Business Information Security Officer (BISO)2 days ago Be among the first 25 applicants
Join to apply for the Specialist II, Business Information Security Officer (BISO) role at Concentrix
Direct message the job poster from Concentrix
Professional Talent Acquisition @ Concentrix | IT & Digital Recruiter LATAMConcentrix Corporation is seeking a Country Business Information Security Officer to join the Global Security team reporting to the CNX GEO Business Information Security Officer – Insider Risk and Compliance team.
Qualifications:
- 3 to 5 years of experience working in risk and compliance management, internal security controls, internal/external security assessment or audit, internal or cyber incident investigations.
- Bachelor's degree preferred in Security or Information Technology.
- Experience in the BPO industry working in quality, security compliance or delivery strongly preferred.
- Deep understanding of BPO Business Operation and CRM services delivery processes.
- Ability to identify performance and opportunity gaps.
- Process driven and an eye for detail
- Demonstrable experience of driving operational implementation of risk reduction initiatives, across business units, using influencing and security skills
- Solid background of key network and technical security controls
BISO Responsibilities:
- Drive the highest Integrity and Ethical standards across the staff and the accounts in scope.
- Provide governance to operations management team and Quality Assurance team for effective and efficient surveillance and monitoring towards pro-active security and business process non-compliance issue identification.
- Collaborate with respective supporting functions/departments (IT, HR, Facility, Legal, DPO, etc.) to address relevant security issues/risks.
- Perform internal audit/assessment on regular basis based on different business process compliance management and risk control mechanisms in different accounts to ensure the full compliance as per relevant standard and identify potential issues/risks.
- Work closely with the operation team to get all identified non-compliance items fixed in a timely manner to drive for closure and proactively propose and deploy extra preventive controls where appropriate.
- Establish and execute a robust methodology for periodic reviews aiming to highlight the gaps that exist in the operational processes.
- Analyze operational data to identify trends, root causes of business issues, and/or opportunities.
- Provide recommendations for corrective and preventive actions and suggest improvements to the processes.
- Review and report the results and present them to management team.
- Ensure partnership with accounts management team for Proactive Compliance Risk Management – identification, assessment, risk action planning, and closures.
- Coordinate and support Global Security Assessments (GSAs) - a holistic assessment (technology, HR, operations, finance, etc.) of risks being faced by delivery operations and No Notice Inspections (NNIs) conducted against the specific accounts in scope.
- Conduct employee awareness and assist in developing training materials and where necessary assist in specific training.
Accountability:
- Primary contact for security matters in country/region as appropriate
- Accountable for local implementation of country specific global security strategies and initiatives
- Delivery of established Global Security metrics as well as all visibility enabling initiatives, country-wide
- Study the contracts signed with Clients, and validate continuous contractual compliance for all controls, both physical and logical.
- Must have strong project leadership experience and ability to work with global, multi-cultural teams and drive to meet stringent deliverable timelines
- Accountable to drive identified account (client) and internal (corporate) risks, in partnership with key stakeholders, through to remediation or risk sign-off
- Plan, participate and execute Global Security Assessments (GSAs) in specific country per GSA Schedule / Calendar identifying both internal & external vulnerabilities
- Lead & Execute in the action planning activity as necessary to close identified vulnerabilities the security and business process compliance in various accounts to meet business and client expectation.
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Consulting and Analyst
- Industries IT Services and IT Consulting
Referrals increase your chances of interviewing at Concentrix by 2x
Get notified about new Information Security Officer jobs in Curitiba, Paraná, Brazil .
Specialist II, Business Information Security Officer (BISO) (TCF) Bilingual Specialist II, Business Information Security Officer (BISO) (TCF) Bilingual Scientific System Administrator - Remote - Latin AmericaWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrInformation Security Team Leader Curitiba | On-site
Publicado há 5 dias atrás
Trabalho visualizado
Descrição Do Trabalho
At EBANX, you’ll help expand access to payments and technology in some of the world’s most dynamic markets. We’re a unicorn-status fintech , AI-powered , and scaling fast across 29 countries and counting .
Our platform connects leading global companies to more than 1 billion consumers , enabling seamless cross-border payments where it matters most. We build with purpose, move with speed, and create solutions that are both innovative and inclusive.
If you’re looking to be part of a company that’s transforming the future of payments with clarity , ambition , and real-world impact — we’d love to meet you.
In the IT Ops team, we take care of the infrastructure that keeps EBANX running every day. We ensure that employees have the best experience with devices, networks, and systems, providing fast, secure, and efficient support so nothing gets in the way.
Responsibilities- Lead and develop a high-performing InfoSec team focused on Governance and Awareness;
- Oversee the implementation, maintenance, and continuous improvement of ISO/IEC 27001, 27701, 27018, and PCI DSS compliance frameworks;
- Coordinate internal and external security assessments, audits, and the execution of remediation plans;
- Define, monitor, and report on key security metrics and service-level agreements (SLAs);
- Drive the creation and delivery of company-wide security awareness programs, phishing simulations, and training initiatives;
- Ensure alignment between InfoSec policies and EBANX’s business processes, internal controls, and legal/regulatory obligations;
- Collaborate with cross-functional teams (Legal, Risk, HR, Engineering, etc.) to embed security practices into business operations;
- Manage operational routines, handle incidents, support change requests, and ensure governance of ongoing activities;
- Track and report on the team’s progress, resource planning, KPIs, and strategic initiatives;
- Support the onboarding of new services and contracts, ensuring security requirements are embedded from day one;
- Foster a security-first mindset through influence, engagement, and continuous improvement culture;
- Solid experience in leading teams , with proven ability to motivate, coach, and develop people.
- Deep knowledge in Information Security Governance and Compliance , including risk management, internal controls, and security frameworks.
- Hands-on experience with global standards and certifications such as ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27018, and PCI DSS.
- Strong communication skills , capable of engaging both technical and non-technical stakeholders.
- Proven track record managing audits, assessments, and external regulatory demands.
- Analytical mindset with a business-oriented approach , connecting security decisions with strategic goals.
- Experience designing and running awareness programs that go beyond checklists and truly shift culture.
- Advanced English — you’ll often interact with international stakeholders.
- Information Security certifications such as ISO/IEC 27001 Lead Implementer/Auditor
- Experience working in global or multicultural environments , with distributed teams and international operations.
- Familiarity with SOX controls , data privacy frameworks, and third-party risk management.
- Knowledge of cloud security standards (eg AWS, GCP, Azure) and secure development practices.
- Hands-on experience with awareness platforms (eg KnowBe4, Wombat, MetaCompliance) and phishing simulation tools.
- Experience implementing metrics dashboards and KPIs for InfoSec programs.
- Previous involvement in security incident response , including coordination and post-incident reviews.
- Passion for building a security culture , storytelling, and engaging people in non-technical areas.
- Experience using Artificial Intelligence (AI) or Machine Learning to automate governance processes, enhance risk analysis, streamline controls management, or improve compliance monitoring.
- WAVES Program: Annual bonuses based on the company’s performance.
- Meal/Food Allowance: Credit provided on a flexible benefits card.
- EBANX Education: Financial support for undergraduate, graduate, and MBA programs to support your professional growth.
- EBANX Skills: Budget dedicated to workshops, courses, and certifications to encourage your continuous development.
- Language Classes: Spanish, English, and Portuguese lessons for your personal and professional development.
- EBANX Health: Comprehensive medical and dental plans fully covered for the employee, plus subsidies for dependents to take care of your and your family’s well-being.
- EBANX Family: Childcare assistance, extended parental leave for caregivers, and support programs for pregnant employees and children.
- Life Insurance: Fully paid by EBANX.
- Transportation: Parking assistance or transportation vouchers, depending on your needs.
- EBANX Flexible: A special day off on your birthday, semi-flexible working hours (8 hours/day, Monday to Friday), and year-end recess between Christmas and New Year’s without affecting your vacation days.
- EBANX Play: Well-being program including access to Wellhub, e-Sports, and partnerships with SESC.
- Blue Club: Exclusive discounts at bakeries, restaurants, stores, courses, and more.
Specialist II, Business Information Security Officer (BISO) (TCF) Bilingual
Hoje
Trabalho visualizado
Descrição Do Trabalho
Overview
Job Title: Specialist II, Business Information Security Officer (BISO) (TCF) Bilingual
The Country Business Information Security Officer (BISO) focuses on proactively identifying security and compliance issues/risks to business operation processes in various accounts, drives in executing the controls to deter, detect and mitigate security and insider risks - including establishing capability and mechanisms to monitor and audit information and data protection of both Concentrix and clients as well as compliance level of each process and relevant control item as deployed in the operational environment. The country BISO drives proactively to enhance the fraud and compliance prevention culture and risk-free environment in Concentrix as well as identifies issues that would include but not limited to physical and logical security, data privacy, KPI, CSAT, inbound/outbound calls manipulation, information leakage, etc. impacting business. Typical activities include but are not limited to Risk Management – risk identification, risk assessments, support in development of risk action plans, risk closures, supporting investigations - case documentation, written first-hand reports, involve in-person or remote interview of persons of interest and working outside normal business hours, etc., Governance and metrics, Executive presentations, Collaboration with all teams/departments. Achieves results through direct interaction as well as influencing other internal groups or persons to achieve results.
Concentrix Corporation is seeking a Country Business Information Security Officer to join the Global Security team reporting to the CNX GEO Business Information Security Officer – Insider Risk and Compliance team.
Qualifications- 3 to 5 years of experience working in risk and compliance management, internal security controls, internal/external security assessment or audit, internal or cyber incident investigations.
- Bachelor's degree preferred in Security or Information Technology.
- Experience in the BPO industry working in quality, security compliance or delivery strongly preferred.
- Deep understanding of BPO Business Operation and CRM services delivery processes.
- Ability to identify performance and opportunity gaps.
- Process driven and an eye for detail
- Demonstrable experience of driving operational implementation of risk reduction initiatives, across business units, using influencing and security skills
- Solid background of key network and technical security controls
- Drive the highest Integrity and Ethical standards across the staff and the accounts in scope.
- Provide governance to operations management team and Quality Assurance team for effective and efficient surveillance and monitoring towards pro-active security and business process non-compliance issue identification.
- Collaborate with respective supporting functions/departments (IT, HR, Facility, Legal, DPO, etc.) to address relevant security issues/risks.
- Perform internal audit/assessment on regular basis based on different business process compliance management and risk control mechanisms in different accounts to ensure the full compliance as per relevant standard and identify potential issues/risks.
- Work closely with the operation team to get all identified non-compliance items fixed in a timely manner to drive for closure and proactively propose and deploy extra preventive controls where appropriate.
- Establish and execute a robust methodology for periodic reviews aiming to highlight the gaps that exist in the operational processes.
- Analyze operational data to identify trends, root causes of business issues, and/or opportunities.
- Provide recommendations for corrective and preventive actions and suggest improvements to the processes.
- Review and report the results and present them to management team.
- Ensure partnership with accounts management team for Proactive Compliance Risk Management – identification, assessment, risk action planning, and closures.
- Coordinate and support Global Security Assessments (GSAs) - a holistic assessment (technology, HR, operations, finance, etc.) of risks being faced by delivery operations and No Notice Inspections (NNIs) conducted against the specific accounts in scope.
- Conduct employee awareness and assist in developing training materials and where necessary assist in specific training.
- Primary contact for security matters in country/region as appropriate
- Accountable for local implementation of country specific global security strategies and initiatives
- Delivery of established Global Security metrics as well as all visibility enabling initiatives, country-wide
- Study the contracts signed with Clients, and validate continuous contractual compliance for all controls, both physical and logical.
- Must have strong project leadership experience and ability to work with global, multi-cultural teams and drive to meet stringent deliverable timelines
- Accountable to drive identified account (client) and internal (corporate) risks, in partnership with key stakeholders, through to remediation or risk sign-off
- Plan, participate and execute Global Security Assessments (GSAs) in specific country per GSA Schedule / Calendar identifying both internal & external vulnerabilities
- Lead & Execute in the action planning activity as necessary to close identified vulnerabilities the security and business process compliance in various accounts to meet business and client expectation.
Location: BRA Curitiba - MAL DEODORO, 314 Ed. Tibagi
Time Type: Full time
Posting Date:
Privacy Notice: If you are a California resident, by submitting your information you acknowledge that you have read and have access to the Job Applicant Privacy Notice for California Residents.
#J-18808-LjbffrSpecialist II, Business Information Security Officer (BISO) (TCF) Bilingual

Publicado há 9 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Specialist II, Business Information Security Officer (BISO) (TCF) Bilingual
Job Description
The Country Business Information Security Officer (BISO) focuses on proactively identifying security and compliance issues/risks to business operation processes in various accounts, drives in executing the controls to deter, detect and mitigate security and insider risks - including establishing capability and mechanisms to monitor and audit information and data protection of both Concentrix and clients as well as compliance level of each process and relevant control item as deployed in the operational environment, The country BISO drives proactively to enhance the fraud and compliance prevention culture and risk-free environment in Concentrix as well as identifies issues that would include but not limited to physical and logical security, data privacy, KPI, CSAT, inbound/outbound calls manipulation, information leakage, etc. impacting business. Typical activities include but are not limited to Risk Management - risk identification, risk assessments, support in development of risk action plans, risk closures, supporting investigations - case documentation, written first-hand reports, involve in-person or remote interview of persons of interest and working outside normal business hours etc., Governance and metrics, Executive presentations, Collaboration with all teams/ departments. Achieves results through direct interaction as well as influencing other internal groups or persons to achieve results.
Concentrix Corporation is seeking a Country Business Information Security Officer to join the Global Security team reporting to the CNX GEO Business Information Security Officer - Insider Risk and Compliance team.
**Qualifications:**
+ 3 to 5 years of experience working in risk and compliance management, internal security controls, internal/external security assessment or audit, internal or cyber incident investigations.
+ Bachelor's degree preferred in Security or Information Technology.
+ Experience in the BPO industry working in quality, security compliance or delivery strongly preferred.
+ Deep understanding of BPO Business Operation and CRM services delivery processes.
+ Ability to identify performance and opportunity gaps.
+ Process driven and an eye for detail
+ Demonstrable experience of driving operational implementation of risk reduction initiatives, across business units, using influencing and security skills
+ Solid background of key network and technical security controls
**BISO Responsibilities:**
+ Drive the highest Integrity and Ethical standards across the staff and the accounts in scope.
+ Provide governance to operations management team and Quality Assurance team for effective and efficient surveillance and monitoring towards pro-active security and business process non-compliance issue identification.
+ Collaborate with respective supporting functions/departments (IT, HR, Facility, Legal, DPO, etc.) to address relevant security issues/risks.
+ Perform internal audit/assessment on regular basis based on different business process compliance management and risk control mechanisms in different accounts to ensure the full compliance as per relevant standard and identify potential issues/risks.
+ Work closely with the operation team to get all identified non-compliance items fixed in a timely manner to drive for closure and proactively propose and deploy extra preventive controls where appropriate.
+ Establish and execute a robust methodology for periodic reviews aiming to highlight the gaps that exist in the operational processes.
+ Analyze operational data to identify trends, root causes of business issues, and/or opportunities.
+ Provide recommendations for corrective and preventive actions and suggest improvements to the processes.
+ Review and report the results and present them to management team.
+ Ensure partnership with accounts management team for Proactive Compliance Risk Management - identification, assessment, risk action planning, and closures.
+ Coordinate and support Global Security Assessments (GSAs) - a holistic assessment (technology, HR, operations, finance, etc.) of risks being faced by delivery operations and No Notice Inspections (NNIs) conducted against the specific accounts in scope.
+ Conduct employee awareness and assist in developing training materials and where necessary assist in specific training.
**Accountability:**
+ Primary contact for security matters in country/region as appropriate
+ Accountable for local implementation of country specific global security strategies and initiatives
+ Delivery of established Global Security metrics as well as all visibility enabling initiatives, country-wide
+ Study the contracts signed with Clients, and validate continuous contractual compliance for all controls, both physical and logical.
+ Must have strong project leadership experience and ability to work with global, multi-cultural teams and drive to meet stringent deliverable timelines
+ Accountable to drive identified account (client) and internal (corporate) risks, in partnership with key stakeholders, through to remediation or risk sign-off
+ Plan, participate and execute Global Security Assessments (GSAs) in specific country per GSA Schedule / Calendar identifying both internal & external vulnerabilities
+ Lead & Execute in the action planning activity as necessary to close identified vulnerabilities the security and business process compliance in various accounts to meet business and client expectation.
#LATAMCNX
Location:
BRA Curitiba - MAL DEODORO, 314 Ed. Tibagi
Language Requirements:
Time Type:
Full time
**If you are a California resident, by submitting your information, you acknowledge that you have read and have access to the Job Applicant Privacy Notice for California Residents (
Security Risk Management Specialist
Publicado há 4 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Overview
In security risk management we're looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we identify, track and reduce our security risk across everything we do. To support this we use industry best practices paired with emerging threat information to promote risk identification, quantification, impact analysis, and modelling to ultimately drive decision making. In this role, you will help establish and execute a broad strategic vision for the security risk program at Canonical. You will work within the team and cross-functionally with various teams across the organisation. The team contributes ideas and requirements for Canonical product security, improving the resilience and robustness of all Ubuntu customers and users subject to cyber attacks. Additionally, the team collaborates with our Organisational Learning and Development team to develop playbooks and facilitate security training across Canonical.
The security risk management team’s mission is not only to secure Canonical, but also to contribute to the security of the wider open source ecosystem. They might share knowledge through public presentations and industry events, and share threat intelligence with the wider community or represent Canonical in sector-specific governance bodies.
What you will do in this role- Define Canonical's security risk management standards and playbooks
- Analyse and improve Canonical's security risk practices
- Evaluate, select and implement new security requirements, tools and practices
- Grow the presence and thought leadership of Canonical security risk management practice
- Develop Canonical security risk learning and development materials
- Work with Security leadership to present information and influence change
- Participate in developing key risk indicators, provide inputs to the development of key control indicators, and key performance indicators for various programs
- Apply statistical models to risk frameworks (such as FAIR, sensitivity analysis, and others)
- Participate in risk management, decision-making, and collaborative discussions
- Lead quantified risk assessments and understand the value of qualitative data for improvements to quality and engineering processes
- Interpret internal or external cyber security risk analyses in business terms and recommend a responsible course of action
- Develop templates and materials to help with self-service risk management actions
- Monitor and identify opportunities to improve the effectiveness of risk management processes
- Launch campaigns to perform security assessments and help mitigate security risks across the company
- Build evaluation methods and performance indicators to measure efficiency of security functions and capabilities
- An exceptional academic track record
- Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path
- Drive and a track record of going above-and-beyond expectations
- Deep personal motivation to be at the forefront of technology security
- Leadership and management ability
- Excellent business English writing and presentation skills
- Problem-solver with excellent communication skills, a deep technical understanding of security assessments and risk management
- Expertise in threat modelling and risk management frameworks
- Broad knowledge of how to operationalize the management of security risk
- Experience in Secure Development Lifecycle and Security by Design methodology
- Distributed work environment with twice-yearly team sprints in person
- Personal learning and development budget of USD 2,000 per year
- Annual compensation review
- Recognition rewards
- Annual holiday leave
- Maternity and paternity leave
- Employee Assistance Programme
- Opportunity to travel to new locations to meet colleagues
- Priority Pass, and travel upgrades for long haul company events
Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence - in order to succeed, we need to be the best at what we do. Canonical has been a remote-first company since its inception in 2004. Working here is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game.
Canonical is an equal opportunity employer
Seniority level- Entry level
- Full-time
- Finance and Sales
- Industries
- Software Development
Referrals increase your chances of interviewing at Canonical by 2x
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrSeja o primeiro a saber
Sobre o mais recente Certified ethical hacker Empregos em Curitiba !