Job Closed
This listing is no longer active.
Let's build the future together
Head of Security
Location
Brazil
Posted
141 days ago
Salary
0
Seniority
Lead
Job Description
Head of Security
avra
• Develop and implement a strategic vision for information security, aligned with business objectives and focused on the continuous improvement of the area's processes and controls. • Manage contracts, assets, and services related to information security, ensuring their optimal efficiency. • Define information security standards and policies to protect information assets and support business continuity. • Ensure regulatory compliance applicable to the company and adherence to industry best practices. • Collaborate with technology teams to define and implement effective security integration strategies across the development lifecycle, from design through production. • Analyze and respond to information security incidents, map threats and vulnerabilities, and develop projects to prevent or remediate them. • Lead risk management, threat modeling, and impact assessments for new products, features, and partnerships. • Lead training and enablement programs to build a strong security culture across the company. • Provide support for internal and external audits. • Evaluate and monitor security KPIs, keeping leadership informed about the maturity of the information security program. • Respond to requests and support the provision of the company's ISMS (SGSI) information to clients and other stakeholders as needed.
Job Requirements
- More than 5 years of experience leading information security projects, preferably in technology companies and startups.
- Strategic mindset, data- and risk-oriented with focus on business impact, risk management, and a pragmatic approach.
- Experience conducting ISO 27001 assessments.
- Strong knowledge of cloud security, particularly GCP and AWS.
- Knowledge of information security standards, frameworks, and best practices, such as application security testing (AST), NIST, CIS, ISO 27001, and OWASP.
- Experience in secure development and knowledge of security engineering.
- Knowledge of DevSecOps best practices and methodologies.
- Strong verbal and written communication skills, including demonstrated ability to prepare high-quality documentation and presentations for technical and non-technical audiences, including C-level executives.
- Experience operating in critical scenarios and supporting regulatory compliance (e.g., LGPD / ANPD).
Benefits
- N/A
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Professional, Security Compliance
SyntaxEnterprise Cloud / ERP Consulting / Managed Services
• Operate and maintain security compliance processes across ISO 27001, SOC 2, NIST, CIS, GDPR, and other relevant frameworks. • Collect, analyze, and validate technical compliance evidence from systems, applications, and security platforms. • Use SIEM and other monitoring tools to review logs, configurations, and control effectiveness. • Support internal and external audits by preparing evidence, coordinating with stakeholders, and responding to auditor requests. • Contribute to security control testing, system hardening reviews, and validation of technical baselines. • Collaborate with internal stakeholders to ensure compliance requirements are integrated into operations and projects. • Support responses to customer security questionnaires and due diligence requests as needed. • Maintain documentation of compliance processes, evidence repositories, and audit history. • Monitor changes in regulatory and framework requirements, recommending updates to controls or processes as required. • Assist in developing metrics and reports on compliance status for leadership review.
Senior Security Engineer – Security Program Delivery
Aya HealthcareAya Healthcare has provided travel nurse staffing solutions for thousands of medical facilities since 2001. The largest travel nurse provider in North America,
• Lead the design, planning, and delivery of security projects spanning cloud infrastructure (primarily Azure), web application security, secure coding practices, application code reviews, GenAI/Agentic AI security controls, and security for global, multi-region/diverse infrastructure. • Coordinate closely with engineering, architecture, DevOps, product, and international teams to define requirements, align dependencies, and drive risk reduction through mature security practices. • Perform hands-on implementation, automation, and maintenance of security solutions, including vulnerability management, policy-as-code, automated remediation workflows, secure-by-design frameworks, web application firewalls, code scanning, and runtime protection. • Provide technical coordination on securing web applications (e.g., OWASP Top 10 mitigation, secure headers, input validation), application code (secure coding standards, SAST/DAST/IAST integration), threat modeling (e.g., STRIDE), SDLC security integration, and compliance with SOC 2, ISO 27001, and UK GDPR requirements. • Ensure security controls and processes support global operations, including data sovereignty, cross-border data flows, and regional regulatory variations under UK GDPR. • Socialize security best practices, facilitate knowledge transfer, and build collaborative relationships to embed security throughout the development and deployment lifecycle. • Drive full solution delivery and implementation of tools that enable secure development, web application protection, and operational security at scale. • Balance multiple priorities, overcome obstacles, and maintain structured delivery in a fast-paced, globally distributed environment.
Security Engineer
The Trevor ProjectThe world's largest suicide prevention and mental health organization for LGBTQ young people.
• Oversee the security of The Trevor Project’s systems, data, and other digital assets. • Direct contributor to the overall organizational Information Security Program. • Support the security strategy plan and ensure compliance with security frameworks. • Monitor cloud based systems for security issues and deploy security tools. • Manage the Security Awareness Training Program and investigate security issues or breaches.
• Working independently and collaboratively with a team to both lead and support • Perform penetration testing on applications with complex technology stacks from both a: Unauthenticated perspective and Authenticated perspective • Dynamically flex your skills when assessing emerging or custom technologies. • Lead complex engagements to provide a technical consistency approach across multiple tests. • Contextualize vulnerabilities and assess realistic impact to a client accounting for mitigating and aggravating factors. • Manage priorities and tasks to achieve utilization targets. • Operate with professionalism both internally and with clients. • Ensure quality reports and services are delivered efficiently and on time. • Support sales and business growth by scoping out potential opportunities. • Maintains strong depth of knowledge in the practice area. • Collaborate with project managers, quality management, sales and other delivery team members to drive customer satisfaction and meet project deliverables.




