Business Information Security Officer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 1,001-5,000Since 1999H1B No SponsorCompany SiteLinkedIn

Location

Brazil

Posted

3 days ago

Salary

0

Seniority

Senior

Bachelor DegreePortuguese

Job Description

Business Information Security Officer

Blip

• Be the link between Information Security (IS) and the business. • Serve as the dedicated and ongoing Information Security point of contact for Product and Engineering squads. • Actively participate in team ceremonies, planning sessions and product reviews — not as an occasional guest, but as a relevant member of the conversation. • Translate security requirements into language and context that make sense for development teams, product managers (PMs) and product leaders. • Identify, assess, and communicate security risks clearly to non-technical stakeholders. • Build and track risk treatment plans with the areas, prioritizing based on real business impact. • Ensure Product and Engineering teams understand the risks they are assuming with each decision — and that those choices are made consciously. • Act as a facilitator between squads and the IAM team for access provisioning and reviews — removing friction while maintaining necessary controls. • Support teams in incorporating security practices throughout the development lifecycle (security by design, threat modeling, architecture reviews). • Act as a guide on compliance and Information Security policies, with a pragmatic view of the real needs of those building the products. • Foster a security culture that is perceived as an enabler, not an obstacle. • Promote continuous, contextualized security awareness for Product and Engineering teams. • Identify recurring risk patterns and propose systemic improvements, not just ad-hoc fixes.

Job Requirements

  • Strong experience in Information Security, including roles that involved direct interaction with business, product or software engineering teams.
  • Practical knowledge of risk management, Information Security policies and security frameworks (ISO 27001, NIST, etc.).
  • Familiarity with software development lifecycles and agile methodologies — you need to speak the language of the teams you will support.
  • Preferred: experience at technology companies or fintechs.

Benefits

  • Flexible Hours: More autonomy to organize your schedule with balance and responsibility.
  • Flexible Work Models: Remote, hybrid or on-site, depending on the role's needs.
  • No Dress Code: Freedom to be yourself, without formality.
  • Birthday Day Off: One day off during your birthday month to celebrate as you wish.
  • Blip Recharge: 5 paid days off per year for roles without time tracking, designed to help balance workload.
  • Meal or Food Allowance: BRL 1,144.00 per month, paid with no deductions and credited during vacation and leave.
  • Transportation Allowance: Available according to commuting needs.
  • Wellhub (Gympass): Access to gyms, wellness apps and fitness activities, also available for dependents.
  • SESC Partnership: Access to cultural activities, leisure, sports, hotels, holiday resorts and more.
  • Health Insurance (SulAmérica): National coverage, private room for you and your dependents, with only copayment contributions.
  • Dental Plan: National coverage for you and your dependents, three plan options, with the full cost of the chosen plan covered.
  • Conexa Saúde: Online psychological care platform.
  • Life Insurance: Coverage equivalent to 24 times your monthly salary.
  • Extended Maternity Leave: 180 days to comfortably experience the start of this new phase.
  • Extended Paternity Leave: 30 days to be present and strengthen bonds.
  • Childcare Allowance: Reimbursement of BRL 676.81 for children up to 2 years old and BRL 592.21 for children up to 5 years old.
  • Allowance for Dependents with Disabilities: Support of BRL 846.02 for children with disabilities or neurodiversity.
  • Educational Support: Partnerships with higher education institutions and language schools.
  • ICP – Short-Term Incentive: Financial recognition linked to Blip's goals.
  • Your Name Matters: Reimbursement of up to BRL 250.00 for expenses related to legal first-name and/or gender marker changes, supporting inclusion and respect for identity.

Related Categories

Related Job Pages

More Security Engineer Jobs

Grant Street Group logo

Security & Compliance Engineer

Grant Street Group

Grant Street Group specializes in cloud-based government solutions for tax collection, e-payments, and auctions.

Full TimeRemoteTeam 201-500H1B No Sponsor

• Support the day-to-day security posture of systems and services across cloud and on-prem environments. • Review vulnerability findings from scanners, penetration tests, and other assessments, and help drive remediation to closure. • Partner with infrastructure, platform, and engineering teams on secure configuration, access control, logging, monitoring, and incident readiness. • Support compliance and assessment activities related to GovRAMP/FedRAMP, PCI DSS, internal reviews, and third-party examinations. • Use AWS security tooling effectively, support day-to-day security processes, and help translate security and compliance requirements into practical, durable operational outcomes. • Maintain documentation, procedures, and other operational artifacts so they stay aligned with the environment and current control expectations.

United States
$100K - $160K / year
Planet Technologies logo

Security and Compliance Consultant

Planet Technologies

For 24 years, we have built our reputation on establishing trust. Trust with our clients and among our team.

Full TimeRemoteTeam 201-500Since 1999H1B No Sponsor

• Serve as a primary technical lead on client engagements involving Microsoft security, compliance, and data protection solutions • Design and implement data security, governance, and compliance strategies aligned with Microsoft 365 and Azure capabilities • Advise clients on secure adoption of Microsoft Copilot, including data exposure risks, governance controls, and compliance considerations • Architect and deploy solutions leveraging tools such as: Microsoft Purview, Microsoft Defender suite and Microsoft Sentinel • Translate regulatory and compliance requirements into actionable technical solutions (e.g., ISO frameworks, government regulations, internal controls) • Conduct data discovery, classification, and protection strategy design • Collaborate with project managers and stakeholders to deliver high-quality outcomes • Contribute to pre-sales efforts, including solution design, scoping, and level-of-effort estimates • Create technical documentation, implementation guides, and client training materials • Act as a subject matter expert (SME) and mentor to other engineers • Develop and refine repeatable offerings around data security, compliance, and Copilot readiness • Stay current on evolving Microsoft security, compliance, and AI governance capabilities

United States
$120K - $210K / year
Full TimeRemoteTeam 10,001+Since 1993H1B Sponsor

• Define, analyze, and review secure software architectures for centralized automotive computing platforms • Perform threat modeling and security architecture analysis for mixed-criticality, multi-tenant automotive software systems • Partner with safety architects to reason about the interaction between security controls, safety mechanisms, failure modes, and recovery behavior • Define OS security policy, access control, isolation, and privilege models across Android, Linux, QNX, and virtualized environments • Build security systems that maintain integrity and availability for safety-critical vehicle software • Analyze security trade-offs involving performance, latency, memory footprint, boot time, diagnosability, and functional safety requirements • Guide engineering teams on secure build, secure coding, threat mitigation, and security review practices • Collaborate across software, hardware, safety, security, and systems teams to meet NVIDIA and automotive industry standards

California + 4 moreAll locations: California | New York | Michigan | Texas | Washington
$224K - $356.5K / year
Full TimeRemoteTeam 11-50

Role Description 10a Labs' Investigations Team is looking for a Senior Cyber Investigator to support critical safety incidents and conduct investigations across a range of cyber abuse areas. This role requires deep cybersecurity subject-matter expertise to detect and respond to malicious activity, assess threat actor behavior at the organizational level, and handle escalated cases requiring senior technical judgment. Investigations may involve exposure to harmful or disturbing content, including malicious code, exploit development, and content designed to facilitate cyberattacks. - Detect and investigate malicious uses and cyber abuse, including cases involving scaled data extraction, ransomware, and local and remote exploits. - Conduct org-level analysis of threat actor behavior, identifying patterns across cases to inform detection and mitigation strategies. - Handle escalated and technically complex cases, applying senior cybersecurity expertise to assess real-world harm potential. - Query internal data sources using SQL and Python and cross-reference open-source information (OSINT) to support investigations. - Document and share investigative findings and recommendations with internal stakeholders and client teams. - Support quality and consistency across the investigations team, providing guidance to junior investigators on ambiguous cases. - Respond to reactive escalations and on-call leads, including those not caught by existing safety systems. Qualifications - At least 5+ years of experience in cybersecurity, threat intelligence, Trust & Safety, national security, defense, intelligence, or law enforcement domains. - Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience. - Familiarity with LLM systems and how AI technology can be misused for cyber operations. - Deep subject-matter expertise in one or more of the following: scaled data extraction, ransomware, local and remote exploits, or offensive security operations. - Strong ability to assess the real-world harm potential of technical content, distinguishing genuine offensive uplift from benign or educational security research. - Strong SQL and Python proficiency for querying data and supporting detection workflows. - Proven experience conducting org-level threat actor analysis across large datasets. - Ability to rapidly context-switch across domains, modalities, and abuse areas in a fast-paced, ambiguous environment. - Ability to clear an insider-threat background check. Preferred Qualifications - Experience with threat intelligence frameworks such as MITRE ATT&CK. - Background in dark web monitoring, OSINT, or cross-platform threat analysis. - Experience scaling and automating detection and mitigation processes. - Full professional proficiency in Arabic, Chinese, Farsi, Portuguese, Russian, or Spanish. - Relevant certifications such as OSCP, GREM, or GCTI. Benefits - Salary Range: $115K–$140K, depending on experience and location. - Work Environment: Fully remote, U.S.-based. - Health Benefits: Comprehensive health, dental, and vision coverage. - Time Off: Generous PTO and paid holiday schedule. - Retirement: 401(k) plan.

United States
$115K - $140K / year