Promoting wellbeing by making 1:1 dietitian-led, comprehensive nutrition care globally accessible.
Security & Compliance Specialist
Location
Portugal
Posted
2 days ago
Salary
€19.6K - €29.4K / year
Seniority
Junior
Job Description
Security & Compliance Specialist
Nutrium
• Own compliance execution across Nutrium's security and privacy frameworks (ISO 27001, ISO 27701, SOC 2, ISO 9001, HIPAA, and GDPR) • Manage Nutrium's GRC platform end to end: controls, evidence, tasks, audits, and remediation plans • Prepare for and support internal and external audits, from scoping to evidence collection • Maintain and improve internal policies, procedures, controls, and compliance documentation • Partner with internal teams (Engineering, Legal and Operations), and external consultants, to turn requirements into practical implementation • Respond to security questionnaires and due diligence requests from prospects and clients • Support meetings with national and international clients on security, privacy, compliance, and data flows • Provide operational legal support, when needed.
Job Requirements
- Hold a Degree in Law, Information Security, Cybersecurity, Data Protection, or a related field (a Degree from NOVA IMS is a plus!)
- Have between 1 - 3 years of experience in compliance, legal operations, privacy, risk, governance or a similar area, ideally in a regulated environment (healthcare, SaaS or fintech is a plus!)
- Have hands-on experience with at least one major framework (ISO 27001, SOC 2, or GDPR), and familiarity with the others
- Have experience working with GRC platforms to manage controls, evidence and audit cycles (nice to have)
- Are highly organized, structured and detail-oriented, with strong ownership over follow-ups and deadlines
- Bring exposure to HIPAA or health-data privacy, or a relevant certification (ISO 27001 Lead Implementer or Auditor, CIPP, CISA), or are working towards one
- Thrive in a fast-moving scale-up where processes are still being built
- Are comfortable preparing for and supporting internal and external audits
- Have experience responding to client security questionnaires and due diligence requests
- Thrive in collaborative environments and enjoy working with cross-functional teams and external consultants
- Are fluent in Portuguese and English (additional languages are a plus).
Benefits
- A flexible work model and hours
- 27 days of annual leave
- Unlimited nutritional appointments (via Nutrium Care)
- Unlimited psychology sessions
- Health insurance
- Meal allowance: 10,46€ per working day
- Professional development budget
- Snacks and good coffee in the offices
- A multicultural team that enjoys spending time together, not just while working, but also through team activities, social events, and our annual offsite.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
What's the role?We are looking for a highly motivated and technically skilled Threat Intelligence Engineer to join our Cyber Security team. The ideal candidate will combine strong analytical capabilities with hands-on engineering and automation skills to proactively identify, analyze, operationalize, and communicate cyber threats relevant to the organization. This role focuses on transforming threat intelligence into actionable security outcomes by leveraging Threat Intelligence Platforms (TIPs), automation, adversary tracking, and close collaboration with SOC, Incident Response, Detection Engineering, and Security Operations teams. The successful candidate will help mature the company’s Cyber Threat Intelligence (CTI) capabilities, improve visibility into emerging threats, and automate intelligence collection, enrichment, and distribution workflows. Key Responsibilities - Monitor and analyze the global threat landscape to identify threats relevant to the company, industry, assets, and business operations. - Track emerging threat actors, malware campaigns, vulnerabilities, ransomware groups, phishing activity, and attacker TTPs. - Collect, enrich, correlate, and operationalize Indicators of Compromise (IOCs) and threat intelligence from internal and external sources. - Operate and maintain Threat Intelligence Platforms, including MISP and related integrations. - Develop automated workflows for threat ingestion, enrichment, deduplication, scoring, and distribution. - Integrate threat intelligence into SIEM, SOAR, EDR/XDR, ticketing systems, and detection pipelines through APIs and automation. - Produce tactical, operational, and strategic intelligence reports for technical and non-technical stakeholders. - Support Incident Response, Threat Hunting, Detection Engineering, and Purple Team activities with actionable intelligence. - Conduct malware, infrastructure, and campaign analysis to identify attacker patterns and risks. - Evaluate new intelligence sources, tools, and technologies to continuously improve CTI capabilities. - Build dashboards, metrics, and reporting capabilities to measure intelligence effectiveness and threat trends. Who are you? - 3+ years of experience in Cyber Threat Intelligence, SOC, Detection Engineering, Incident Response, or similar cybersecurity roles. - Hands-on experience with Threat Intelligence Platforms such as MISP, OpenCTI, ThreatConnect, or equivalent. - Strong understanding of Cyber Threat Intelligence concepts, IOC lifecycle management, and intelligence-driven defense. - Experience analyzing threat actors, malware, phishing campaigns, vulnerabilities, and adversary TTPs. - Practical knowledge of MITRE ATT&CK framework. - Experience with SIEM technologies such as Splunk, Microsoft Sentinel, Elastic, QRadar, or similar. - Basic to intermediate scripting and automation skills using Python, Bash, or similar languages. - Familiarity with STIX/TAXII and intelligence-sharing methodologies. - Understanding of networking, operating systems, cloud environments, and modern attack techniques. - Ability to communicate technical findings clearly to both technical and business audiences. - Strong analytical mindset with attention to detail and prioritization skills. What Do We Offer? - Work on the development of large-scale services, serving and storing petabytes of data. - Work with cutting-edge, modern technologies. - A great work-life balance. - Flexible working hours. - Competitive salary plus bonus. - Fantastic & talented people from 60+ countries worldwide. Change is HERE. Apply Now! As part of HERE Technologies employment process, candidates will be required to successfully complete a pre-employment screening process. This offer and any related claims are subject to the successful completion of a pre-employment screening. This will involve employment, education, and criminal verification if applicable. #LI-AY2 #LI-HYBRID Who are we?HERE Technologies is a location data and technology platform company. We empower our customers to achieve better outcomes – from helping a city manage its infrastructure or a business optimize its assets to guiding drivers to their destination safely. At HERE we take it upon ourselves to be the change we wish to see. We create solutions that fuel innovation, provide opportunity and foster inclusion to improve people’s lives. If you are inspired by an open world and driven to create positive change, join us. Learn more about us on our YouTube Channel.
• Write expert‑level prompts across specialized cybersecurity topics. • Evaluate and annotate model responses for technical accuracy, helpfulness, and appropriate handling of sensitive content. • Apply structured guidelines to classify prompts and conversations.
Security Enterprise Architect – Identity, PAM, Zero Trust
KyndrylWe design, build, manage and modernize the mission-critical technology systems that the world depends on every day.
• Create, maintain, and deepen trusted relationships with senior client stakeholders • Act as a senior advisor to clients on IAM, PAM, and Zero Trust strategy • Support contract execution and operational excellence for led accounts • Drive profitable growth through consult led identity and Zero Trust engagements • Provide deep expertise in Identity and Access Management, Privileged Access Management, and Zero Trust architectures • Lead client discussions on identity strategy, target state architecture, roadmaps, and business aligned outcomes • Ensure account compliance and act with integrity across all client engagements • Support the development of technical and consulting talent across Kyndryl
Title: Communications and Security Engineer Location: Fortitude Valley Australia Employees work in a hybrid mode Full-time State/Province: Queensland Business Group: DCS Legal Entity: AECOM Australia Pty Ltd Business Line: B&P - Buildings & Places Work Location Model: Hybrid Operating Group: International Job Description: Work with Us. Change the World. At AECOM, we''re delivering a better world. Whether improving your commute, keeping the lights on, providing access to clean water, or transforming skylines, our work helps people and communities thrive. We are the world''s trusted infrastructure consulting firm, partnering with clients to solve the world's most complex challenges and build legacies for future generations. There has never been a better time to be at AECOM. With accelerating infrastructure investment worldwide, our services are in great demand. We invite you to bring your bold ideas and big dreams and become part of a global team of over 50,000 planners, designers, engineers, scientists, digital innovators, program and construction managers and other professionals delivering projects that create a positive and tangible impact around the world. We''re one global team driven by our common purpose to deliver a better world. Join us. AECOM''s ICT & Security practice is growing, and we''re looking for experienced consultants to take on complex, high-stakes work across Defence and Federal Government. The roles sit at the Senior to Principal level, meaning you''ll lead design deliverables, represent your discipline in client meetings, and contribute to the technical quality of the team, not just execute tasks. The work spans physical security systems, passive (Layer 0 - Passive Infrastructure / Civil Infrastructure, OSP, external and internal cable containment, Layer 1 - structured cabling, fibre etc.) and active ICT infrastructure, and communications design, predominantly in environments governed by PSPF, ISM, and DSPF. If you''ve spent your career in built-environment advising, consulting, and guiding, and understand the difference between designing a system and deploying one, this role is for you. Lead the development of communications and security designs for Defence and Federal Government clients, from concept through to detailed, and construction documentation. Apply your working knowledge of AS/NZS 11801, AS/CA S009, DCCS, and DCRS to deliver compliant, buildable designs. Hold workshops and client design meetings, providing clear technical advice and manage stakeholder expectations. Mentor junior and intermediate staff and contribute to quality reviews across the broader practice. What we''re looking for: You''ll hold a tertiary qualification in electrical engineering, communications, or mechatronics, and have hands-on experience delivering integrated ICT infrastructure, structured cabling, OSP, and physical security systems in complex built environment projects. You''ll hold an AGSVA Baseline Security Clearance with a clear pathway to NV1. Candidates working towards RPEQ, SCEC registration, or RCDD/AVIXA accreditation will stand out, as will those with exposure to Systems Safety and WHS planning in regulated environments. Three to five years in a Defence environment is desirable, but the quality of your design experience matters more than the number of years. We''re one of the few firms in Australia with the scale, sector relationships, and technical depth to deliver at the intersection of ICT, security, and major infrastructure. You''ll work on projects that matter, with a team that takes quality seriously, in a practice actively investing in its people and capability. At AECOM, we are committed to maintaining a secure and trustworthy recruitment process and take any fraudulent hiring activity seriously. To support this commitment, all newly hired employees are required to attend an in-person Day 1 onboarding at an AECOM office location as a condition of employment. AECOM acknowledges the Traditional Owners and Custodians of the lands on which we, our clients and our communities live and work around Australia. We pay our respects to their cultures and to their Elders - past, present, and emerging. We are committed to connecting to Country in our work through meaningful engagement with First Nations peoples and businesses. Find out more about our Australian Reconciliation Action Plan here: https://aecom.com/au/our-vision-for-reconciliation/. About AECOM AECOM is the world's trusted infrastructure consulting firm, delivering professional services throughout the project lifecycle - from advisory, planning, design and engineering to program and construction management. On projects spanning transportation, buildings, water, new energy and the environment, our public- and private-sector clients trust us to solve their most complex challenges. Our teams are driven by a common purpose to deliver a better world through our unrivaled technical and digital expertise, a culture of equity, diversity and inclusion, and a commitment to environmental, social and governance priorities. AECOM is a Fortune 500 firm and its Professional Services business had revenue of $16.1 billion in fiscal year 2025. See how we are delivering sustainable legacies for generations to come at aecom.com and @AECOM. Freedom to Grow in a World of Opportunity You will have the flexibility you need to do your best work with hybrid work options. Whether you're working from an AECOM office, remote location or at a client site, you will be working in a dynamic environment where your integrity, entrepreneurial spirit and pioneering mindset are championed. You will help us foster a culture of equity, diversity and inclusion - a safe and respectful workplace, where we invite everyone to bring their whole selves to work using their unique talents, backgrounds and expertise to create transformational outcomes for our clients. AECOM provides a wide array of compensation and benefits programs to meet the diverse needs of our employees and their families. We also provide a robust global well-being program. We're the world's trusted global infrastructure firm, and we're in this together - your growth and success are ours too. Join us, and you'll get all the benefits of being a part of a global, publicly traded firm - access to industry-leading technology and thinking and transformational work with big impact and work flexibility. As an Equal Opportunity Employer, we believe in each person's potential, and we'll help you reach yours.




