Head of Security

Posted 72ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Lead strategic security for Avra, an AI-driven platform focusing on insights for businesses. Enhance information security practices aligned with business objectives and continuous improvement.

Responsibilities:

  • Develop and implement a strategic vision for information security, aligned with business objectives and focused on the continuous improvement of the area's processes and controls.
  • Manage contracts, assets, and services related to information security, ensuring their optimal efficiency.
  • Define information security standards and policies to protect information assets and support business continuity.
  • Ensure regulatory compliance applicable to the company and adherence to industry best practices.
  • Collaborate with technology teams to define and implement effective security integration strategies across the development lifecycle, from design through production.
  • Analyze and respond to information security incidents, map threats and vulnerabilities, and develop projects to prevent or remediate them.
  • Lead risk management, threat modeling, and impact assessments for new products, features, and partnerships.
  • Lead training and enablement programs to build a strong security culture across the company.
  • Provide support for internal and external audits.
  • Evaluate and monitor security KPIs, keeping leadership informed about the maturity of the information security program.
  • Respond to requests and support the provision of the company's ISMS (SGSI) information to clients and other stakeholders as needed.

Requirements:

  • More than 5 years of experience leading information security projects, preferably in technology companies and startups.
  • Strategic mindset, data- and risk-oriented with focus on business impact, risk management, and a pragmatic approach.
  • Experience conducting ISO 27001 assessments.
  • Strong knowledge of cloud security, particularly GCP and AWS.
  • Knowledge of information security standards, frameworks, and best practices, such as application security testing (AST), NIST, CIS, ISO 27001, and OWASP.
  • Experience in secure development and knowledge of security engineering.
  • Knowledge of DevSecOps best practices and methodologies.
  • Strong verbal and written communication skills, including demonstrated ability to prepare high-quality documentation and presentations for technical and non-technical audiences, including C-level executives.
  • Experience operating in critical scenarios and supporting regulatory compliance (e.g., LGPD / ANPD).

Benefits:

  • N/A