Head of Security
Posted 72ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Lead strategic security for Avra, an AI-driven platform focusing on insights for businesses. Enhance information security practices aligned with business objectives and continuous improvement.
Responsibilities:
- Develop and implement a strategic vision for information security, aligned with business objectives and focused on the continuous improvement of the area's processes and controls.
- Manage contracts, assets, and services related to information security, ensuring their optimal efficiency.
- Define information security standards and policies to protect information assets and support business continuity.
- Ensure regulatory compliance applicable to the company and adherence to industry best practices.
- Collaborate with technology teams to define and implement effective security integration strategies across the development lifecycle, from design through production.
- Analyze and respond to information security incidents, map threats and vulnerabilities, and develop projects to prevent or remediate them.
- Lead risk management, threat modeling, and impact assessments for new products, features, and partnerships.
- Lead training and enablement programs to build a strong security culture across the company.
- Provide support for internal and external audits.
- Evaluate and monitor security KPIs, keeping leadership informed about the maturity of the information security program.
- Respond to requests and support the provision of the company's ISMS (SGSI) information to clients and other stakeholders as needed.
Requirements:
- More than 5 years of experience leading information security projects, preferably in technology companies and startups.
- Strategic mindset, data- and risk-oriented with focus on business impact, risk management, and a pragmatic approach.
- Experience conducting ISO 27001 assessments.
- Strong knowledge of cloud security, particularly GCP and AWS.
- Knowledge of information security standards, frameworks, and best practices, such as application security testing (AST), NIST, CIS, ISO 27001, and OWASP.
- Experience in secure development and knowledge of security engineering.
- Knowledge of DevSecOps best practices and methodologies.
- Strong verbal and written communication skills, including demonstrated ability to prepare high-quality documentation and presentations for technical and non-technical audiences, including C-level executives.
- Experience operating in critical scenarios and supporting regulatory compliance (e.g., LGPD / ANPD).
Benefits:
- N/A


















