Act as the digital security focal point for digital channels and new business projects, connecting business, technology, architecture and security areas (defensive security, identity, fraud prevention and others).
Conduct security analyses, threat modeling, architecture assessments and recommend controls for Web, Mobile and Cloud applications, applying security by design from the early stages of projects.
Anticipate needs, build partnerships with product and technology teams and influence the security backlog of the channels/products under your responsibility.
Prepare and present executive-level materials for committees, boards and other senior audiences, translating technical risks into business language with clarity and storytelling.
Lead, develop and engage a team of consultants, analysts and interns, creating individual development plans (IDPs), tracking individual progress and fostering a culture of continuous learning.
Manage squads integrated with the business, including backlog management, vendor performance evaluation, resource allocation and budget advocacy.
Support the security of digital financial products (Fintech), ensuring adherence to regulatory requirements applicable to the banking environment.
Requirements
Strong experience in cybersecurity or related areas.
Experience analyzing business projects with application of security by design, threat modeling, risk analysis and recommendation of security controls.
Holistic view of cybersecurity, understanding the different disciplines — defensive security, offensive security, identity, governance, fraud prevention, investigation, among others — and how they connect to business projects.
Solid knowledge of the software development lifecycle for digital channels, understanding all phases (design, development, testing/acceptance and production) and their respective security control points.
Experience in people management or technical leadership, either via indirect leadership or mentoring security professionals.
Executive communication skills, with the ability to present complex topics clearly and concisely to non-technical audiences.
Familiarity with frameworks and market regulations: OWASP, CIS, NIST, LGPD or PCI-DSS.
Knowledge of the financial market and Central Bank regulations applicable to fintechs and banking channels (advantage).
Experience in budget management, vendor contracts and defending investments in security (advantage).
Direct experience in software development, especially in digital channels (web, app or backend) (advantage).
Ability to guide the development of internal platforms (web/backend) for demand management, AI and assessments (advantage).
Tech Stack
Cloud
Benefits
We have a culture that values diversity, differences and people's potential!