Provide structured feedback at an appropriate cadence using one-on-one meetings, performance evaluation tools and formal records, fostering a collaborative and healthy environment;
Align security initiatives with corporate objectives through strategic planning, risk analysis, integration with business areas and the use of governance frameworks;
Delegate tasks and responsibilities using RACI matrices, management systems and alignment rituals to optimize resources and strengthen team capabilities;
Monitor security metrics and events using SIEM, dashboards, automated alerts and periodic reports, anticipating risks and ensuring proactive response;
Ensure compliance with security policies through training, awareness campaigns, internal audits and compliance tools;
Serve as a strategic liaison between security, the business and senior management, contributing to corporate decisions related to risk and continuity.
Requirements
Advanced knowledge of frameworks and regulations: ISO 27001, NIST, CIS Controls;
Information security and risk management (advanced level);
Experience managing information security services and products (SOC, WAAP, content filtering, EDR, NDR, etc.);
Experience leading Application Security (development pipeline perspective, APIs and AppSec models);
Experience managing Information Security teams in complex environments with influence over areas such as Systems Engineering, Solution Architecture and IT infrastructure;
Experience and mindset for results-driven management based on metrics and OKRs;
Focus on team performance and continuous process improvement;
Experience managing vendor relationships and outsourced services;
Experience managing access and identity control teams and ensuring compliance with regulatory requirements;
Analytical ability to interpret reports and metrics.
Benefits
Equal opportunity employer — no distinction by gender, race, color, age, sexual orientation or ethnicity