Plan and design security architectures for corporate projects, including cloud and on-premises environments, producing technical and reference documentation;
Define security requirements for new solutions and validate their compliance throughout the project lifecycle;
Propose, evaluate, and track the roadmap for security solutions;
Provide technical leadership for the implementation of security solutions and controls;
Collaborate with IT Architecture, Digital Channels, BaaS, Open Finance and Business areas to identify needs and recommend new solutions;
Perform risk assessments and threat analysis;
Conduct threat modeling (OWASP Threat Dragon);
Prepare security opinions and technical reports based on technical and regulatory requirements;
Ensure architectures comply with internal and regulatory standards and enforce mandatory application;
Monitor and enforce the Security by Design and Security by Default programs;
Document processes, architectural diagrams, and security flows;
Validate security controls and architectural components such as WAF, DLP, Firewall, IDS, IPS, API Gateway, API Proxy, EDR, SIEM, CNAPP, among others;
Participate in technical committees and multidisciplinary architecture and decision forums;
Manage and support the use of corporate tools from the Gartner quadrant;
Take part in technical interviews, onboarding of new team members, and mentoring;
Deliver internal trainings on tools and best practices;
Produce internal technical content (articles, documentation, guides) and environment control reports;
Support incident response and threat mitigation;
Review, create, and restructure technical documentation;
Continuously monitor the environment, identify improvements, and promote security best practices.
Requirements
Deep technical knowledge of infrastructure, networking, AppSec, data protection, cloud, and security applied to LLMs/AI;
Solid experience in information security with a focus on architecture, cloud security and cyber engineering;
Experience securing cloud environments, including architecture, governance and controls for availability, integrity and confidentiality (AIC), event logging, chain of custody and non-repudiation;
Proficiency with cloud components and infrastructure (IaaS / PaaS / SaaS) and native and third-party protection solutions;
Knowledge of APIs, communication protocols, encryption, key management, and security inventory;
Experience with market-leading tools (Gartner Magic Quadrant), including firewall, EDR/XDR, CASB, SIEM, DLP, CNAPP, password vaults, DevSecOps solutions, among others;
Deep understanding of security technologies: firewalls, IDS/IPS, SIEM, DLP, EDR, Web Filtering, Cloud Security, API Security and encryption;
Skill with threat modeling and frameworks such as OWASP;
Experience in incident management and technical response;
Industry certifications (e.g., CISSP, CCSP, CEH, AZ-500, SC-200, ISO 27001) are a plus;
Strong analytical skills, clear communication, organization, and problem-solving abilities;
Ability to work in multidisciplinary environments with a collaborative attitude and delivery focus.
Benefits
Medical Assistance;
Dental Assistance (Omint);
Life Insurance;
Profit Sharing (PLR);
PPR (performance-based profit sharing);
"ABC with You": a program that supports employees and their families with legal, social, psychological and financial assistance;
Meal Voucher;
Grocery Voucher;
Extended parental leave: 20 days paternity and 6 months maternity;
Childcare/Babysitting Assistance;
Annual Day Off;
Home Office Allowance;
Home Office Infrastructure Allowance;
TotalPass;
Job title
Senior Information Security Analyst – Architecture, Cloud Security
Segment Risk Manager supporting the Cybersecurity segment with risk management and governance. Collaborating on risk assessments and providing advisory on standards and practices.
Penetration Testing Coordination Leader managing pre - testing activities and pipelines. Mentoring teams and ensuring timely execution of penetration tests in financial services context.
Sales Representative responsible for B2B IT - Security Consulting services. Focused on active sales, relationship management, and new business opportunities in cybersecurity.
Leading Cybersecurity Consulting initiatives and teams to drive client security strategies at Schönbrunn TASC GmbH. Ensuring the development of secure digital solutions and fostering client relationships.
Security Engineer focusing on detection and response and collaborating with teams to secure infrastructure at Semperis. Building security monitoring solutions and contributing to risk management.
IT Engineer managing network and security infrastructures for industrial clients. Focused on proactive development and troubleshooting in a collaborative team environment.
Cyber Security Management Consultant supporting clients with ISMS implementation and transitional audit preparation. Focused on secure implementation of information security management systems and client relationship management in cyber security.
Information Security Officer ensuring effective ISMS for aedifion's energy - efficient building solutions. Focusing on continuous development, employee safety, and security controls in a tech - driven environment.