Hybrid Information Security Manager – Red Team

Posted 3 weeks ago

Apply now

About the role

  • Gerente de Segurança Ofensiva na C&A encarregado de liderar a gestão de vulnerabilidades digitais e segurança ofensiva. Envolvendo equipe técnica e planejamento anual de testes de segurança.

Responsibilities

  • Define and evolve the Vulnerability Management vision and roadmap for typical retail environments, including e-commerce, mobile applications, APIs, partner integrations, payment methods and corporate infrastructure.
  • Lead the Offensive Security program, covering penetration tests on digital platforms, in-store systems, corporate environments and new projects.
  • Plan, prioritize and approve the annual security testing calendar, taking into account business impact, internet exposure, retail seasonality (e.g., critical commercial dates) and regulatory requirements.
  • Manage multidisciplinary teams (Specialists, Seniors, Mid-level and Junior engineers), promoting technical development, process standardization and a security culture.
  • Define, monitor and report KPIs and OKRs that translate technical risk into business impact (operational continuity, reputation, customer data and payment methods).
  • Coordinate and govern external security testing vendors, ensuring technical quality, methodological adherence and effectiveness of deliverables.
  • Work closely with Technology, Product and other security teams, supporting prioritization and risk mitigation decisions.
  • Conduct analyses and make decisions in critical scenarios, such as emergency vulnerabilities, breached SLAs and support for security incidents.
  • Represent Offensive Security and Vulnerability Management topics in executive forums, committees and audits, both internal and external.
  • Ensure the program’s compliance with internal policies, standards and regulatory requirements, such as LGPD, PCI DSS and other obligations applicable to retail.

Requirements

  • Strong experience in Offensive Security, Penetration Testing and Vulnerability Management in large-scale environments.
  • Practical experience with digital retail environments such as e-commerce, mobile apps, APIs, third-party integrations and payment platforms.
  • Proficiency with security testing methodologies (PTES, OWASP, NIST 800-115, MITRE ATT&CK) and risk-based prioritization.
  • Experience leading technical teams with a focus on delivery, maturity and continuous improvement.
  • Ability to translate technical vulnerabilities into business risk, supporting executive decision-making.
  • Strong written and verbal communication skills with technical audiences, managers and executives.
  • Organized, analytical and results-oriented profile.
  • Ability to work collaboratively in dynamic environments with multiple stakeholders.

Benefits

  • Medical and Dental Insurance (Primary and Dependents)
  • Dr. C&A - Telemedicine and Teletherapy
  • Annual bonus
  • Parking or Commuter Allowance (Work location Alphaville – Barueri/SP)
  • Birthday Off — one paid day off during your birthday month
  • Flexible working hours
  • On-site cafeteria
  • Flexible Meal Benefit (Meal Card and/or Meal Voucher)
  • Gympass
  • Semi-annual vacation
  • “Friend” program (psychological, legal and social support)
  • Pharmacy partnership with payroll discount
  • Discounts on purchases at C&A stores and e-commerce

Job title

Information Security Manager – Red Team

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

No Education Requirement

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job