Security Engineering Lead ensuring Creditas maintains innovation and integrity in product security and incident response. Leading multi-disciplinary teams in a hybrid work environment.
Responsibilities
People Management: Lead and develop multidisciplinary teams (AppSec, CloudSec, Blue Team, and Incident Response), focusing on technical mentorship and career development.
Defense Strategy: Define the detection, monitoring, and incident response (Blue Team) roadmap, ensuring our threat visibility is best-in-class.
Product Security: Influence the software development lifecycle (SDLC), ensuring AppSec and cloud security (CloudSec) practices are integrated and automated within the CI/CD pipeline.
Incident Response: Serve as the focal point for critical incidents, coordinating containment, eradication, and post-incident reviews to drive continuous improvement.
Collaboration: Work closely with Engineering and Product teams to demystify security and make it a business enabler rather than a blocker.
Requirements
Leadership Experience: Proven experience managing technical security teams or serving as a senior Tech Lead.
Holistic Perspective: Solid knowledge in at least two of the areas under your responsibility (e.g., expertise in AppSec and a strong background in Incident Response).
Engineering Mindset: Experience with security automation and infrastructure-as-code (Terraform, CloudFormation) in AWS or GCP environments.
Assertive Communication: Ability to translate complex technical risks into business-impact terms for stakeholders.
Prior experience in fintechs or highly regulated environments (e.g., BACEN, LGPD).
Active engagement in the security community (talks, CTFs, Bug Bounty).
Availability for hybrid work: required to attend our office in the Morumbi area of São Paulo once per month for 4 consecutive days, usually in the last or first week of the month (Creditas in Person).
Benefits
Health Plan (Alice)
Dental Plan (SulAmérica)
Wellz: 100% free therapy sessions
Wellhub: access to gyms and studios
Creditas Endurance: high-impact sports incentive program
Pharmacy agreement (Univers)
Life Insurance (Porto Seguro)
Birthday day off
Extended parental leave: 6 months for birth parents and 35 days for non-birth parents
Family Care: support program for maternity and paternity
Manager at PwC contributing to digital transformation in Utilities through technology consulting and stakeholder management. Focused on creating strategies and providing technology solutions in a data - driven world.
Research Associate conducting advanced research in iOS security within a leading institute for applied cybersecurity. Emphasis on secure application development and vulnerability analysis.
Cybersecurity Engineer focused on threat monitoring and incident response for Verizon's network security. Collaborating on security architecture and vulnerability management across multiple locations.
Senior Manager of Application Security leading initiatives to protect applications at Nordstrom through strategic leadership and AI - driven tooling. Collaborating with engineering to ensure secure software development practices.
Information Security Engineer responsible for deploying and supporting security tools across cloud and on - premise systems. Collaborating with IT to mitigate security risks in a hybrid work environment.
Casual Retail Security Officer for MSS Security ensuring safety at Tweed Mall in Tweed Heads. Responsible for patrols, incident response, and customer service.
Financial security advisor at Desjardins developing client relationships and selling life and health insurance products. Focusing on customer satisfaction and personalized financial solutions.
Principal Information Security Consultant at Westpac focusing on security protocols and employee benefits for staff. Hybrid role centrally located with opportunities for professional development and employee perks.
Engineer supporting secure development lifecycle processes for product lines in the energy sector. Collaborating with R&D on security requirements and compliance audits.
Automation Oversight Engineer providing oversight of compliance in automated device configurations for Comcast Business. Managing configuration checks and reporting, ensuring reliable oversight and improvement strategies.