Senior DPO & CISO managing information security and data privacy at Rox Partner consultancy. Leading cybersecurity strategy and compliance with ISO 27001 and LGPD.
Responsibilities
Lead the company's Information Security and Cybersecurity strategy.
Maintain and evolve the ISMS in accordance with ISO/IEC 27001.
Act as the Data Protection Officer (DPO) before the ANPD, ensuring compliance with the LGPD.
Define, review and ensure adherence to security and privacy policies.
Plan and conduct internal audits and support external audits.
Design, operate and evolve the SOC (internal or outsourced).
Define and execute monitoring, vulnerability management and incident response processes.
Act directly on critical incidents (log analysis, containment, eradication and recovery).
Manage security tools such as SIEM, EDR/XDR, Firewall, WAF, IAM, DLP and CASB.
Conduct DPIA/RIPD and manage privacy incidents.
Serve as the technical and executive interface with clients, partners, auditors and regulatory bodies.
Requirements
Degree in IT, Information Security, Engineering or related fields
Solid experience in Information Security and Cybersecurity
Mandatory knowledge of ISO/IEC 27001 and LGPD
Experience with SOC, SIEM, EDR/XDR and incident response
Knowledge of cloud security (AWS, Azure or GCP)
Experience with NIST, CIS and MITRE ATT&CK frameworks
Certifications such as ISO 27001 Lead, CISSP, CISM, CDPO, CEH, GCIH
Experience with audits and regulated environments
Hands-on profile with strategic and executive vision
Benefits
Hybrid work – Monday to Friday (9:00 AM to 6:00 PM)
Home-office allowance – R$300.00 per month credit on an iFood card for meals/food
Birthday – Rox rewards you with a gift card and a day off to celebrate your special day
Blog – We encourage knowledge sharing; for every 2 approved articles on the Rox blog you publish, you earn a day off
Courses – Full access to RoxSchool, Alura, Pluralsight and O'Reilly for books and talks
Certifications – Certification reimbursement up to R$300.00 (TECHNOLOGY) plus a R$300.00 bonus per certification achieved from these providers
Psychologist support – Two psychotherapy sessions monthly covered by ROX with partner psychologists
Feedz partnership – Gamified platform to improve communication and track sentiment, engagement, feedback, IDP and performance
WellHub (Gympass) – Partnership with gyms and health & wellness apps
Senior Engineer specializing in AI technologies for cybersecurity at Bank of America. Driving integration of AI in threat detection and combating AI - driven threats with innovative solutions.
Director of Security Architecture & Assurance overseeing security controls and assurance programs for a leading quantum computing company in Broomfield, CO with hybrid work options.
Senior Network Security Engineer responsible for designing, implementing, and supporting secure network solutions for clients. Working with Cisco routers, firewalls, and ensuring customer satisfaction with network security.
Cyber Security Implementation Engineer implementing cybersecurity solutions for the National Geospatial - Intelligence Agency. Responsibilities include maintaining cloud - based infrastructure and enhancing cybersecurity posture.
Technical Program Manager driving complex infrastructure and security initiatives in fast - moving SaaS environment. Delivering projects with high standards of reliability, security, and quality.
Information Security Technical Lead managing security compliance and assessments for a financial services leader. Opportunity to work with technology and business stakeholders in a collaborative environment.
Cyber Security Architect at Porsche Digital, responsible for auditing and advising on security architecture. Collaborating with teams to ensure compliance and integrate security into IT systems design.
Info Security Tech Lead evaluating business solutions aligned with security policies. Engaging in vulnerability management and security assessments at Ameriprise India LLP.
Safety & Security Officer safeguarding persons, property, and company assets for Frasers Property in Singapore. Monitoring entry, assisting during emergencies, and ensuring safety and security.
Application Security Programmer - Engineer at State Street focusing on building DevSecOps & AppSec strategies. Partnering with teams to enhance application security across various technologies.