Description
Job Summary:
We are seeking a professional to define the security strategy, lead incident response, design security governance, and drive innovation.
Key Highlights:
1. Positive environment and culture of excellence
2. Opportunity for professional growth and development
3. Innovation in security and process automation
We are GuestWorld, a company specialized in outsourcing and human resources development. We operate under a culture of excellence and foster a positive environment, aligning our clients' objectives with the motivation of our people. We focus on effective solutions, continuous training, and partnerships built on trust and value creation.
**Responsibilities:**
* Define the organization's security strategy and roadmap;
* Assume responsibility for the security architecture of critical infrastructures;
* Lead high-impact security incidents and coordinate the response;
* Design and implement a security governance model;
* Conduct Purple Team exercises, promoting collaboration between Red Team and Blue Team;
* Collaborate with architecture teams on defining and adopting secure design patterns;
* Lead compliance and audit programs covering multiple standards and frameworks;
* Define security metrics and KPIs for leadership reporting;
* Represent the security function in stakeholder meetings;
* Manage relationships with security vendors, including tool evaluation and selection;
* Drive security innovation, including DevSecOps, shift-left, and security process automation.
**Requirements:**
* Bachelor’s degree in Computer Engineering or related fields (preferred);
* Enterprise-wide and multi-cloud security architecture;
* Development of security programs, including policies, standards, and procedures;
* Advanced penetration testing and Red Team techniques using the MITRE ATT&CK framework;
* Security orchestration and automation, including SOAR and runbook automation;
* Data protection and Privacy Engineering, including encryption, DLP, and data governance;
* Security of distributed systems (e.g., microservices, service mesh, and Zero Trust architectures);
* Cloud-Native security, including CSPM, CWPP, container security, and serverless environments;
* Regulatory compliance, including SOC 2, ISO 27001, GDPR, DORA, PCI DSS, and HIPAA;
* Security operations, including SOC design and evolution, SIEM optimization, and threat hunting;
* Large-scale identity and access management, including enterprise SSO and identity federation.
**Preferred Certifications:**
* CISSP;
* OSCP;
* GIAC;
* Cloud Security.
**Benefits:**
* Competitive salary and comprehensive benefits package;
* Continuous training and role-specific certifications;
* Opportunity for professional growth and development;
* Dynamic and collaborative work environment;
* A growing company with a promising future.
*See how we handle your data at* *www.guestworld.pt*