远程工作雷达

首席信息安全官(CISO)

Chief Information Security Officer (CISO)

开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司RecargaPay
薪资未公开
工作地点Brazil
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 Brazil 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

为数百万巴西人带来影响!
在RecargaPay,我们的使命是通过构建一个强大的数字生态系统,为巴西消费者和小企业提供最佳的支付体验,让有银行账户和无银行账户的人群连接起来,让消费者和商家都能在一个一站式平台上满足所有金融需求。
我们服务超过1000万用户,每年处理超过40亿美元的交易。自2022年以来我们一直保持盈利,并运营自己的信贷业务。我们是一支以人工智能为核心的100%远程团队,在快速变化的巴西金融市场中不断扩展。
我们的目标是为个人和小企业带来巴西最好的支付体验。
我们重视自主性、责任感和行动导向。我们寻找那些充满好奇心、注重实践、以影响力为驱动力的人,他们希望解决真实的问题,与优秀的团队合作,并重新定义可能性。
如果你准备在有目的的前提下,大规模地发挥你的最佳水平,这里就是你的选择。

职责

我们正在寻找一位首席信息安全官(CISO),他需要具备战略思维、扎实的技术专长和卓越的领导能力,以保护组织的数字资产,确保合规性,并在企业内部培养一种以安全为先的文化。
CISO将负责制定、领导并执行公司的信息安全和业务连续性战略,作为高管领导层的战略合作伙伴。这位高管需要在平衡风险管理、监管要求和创新速度的同时,对关键的产品、技术和运营决策产生影响。
成功的候选人将拥有自主权来组建团队、建立安全标准、定义安全架构,并推动公司网络安全成熟度的持续演进。

  • 制定、实施并持续演进公司信息安全战略,使其与业务目标和可持续的组织增长保持一致;
  • 领导并发展安全工程、SOC、GRC、应用安全、蓝队和红队职能;
  • 管理公司治理和风险管理计划,包括定期的网络风险评估和缓解计划跟踪;
  • 确保符合相关法规和标准,包括巴西中央银行(BACEN第4,893号决议)、LGPD、PCI DSS、ISO 27001、ISO 22301和开放金融的要求;
  • 监督安全运营
查看英文原文

Come Make an Impact on Millions of Brazilians!
At RecargaPay, we’re on a mission to deliver the best payment experience for Brazilian consumers and small businesses, by building a powerful digital ecosystem where the banked and unbanked connect, and where consumers and merchants have a one-stop shop for all their financial needs.
We serve over 10 million users and process more than USD 4 billion annually. We’ve been profitable since 2022 and operate our own credit business. We are an AI-first, 100% remote team, scaling in the rapidly changing Brazilian financial market.
Our goal? Deliver the best payment experience in Brazil for people and small businesses alike.
We value autonomy, ownership, and a bias for action. We’re looking for people who are curious, hands-on, and driven by impact, who want to solve real problems, work with strong teams, and rethink what’s possible.
If you’re ready to do your best work, at scale, with purpose, this is your place.

Responsibilities

We are seeking a Chief Information Security Officer (CISO) with a strategic mindset, strong technical expertise, and exceptional leadership capabilities to protect the organization's digital assets, ensure regulatory compliance, and foster a security-first culture embedded within the business.
The CISO will be responsible for defining, leading, and executing the corporate Information Security and Business Continuity strategy, acting as a strategic partner to executive leadership. This executive is expected to influence critical product, technology, and operational decisions while balancing risk management, regulatory requirements, and innovation speed.
The successful candidate will have the autonomy to structure teams, establish security standards, define security architectures, and drive the continuous evolution of the company’s cybersecurity maturity.

  • Define, implement, and continuously evolve the corporate Information Security strategy, aligning it with business objectives and sustainable organizational growth;
  • Lead and develop Security Engineering, SOC, GRC, Application Security, Blue Team, and Red Team functions;
  • Manage the corporate Governance and Risk Management program, including periodic cyber risk assessments and mitigation plan tracking;
  • Ensure ongoing compliance with applicable regulations and standards, including the Central Bank of Brazil (BACEN Resolution No. 4,893), LGPD, PCI DSS, ISO 27001, ISO 22301, and Open Finance requirements;
  • Oversee Security Operations Center (SOC) activities, ensuring effective capabilities for incident detection, response, containment, and recovery;
  • Lead security initiatives across cloud environments, focusing on modern architectures, Zero Trust models, and critical infrastructure protection;
  • Embed security practices throughout the software development lifecycle, promoting the adoption of DevSecOps, SAST, DAST, threat modeling, and secure code review practices;
  • Communicate cybersecurity risks to the Board of Directors and C-level executives in a clear, concise, and decision-oriented manner;
  • Manage relationships with regulatory authorities, external auditors, certification bodies, and other key stakeholders;
  • Design and maintain corporate security awareness and culture programs for all employees;
  • Evaluate, select, and manage information security vendors and strategic partners;
  • Develop, test, and enhance Business Continuity and Disaster Recovery Plans (BCP/DRP), ensuring the company’s operational resilience.

Requirements
Experience and Education

  • Experience in Information Security and in executive or senior leadership positions;
  • Experience in fintechs, digital banks, financial institutions, or companies regulated by the Central Bank of Brazil;
  • Bachelor's degree in Computer Science, Engineering, Information Systems, or related fields;
  • Postgraduate degree, MBA, or specializations in Information Security, Risk Management, or related areas will be considered a plus.

Technical Knowledge

  • Proficiency in cloud security, especially AWS, and in highly available distributed architectures;
  • Strong knowledge of industry frameworks and best practices, such as ISO 27001, NIST Cybersecurity Framework, CIS Controls, and MITRE ATT
  • Hands-on experience with SOC operations, SIEM platforms, EDR, Threat Intelligence, and incident response;
  • Strong understanding of DevSecOps practices, application security, SAST, DAST, and threat modeling;
  • Technical capability to actively participate in architectural discussions with Engineering and Platform teams, contributing beyond a purely managerial perspective;
  • Experience in securing APIs, microservices, and mission-critical digital ecosystems.

Artificial Intelligence and Emerging Technologies

  • Understanding of risks associated with the corporate use of Generative AI, including Shadow AI, sensitive information leakage in LLMs, and prompt engineering-based attacks;
  • Ability to define policies, controls, and guidelines for the secure use of AI tools within the organization;
  • Familiarity with AI and Machine Learning applications focused on fraud detection, behavioral analytics, and incident response automation (SOAR);
  • Critical thinking skills to assess opportunities and risks arising from the adoption of emerging technologies in strategic business processes.

Executive Communication and Leadership

  • Excellent communication skills with Boards of Directors, Executive Committees, and other stakeholders, translating technical risks into business impacts;
  • Experience delivering presentations to auditors, regulators, and risk committees;
  • Ability to influence decisions in matrix organizations and multidisciplinary squads, even without direct formal authority;
  • Proven track record in building, developing, and retaining high-performing technical teams;
  • Ability to balance security rigor, regulatory compliance, and the agility required to support innovation and business growth.

Preferred Certifications

  • CISSP (Certified Information Systems Security Professional);
  • CISM (Certified Information Security Manager).

Benefits
· Competitive and market-aligned salary.

  • Remote work — wherever you are, you’re part of the team!
  • Home office allowance through a monthly deposit in the RecargaPay app.
  • Health and dental plans with no co-pay.
  • Life insurance.
  • Flexible meal allowance (via Flash).
  • TotalPass membership to take care of your health.

Diversity & Inclusion at RecargaPay

At RecargaPay, you’ll have the freedom to be who you are because we believe that diverse perspectives and experiences make us more creative and stronger. Here, everyone is welcome to express themselves authentically. We value the richness of each journey and the multiple ways of seeing the world, without distinctions of gender, race, sexual orientation, age, religion, or any other characteristic that makes us unique.
About the use of your Data
By sharing your resume with us, you authorize the use of your data for analysis during the selection process and possibly for other opportunities within the RecargaPay group. You can request the update or deletion of your information at any time, in accordance with LGPD (General Data Protection Law).

Industry-Specific Knowledge
It is desirable to have practical familiarity with one or more core financial domains such as lending, payments, credit cards, open finance, fraud prevention, merchant acquiring, or investment services, along with an understanding of their fundamental workflows and business drivers. Experience in how these domains intersect to influence revenue, risk management, and customer satisfaction is highly valued.
Ideally, candidates will have applied this knowledge to deliver solutions such as loan-origination engines with real-time decisioning; scalable payment-processing platforms integrated with core banking systems and third-party gateways; secure open-finance interfaces compliant with industry regulations; automated fraud-detection pipelines leveraging behavioral analytics; or financial reporting and reconciliation engines for regulatory compliance. The ability to translate complex compliance mandates (e.g., KYC/AML, PCI-DSS, GDPR) into resilient, high-performance systems without compromising user experience is considered a strong asset.
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

← 返回全部职位