Administrador em Segurança da Informação | Senior
jobgether · Brazil
About The Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Administrador em Segurança da Informação | Senior based in Brazil.
This is a senior-level opportunity focused on protecting and continuously improving enterprise technology <environments.You> will play a key role in strengthening endpoint, network, identity, and privileged-access security.The position combines proactive security administration with vulnerability management and incident <response.You> will help build resilient processes for sophisticated threats, including ransomware and advanced persistent threats.The role also involves translating security events and vulnerabilities into clear technical recommendations and <improvements.You> will work across infrastructure and security domains, contributing to compliance with Brazilian regulations and industry standards.This is an opportunity for an experienced security professional to make a direct impact on the organization's resilience and operational continuity.
Accountabilities
Develop and implement hardening policies for operating systems, servers, endpoints, and network devices, ensuring security configurations remain aligned with organizational standards.
Configure and manage endpoint protection technologies, including antivirus, EDR, XDR, and device-control solutions, while monitoring endpoints for suspicious or anomalous activity.
Apply security patches and updates, conduct vulnerability scans, validate remediation effectiveness in controlled environments, and monitor sources such as NVD, CVEs, and vendor alerts for emerging threats.
Analyze endpoint logs and security events, document incidents, recommend mitigation measures, and support forensic investigations by identifying attack vectors, impacts, and preventive actions.
Develop, maintain, and test incident-response playbooks for scenarios such as ransomware and advanced persistent threats, including tabletop exercises to validate and improve response capabilities.
Prepare and present technical reports and materials covering security incidents, endpoint health, relevant events, current risks, and recommended improvements.
Assess vulnerabilities and their potential impact in accordance with LGPD, ABNT NBR ISO/IEC 27001, and other applicable standards and regulations.
Configure and optimize network segmentation strategies, including VLANs, security zones, and DMZs, as well as Network Detection and Response (NDR) solutions to reduce attack surfaces and identify traffic anomalies.
Manage Identity and Access Management (IAM), including RBAC and ABAC policies, user provisioning and deprovisioning, and multifactor authentication (MFA) flows for critical systems.
Implement and optimize Privileged Access Management (PAM), including secure vaults, automated password rotation, permission audits, and monitoring of privileged-account activity.
Work with Windows and Linux operating systems and contribute to the continuous evolution, security, availability, and resilience of the technology infrastructure.
Requirements
Bachelor's degree in Information Technology, Computer Science, Information Systems, or a related field.
Proven professional experience in Information Security, with employment history demonstrable through a formal employment record or contractor documentation including start and end dates.
Official ITIL 4 Foundation certification or higher.
Advanced, professional, expert, or equivalent certification related to the organization's endpoint protection technology.
One of the following security certifications: ECSA (EC-Council Certified Security Analyst), CySA+ (CompTIA Cybersecurity Analyst), ECIH (EC-Council Certified Incident Handler), or CSIH (Certified Specialist Incident Handler).
Strong knowledge of endpoint security, vulnerability management, incident detection and response, and security event analysis.
Practical understanding of network segmentation, NDR, IAM, RBAC, ABAC, PAM, MFA, and user-access lifecycle management.
Working knowledge of Windows and Linux operating systems.
Analytical and investigative mindset, with the ability to assess complex security events and translate findings into effective technical recommendations.
Strong documentation and communication skills, including the ability to produce and present technical reports and security assessments.
Ability to work proactively, systematically, and collaboratively while maintaining a strong focus on security, risk reduction, and operational continuity.
Benefits
- Health insurance options through Hapvida, Bradesco Saúde, or Unimed, subject to local availability.
- Dental insurance through Hapvida Odonto or Bradesco Dental.
- Alelo meal or food allowance.
- Life insurance fully funded by the employer.
- Transportation allowance.
- Pharmacy partnership.
- Partnerships with universities and educational institutions.
- TotalPass wellness benefit.
- Access to an internal learning and education platform.
- Access to Moodar, including therapy resources.
- Remote work model.
- Opportunity to work in a collaborative environment focused on innovation, professional development, and continuous learning.
- Positions are also open to and preferred for candidates with disabilities (PwD).
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
