Security Engineering Lead ensuring Creditas maintains innovation and integrity in product security and incident response. Leading multi-disciplinary teams in a hybrid work environment.
Responsibilities
People Management: Lead and develop multidisciplinary teams (AppSec, CloudSec, Blue Team, and Incident Response), focusing on technical mentorship and career development.
Defense Strategy: Define the detection, monitoring, and incident response (Blue Team) roadmap, ensuring our threat visibility is best-in-class.
Product Security: Influence the software development lifecycle (SDLC), ensuring AppSec and cloud security (CloudSec) practices are integrated and automated within the CI/CD pipeline.
Incident Response: Serve as the focal point for critical incidents, coordinating containment, eradication, and post-incident reviews to drive continuous improvement.
Collaboration: Work closely with Engineering and Product teams to demystify security and make it a business enabler rather than a blocker.
Requirements
Leadership Experience: Proven experience managing technical security teams or serving as a senior Tech Lead.
Holistic Perspective: Solid knowledge in at least two of the areas under your responsibility (e.g., expertise in AppSec and a strong background in Incident Response).
Engineering Mindset: Experience with security automation and infrastructure-as-code (Terraform, CloudFormation) in AWS or GCP environments.
Assertive Communication: Ability to translate complex technical risks into business-impact terms for stakeholders.
Prior experience in fintechs or highly regulated environments (e.g., BACEN, LGPD).
Active engagement in the security community (talks, CTFs, Bug Bounty).
Availability for hybrid work: required to attend our office in the Morumbi area of São Paulo once per month for 4 consecutive days, usually in the last or first week of the month (Creditas in Person).
Benefits
Health Plan (Alice)
Dental Plan (SulAmérica)
Wellz: 100% free therapy sessions
Wellhub: access to gyms and studios
Creditas Endurance: high-impact sports incentive program
Pharmacy agreement (Univers)
Life Insurance (Porto Seguro)
Birthday day off
Extended parental leave: 6 months for birth parents and 35 days for non-birth parents
Family Care: support program for maternity and paternity
Manager of Cybersecurity and Compliance responsible for global cybersecurity and privacy at Hunter Industries. Leading teams, overseeing cybersecurity solutions, and ensuring compliance across the organization.
Security Specialist responsible for security operations at the Hibikinada Offshore Wind Farm. Collaborating with teams to ensure safety and compliance with local regulations.
Director of Partnerships driving revenue growth through podcast advertising and event sponsorships at War on the Rocks. Building and managing a pipeline while collaborating with company leadership.
IT Security and Information Risk Advisor at Scottish Government’s Cyber Security Unit, providing expertise in managing cyber and information risks and developing security policies.
Non - executive Member supporting governance and strategic direction at Social Security Scotland. Involves contributing to the delivery of devolved benefits across Scotland.
Senior Information and Cyber Security Officer at Social Security Scotland handling risks and providing advice. Leading the risk management activities and contributing to security initiatives to enhance governance.
Lead Cybersecurity Advocate at Humana designing and delivering training programs to enhance cybersecurity culture. Collaborating with leaders to develop education and manage cybersecurity training initiatives.
Project Manager overseeing cybersecurity and infrastructure projects for Almond in Sèvres. Leading cross - functional teams to secure digital environments and ensure compliance.
Cybersecurity Analyst role involving penetration testing and security assessments at Bupa. Supporting processes and collaborating with teams to protect customer information and assets.
InfoSec Compliance Administrator supporting Sabio's Infosec team in Cape Town managing security activities and ISO certification programmes. Working within a dynamic culture and developing your skills.