Deskripsi Pekerjaan
We are seeking a visionary Director of Cybersecurity & Incident Response to join the leadership team at Coins.Ph. In this high-impact role, you will be responsible for establishing and maintaining the organization's security posture, ensuring full compliance with critical regulatory frameworks, and leading our Incident Response (IR) efforts. This position is formally required to ensure that our operations meet the stringent standards outlined in Article 14, III, "e" of the BCB Resolution and other relevant financial regulations.
As the Director, you will serve as the primary guardian of our digital assets, overseeing a team of security professionals and collaborating with cross-functional departments to integrate security into every layer of the business. You will define the strategy for threat detection, response, and recovery, ensuring that we can swiftly neutralize cyber threats while maintaining business continuity. This is a unique opportunity to drive security strategy in a dynamic fintech environment.
Tanggung Jawab
- Develop and implement a comprehensive cybersecurity strategy and roadmap aligned with business goals and regulatory requirements.
- Lead and manage the Incident Response team to effectively detect, analyze, and respond to security breaches and cyber-attacks.
- Ensure strict compliance with the BCB Resolution and other local financial regulations regarding information security.
- Oversee the design, implementation, and maintenance of security infrastructure, including SIEM, IDS/IPS, and DLP solutions.
- Conduct regular security assessments, penetration testing, and vulnerability management to proactively identify risks.
- Manage third-party relationships and conduct vendor risk assessments for all security service providers.
- Establish and lead security awareness and training programs to cultivate a security-first culture across the organization.
Kualifikasi
- 10+ years of experience in information security, with at least 3-5 years in a senior leadership or director-level role.
- Strong working knowledge of the BCB Resolution (Resolução Bacen 3.645/2021) and Brazilian financial security standards.
- Professional certifications such as CISSP, CISM, or CISA are highly preferred.
- Proven track record of managing large-scale incident response, disaster recovery, and business continuity planning.
- Deep technical expertise in network security, cloud security (AWS/Azure), and application security.
- Excellent communication skills, with the ability to present complex technical concepts to executive stakeholders.
- Fluency in English (Portuguese is a significant asset given the regulatory context).