Remote job
Senior Information Security Engineer
Job details
About this role
Role overview A cloud communications platform is hiring a Senior Information Security Engineer to join its Security Risk Management function. The position focuses on building an engineering-driven program that designs, automates, and scales the controls and workflows protecting infrastructure, services, and customer data. It is a hands-on, cross-functional role partnering with engineering, operations, and business stakeholders to surface, treat, and report on security risk.
Responsibilities - Identify, document, and assess security risks across production infrastructure, cloud services, corporate systems, and acquired platforms. - Maintain the Security Risk Register in Jira, ensuring risks are accurately categorized, assigned to owners, and tracked through their lifecycle. - Engage with service owners, engineering leads, and operations teams to establish risk ownership and drive remediation or mitigation plans. - Facilitate the risk acceptance process, including preparing documentation and coordinating approval with appropriate stakeholders. - Develop risk reporting for security leadership and executive audiences, including dashboards and metrics that communicate risk posture clearly. - Collaborate with compliance, vulnerability management, and other Information Security functions to incorporate risk findings into the broader security program. - Contribute to the development of risk management policies, procedures, and playbooks, and research frameworks to continuously improve program maturity.
Requirements - 3+ years of experience in information security, with at least 2 years focused on security risk management or GRC. - Demonstrated experience maintaining a security risk register and driving risk treatment decisions with cross-functional stakeholders. - Strong understanding of qualitative and quantitative risk assessment methodologies. - Familiarity with security frameworks such as NIST CSF, NIST 800-53, ISO 27001, PCI, or SOC 2. - Ability to communicate security risks clearly to both technical and non-technical audiences. - Experience with Jira or similar tools for tracking and managing risk workflows, and comfort engaging directly with engineers and leadership to resolve ambiguity around risk ownership.
Nice to have - Experience with cloud environments (GCP, AWS, or Azure), particularly assessing risks related to cloud architecture and services. - Familiarity with vulnerability management programs and how they feed into risk management. - Experience supporting compliance audits or regulatory assessments such as ISO 27001, SOC 2, or PCI DSS. - Prior work in a SaaS or contact center / communications platform environment. - Hands-on experience with agentic coding tools (Cursor, Claude Code, Copilot, or similar) and a working knowledge of Python. - Professional certification in Information Security or Risk Management (CISSP, CISM, CISA, CRISC, or equivalent).
Benefits and work setup - Fully remote for candidates residing outside a set of specified Porto-area municipalities; candidates within those municipalities work in-office 3 days per week. - Equity shares, bonus scheme, and a 10% flex benefit. - Meal allowance, medical insurance, and life insurance. - 25 days of annual leave plus public holidays. - Reasonable accommodations available for candidates with disabilities throughout the application and interview process.