Remote job
Staff Information Security Engineer
Job details
About this role
Role overview A senior technical role responsible for owning and maturing a Cyber Resiliency program across multi-cloud infrastructure. The position splits focus between running the program as a primary mandate and contributing to cloud security initiatives as a senior technical resource.
Responsibilities - Run the end-to-end operational lifecycle of the Cyber Resiliency program, including tool administration, system mapping, criticality tiering, and issue triage workflows - Build and maintain program governance: process documentation, remediation SLAs, escalation paths, and quarterly review cadences - Produce executive reporting on resilience score trends, remediation velocity, infrastructure-as-code coverage, and risk exposure by criticality tier - Lead the communication plan so engineering teams understand expectations before receiving remediation tickets - Maintain prioritization frameworks that balance system criticality, environment, severity, and remediation effort - Partner with engineering leads to drive remediation of resilience issues, removing blockers and tracking progress - Support cloud security architecture reviews, policy-as-code, guardrails, and automated detection for misconfigurations - Improve cloud security posture across IAM, network segmentation, and workload protection, with solutions deployed via CI/CD
Requirements - 5+ years of experience in information security, with senior-level technical responsibility - Proven track record operationalizing a security program end-to-end: building governance, processes, and reporting rather than only executing existing ones - Deep hands-on experience with at least one major cloud platform (GCP strongly preferred), covering IAM, networking, compute, and storage security - Strong infrastructure-as-code experience with Terraform and CI/CD pipelines - Demonstrated ability to drive remediation and risk reduction across engineering teams without direct authority - Experience producing security reporting and metrics for executive audiences - Strong communication skills and self-direction across competing priorities
Nice to have - Experience with cyber resilience tooling (Gambit, Wiz, or similar CSPM/CNAPP platforms) - Risk or maturity assessments using NIST CSF, ISO 27001, or CMMI - Kubernetes security and container workload protection - Multi-cloud exposure across GCP, AWS, and Azure - Python scripting for automation - Certifications such as CISSP, CCSP, or SANS - Background in SaaS, contact center, or communications platforms - Mentoring or technical leadership of junior engineers
Benefits and work setup Fully remote for candidates outside a specific Portuguese metropolitan area; in-office three days per week for those inside that area. Benefits include an employee share program, bonus scheme, flex benefit, meal allowance, medical and life insurance, and 25 days of annual leave plus public holidays.