Devoteam Cyber Trust | Security Manager | Retail & E-commerce Sector
Lisboa, Portugal
Devoteam
Transform your bussines with Devoteam, the AI-driven tech consulting. Become a leading company embracing AI for sustainable value.Company Description
Devoteam Cyber Trust is the Cybersecurity specialist arm of the Devoteam Group. With our 800+ experts located across EMEA, we aim to establish cybersecurity as an enabler of business success rather than a gatekeeper. We leverage an end-to-end approach to Cyber Resilience, Applied Security, and Managed Security services to secure the tech journey of large and medium-sized companies from all sectors and industries.
Since 2009, previously known as INTEGRITY, our team based in Portugal is specialised in providing cutting-edge Managed Security Services that combine its expertise and proprietary technology to consistently and effectively reduce the cyber risk of our clients.
The comprehensive service range includes Persistent Intrusion Testing, ISO 27001, PCI-DSS, GRC Consulting and Solutions, and Third-Party Risk Management. ISO 27001 (Information Security) and ISO 9001 (Quality) certified, PCI-QSA, and member of CREST and CIS - Centre for Internet Security, we provide services to a considerable number of clients, operating in more than 20 countries.
Job Description
- Collaborate with Compliance Manager to ensure compliance with A-to-Be security policies, standards and procedures
- Determine project-specific security requirements
- Ensure criteria is defined for product acceptance in respect to relevant regulatory and security standards
- Ensure project-specific core security policies and plans are defined and be accountable for their execution:
- Patch Management Policy
- Incident Response Plan
- Business Continuity and Disaster Recovery Plan
- Provide security guidance and recommendations during project planning and execution
- Ensure that the implemented solution complies with security criteria defined for the project
- Work with Compliance Manager, the development teams and businesses in analyzing applications to identify and resolve security vulnerabilities and exploits
- Provide regular reports on security, risks, and improvement efforts to project leadership
- Serve as the primary point of contact for managing security incidents and analyze post-incident reviews and feedback to improve security measures
Qualifications
- Education & Certifications: Bachelor's/Master’s in Computer Science, Cybersecurity, or related field; CISSP, CISM, or ISO 27001 certification is a plus.
- Experience: Proven background in cybersecurity, compliance, and security risk management; familiarity with ISO 27001, NIST, GDPR.
- Technical Skills: Expertise in security policies, threat detection, vulnerability management, cloud security (AWS, Azure), and DevSecOps.
- Soft Skills: Strong analytical, communication, and collaboration abilities; experience working with compliance, development, and business teams.
- Other: Incident management, security assessments, and Business Continuity/Disaster Recovery planning.
Additional Information
What we offer:
- Professional development and monitoring talent;
- Commitment to our employees' development;
- Collaboration in a company that is constantly growing and evolving;
- Strong organisational culture: collaboration, sharing, flexibility, integrity and low ego.
Would you like to join our team? Then send your CV.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: AWS Azure CISM CISSP Cloud Compliance Computer Science CREST DevSecOps E-commerce Exploits GDPR Incident response ISO 27001 Monitoring NIST Risk management Security assessment Threat detection Vulnerabilities Vulnerability management
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.