Cybersecurity Manager — Digital Platform

Grupo SysMapSão Paulo, São Paulogupypublished 08/18/2026
Must-have:AWSAzureGoogle CloudCloudCI/CDAIFinTechPrincipal
Machine translation — original language: Portuguese.Show original

Are you passionate about technology and innovation?💡 At Grupo SysMap – which brings together SysMap Solutions, TriggoLabs and triggo.ai – we believe that great results come from incredible people. We are a Brazilian technology company that, since 1999, has been helping organizations overcome complex challenges and accelerate their digital transformation. Our operations span various segments, such as Telecom, Retail, Education, Financial, Industry/Cosmetics, and Energy, always focusing on innovative and high-impact solutions.👉 Apply now and build the future of technology with us!

Responsibilities and duties

  • Define and lead the corporate Cybersecurity strategy, ensuring alignment between risk, business, technology, and regulatory requirements;
  • Drive the evolution of information security maturity based on the NIST CSF 2.0 and ISO 27001 frameworks, establishing indicators, goals, and a multi-year roadmap;
  • Manage cybersecurity operations, including SOC, SIEM, and EDR, ensuring continuous monitoring, detection, and incident response in national and international environments;
  • Define and monitor security performance indicators, such as MTTD, MTTR, detection effectiveness, and risk exposure levels;
  • Lead Threat Hunting, Threat Intelligence, and Detection Engineering initiatives for the continuous strengthening of the security posture;
  • Be responsible for Identity and Access Management (IAM) strategies, Privileged Access Management (PAM), and the evolution of Zero Trust architecture;
  • Ensure the application of strong authentication principles, least privilege, segregation of access, and digital identity protection;
  • Conduct vulnerability management programs, penetration testing, Red Team, Purple Team, and continuous attack surface assessments;
  • Define vulnerability prioritization criteria based on risk, exploitability, and business impact;
  • Lead the implementation of SecDevOps practices, incorporating SAST, DAST, SCA, secrets management, and threat modeling into the development cycle;
  • Work in partnership with Engineering, Infrastructure, and Architecture teams to establish automated controls that ensure security without compromising delivery speed;
  • Lead incident response processes, cyber crisis management, business continuity, and disaster recovery;
  • Maintain playbooks, response procedures, and periodic simulation exercises and incident preparedness;
  • Ensure adherence to LGPD requirements, Resolução CVM 35, Banco Central regulations, and other applicable regulations;
  • Conduct risk assessments of suppliers, partners, and third parties, ensuring digital supply chain management;
  • Prepare and present indicators, risks, and action plans to the CTO, executive committees, and the board, translating technical risks into business impacts;
  • Lead Information Security awareness programs, promoting a security culture throughout the organization;
  • Act as the main technical and strategic reference in Cybersecurity, supporting corporate decisions related to information protection, risk management, and digital transformation.

Requirements and qualifications

  • Completed degree in Computer Science, Engineering, Information Systems, or related fields;
  • Minimum of 10 years of experience in Information Security and Cybersecurity;
  • At least 4 years of experience in Cybersecurity team leadership positions, preferably in financial institutions or highly regulated environments;
  • Market certifications such as CISSP, CISM, CRISC, or equivalents;
  • Mastery of NIST CSF 2.0, ISO 27001, ISO 27701, CIS Controls, and MITRE ATT&CK frameworks;
  • Solid knowledge of LGPD, Resolução CVM 35, Banco Central regulations, and other applicable regulatory requirements;
  • Experience in Cloud and Multi-Cloud environment security;
  • Experience with Zero Trust architectures, IAM, PAM, cryptography, key management, and data protection;
  • Knowledge of DLP, network security, endpoint protection, and API security;
  • Practical experience with SOC, SIEM, EDR, and incident detection and response operations;
  • Experience with SOAR, incident response automation, and integration of security controls into CI/CD pipelines;
  • Knowledge of SecDevOps, vulnerability management, and security applied to the software development lifecycle;
  • Experience in cyber risk management, business continuity, disaster recovery, and incident response;
  • Advanced English for interaction with offshore operations, international suppliers, audits, and regulatory bodies.

Differentials

  • Postgraduate degree or MBA in Information Security, Risk Management, Technology, or Business;
  • Technical certifications such as OSCP, GIAC, or equivalents;
  • Cloud security certifications on AWS, Microsoft Azure, or Google Cloud Platform platforms;
  • Experience in applying Artificial Intelligence for anomaly detection, event correlation, and incident response automation;
  • Experience in managing risks related to the corporate adoption of Artificial Intelligence-based solutions;
  • Knowledge of the financial market, especially in the Asset Management, Wealth Management, or Investment Banking segments;
  • Experience in high-criticality environments, with strong regulatory requirements and large volumes of sensitive data;
  • Experience presenting cyber indicators and risks to executive committees, directors, and the board.

Additional information