Talent Pool - Information Security Consultant
MTP – Métodos e Tecnologia is a Spanish multinational with 28 years of operation, present in more than 21 countries, with headquarters in Brazil, Spain, and Mexico. We are specialists in Digital Business Assurance, uniting strategy, technology, and innovation to support large companies in their digital transformation journey. With more than 80 active clients in the Finance, Insurance, Telecom, Industry, Retail, Technology, and Energy sectors, we deliver solutions that guarantee quality, security, and performance throughout the digital cycle.
Responsibilities and assignments Act in partnership with technology delivery teams to ensure that security is incorporated right from the design phase. Engage with development teams to guide them on secure design practices and compliance with the Information Security Policy. Be an ambassador for the use of security best practices (NIS) and approved tools. Perform security reviews as part of the Application Readiness Review (ARR) process. Provide consultancy on various topics related to information security.
Requirements and qualifications Experience in software development areas, such as Developer, Architect, Software QA, or Application Security Engineering. Experience in Cloud Infrastructure Experience with commercial source code analysis tools (Source Code Analysis/Static Application Security Testing). Strong understanding of application architectural patterns (MVC, Microservices, Event-driven, etc.). Good business vision and ability to work with development, QA, and security teams. Knowledge of OWASP Top 10. Experience in software development (web, mobile, and different programming languages). Understanding of vulnerability mitigation processes in source code. Ability to identify risk/acceptance factors that impact business and security decisions. Security vulnerability analysis in applications and execution of mitigation strategies. Experience with scanning tools, code review, and vulnerability identification processes. Ability to evaluate mitigation plans considering vulnerabilities, threats, and current security recommendations. Knowledge of effective controls in: Application Security, Cloud & Hosting, Identity and Access Management, Data Protection, Connectivity, Endpoint Security, and Cybersecurity Operations. Familiarity with the information security standard ISO 27002:2005/2013. Knowledge of cloud application architecture and container-based deployment. Advanced/Fluent English
Desirable: Knowledge and interest in agile methodologies: Agile, XP, Scrum, Kanban. Understanding of Test-Driven Development (TDD) based on User Stories. Familiarity with Continuous Integration, Testing, and Continuous Delivery (CI/CD). Knowledge of cloud architecture and services (Azure, AWS, GCP). Familiarity with tools such as Metasploit, Burp Suite, Fuzzing, and Jenkins. Experience in code reviews and penetration testing (Pentests).
Additional information Work model: Remote Contract type: CLT Benefits: Health insurance Dental insurance Meal voucher Mobility voucher Culture voucher Education voucher Life insurance Mental health and wellness program Childcare assistance Partner discounts
MTP Brasil may use artificial intelligence to support the organization and analysis of applications, to verify compatibility between the professional profile and the job requirements, and to prepare analyses, indicators, and reports of the selection process. The use of AI will have human supervision and will follow the MTP Brasil Artificial Intelligence Policy, available at https://mtp.com.br/politica-de-inteligencia-artificial/. By selecting "yes" when answering the job questionnaire, I declare that I have received clear information about these purposes and, freely, informed, and unequivocally, I authorize the processing of the data provided in my application with the support of artificial intelligence systems. To exercise my rights or, when applicable, revoke consent, I may contact dpo@mtp.com.br.