SENIOR EXPERT INFORMATION SECURITY (HYBRID PORTO)
Portuguese company hires for hybrid position
📍 Location: Porto, Portugal
⚠️ Only candidates already based in Portugal will be considered
💼 Work Model: Hybrid — 2 days per week in the office
🗣️ Language Requirements: Fluent English required
🕓 Seniority: Senior (5-8 years)
💲Rate Between €3600 - 3900 RV or unipessoal (gross value)
⚠️ Instructions: Please send your CV in English and make sure to include all skills and experience that match the requirements of the opportunity. This will significantly increase your chances of success.
About the Opportunity
We are looking for a Senior Information Security Expert to strengthen security governance, risk management, and secure architecture. You will help protect digital assets, support compliance, and align security practices with business and technology needs.
Responsibilities
- Define and enforce security strategies, policies, standards, and controls.
- Assess and oversee security architectures across applications, cloud platforms, and infrastructure.
- Identify and mitigate risks, vulnerabilities, and emerging threats.
- Support compliance with applicable requirements and frameworks, including GDPR, ISO, and SOC.
- Advise teams on secure software design, threat modelling, and security best practices.
- Support incident response, audits, security awareness, and continuous improvement.
Requirements
- 5–8 years of proven experience in Information Security, Cybersecurity, or Platform Security.
- Strong experience in enterprise security environments and complex technology landscapes.
- Expertise in security governance, risk management, and compliance, including security assessments and reviews.
- Strong knowledge of security architecture and secure system design.
- Expertise in Identity and Access Management (IAM), authentication, and authorization.
- Experience with application, cloud, and infrastructure security.
- Familiarity with threat modelling, vulnerability management, security testing, and secure software development.
- Knowledge of SIEM, DLP, endpoint protection, and monitoring tools, with an understanding of Agile environments.
Preferred: CCSP certification. CISSP and CISM are additional advantages.
Ideal Candidate Profile
An analytical and accountable security professional who can translate business needs into practical security controls. Able to influence stakeholders, explain technical concepts clearly, and balance security requirements with usability, performance, and delivery objectives.
5 Questions for Candidates
- Do you have 5–8 years of relevant experience in enterprise information security?
- What experience do you have with security governance, risk assessments, and compliance frameworks?
- Have you designed or reviewed security architectures covering IAM, applications, cloud, and infrastructure?
- How have you supported threat modelling, vulnerability management, incident response, or security audits?
- Are you fluent in English and available to work on-site in Porto 2 days per week?
Keywords
Information Security, Cybersecurity, Security Governance, GRC, Risk Management, Security Architecture, IAM, Authentication, Authorization, Application Security, Cloud Security, Threat Modelling, Vulnerability Management, SIEM, DLP, Incident Response, GDPR, ISO, SOC, CCSP, CISSP, CISM.