Information Security Compliance
- Location Lisboa, 11
- Job Type Full Time
- Posted July 7, 2025
About the Role
As an Information Security & Compliance Engineer, you will play a critical role in protecting our infrastructure, applications, and data. You’ll implement and maintain security controls, support compliance initiatives (such as SOC 1, SOC 2, ISO 27001), and collaborate with cross-functional teams to ensure our systems remain secure, private, and resilient.
Key Responsibilities
- Implement and maintain security controls aligned with SOC frameworks, ISO 27001, CIS Benchmarks, and other best practices.
- Support annual compliance audits (SOC 1, SOC 2), including evidence collection, control testing, and remediation tracking.
- Conduct ongoing vulnerability assessments and coordinate remediation with DevOps and infrastructure teams.
- Coordinate penetration testing on web applications in collaboration with independent security specialists.
- Monitor and manage external attack surfaces, advising teams on risk reduction.
- Maintain static code analysis and application security scanning within our SDLC pipelines.
- Define and enforce access control policies, including least privilege and role-based access management.
- Participate in incident response and root cause analysis, ensuring timely resolution and documentation.
- Contribute to security awareness training for employees and contractors.
- Maintain clear documentation for security policies, procedures, and compliance reports.
About You
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- 3+ years of experience in information security, compliance, or IT risk management.
- Solid understanding of cloud security (ideally Microsoft Azure), network security, and endpoint protection.
- Familiarity with compliance frameworks such as SOC 1/2, ISO 27001, and GDPR.
- Hands-on experience with security tools, vulnerability scanners, and SIEM platforms.
- Strong communication and documentation skills.
- Industry certifications (CISSP, CISM, CEH, ISO 27001 Lead Implementer) are a plus.
What’s in It for You?
- Work with a highly collaborative team passionate about security and innovation.
- Significant opportunities for growth in a dynamic, scaling environment.
- Flexible work arrangements—remote or hybrid options.
- Competitive compensation package.
- Comprehensive wellness benefits, including dental, vision, and more.
About the Company
Our client is a rapidly growing, award-winning technology company with a mission to create innovative solutions that make a meaningful impact. They leverage advanced technologies, data-driven insights, and deep industry expertise to help clients improve performance, reduce risk, and exceed customer expectations.
Recognized as a leader in their field, this organization is committed to building a purpose-driven business that benefits employees, customers, partners, and the broader community.
Supported by a well-established growth investment partner, they are embarking on an ambitious expansion plan over the next several years, investing significantly in people, technology, and operations to support their continued growth.
If you value innovation, collaboration, and purpose—and want to be part of a high-performing culture—this is your opportunity to make an impact.
👉 Ready to Apply?
If this sounds like the right fit, we’d love to hear from you. Please submit your CV or get in touch to learn more. You can email me directly at fabienne.viegas@tech-recruitment.eu