Senior Information Security Analyst
1 semana atrás
Welcome to KTO Group, where innovation drives excitement in iGaming. Founded in 2018 by Andreas Bardun, we're transforming online gaming with a focus on transparency and player satisfaction.
At , we blend the thrill of sports betting with online casino entertainment, tailored to local markets and powered by our proprietary platform for a seamless, personalized experience.
KTO is a rising leader in LATAM, proudly ranked among Brazil's top 10 iGaming brands. Join us as we set new standards in trust, innovation, and the future of iGaming.
Summary Of The Position
We are looking for an experienced and highly skilled Senior Information Security Analyst to join our IT & Security team. In this role, you will be responsible for leading efforts to protect our organization's information systems from security threats and vulnerabilities. You will work closely with cross-functional teams to develop, implement, and monitor security measures that align with industry best practices and regulatory requirements. Your expertise will be crucial in safeguarding our digital assets and ensuring the integrity, confidentiality, and availability of our data.
Main Responsibilities
- Develop, implement, and maintain a comprehensive information security governance framework, including policies, standards, and procedures that align with business objectives and regulatory requirements (e.g., LGPD, GDPR, ISO/IEC
- Maintain and continuously improve the security policy lifecycle, ensuring clarity, ownership, and compliance across the organization.
- Act as the document custodian for all security governance artifacts (e.g., security policies, exception registers, control frameworks).
- Lead enterprise-wide risk assessments to identify security and privacy risks, determine likelihood and impact, and design risk treatment plans that align with business risk tolerance.
- Maintain and enhance the corporate risk register, mapping threats to controls and tracking mitigation activities with control owners.
- Deliver threat and vulnerability analyses that feed into continuous improvement of risk posture and security controls.
- Ensure ongoing compliance with applicable laws, regulations, and frameworks (e.g., LGPD, GDPR, ISO 27001), providing evidence-based documentation for all key controls.
- Manage and coordinate internal and external audits, including scoping, readiness preparation, control walkthroughs, remediation planning, and stakeholder communication.
- Maintain audit trails and compliance dashboards, enabling timely and transparent reporting to executives and regulators.
- Maintain the organization's Incident Response Plan (IRP), ensuring alignment with legal obligations, business continuity plans, and best practices (e.g., NIST
- Lead or support the incident management lifecycle, including detection, analysis, containment, eradication, recovery, and root cause analysis.
- Coordinate post-incident reviews (PIRs), capturing lessons learned, assigning ownership of corrective actions, and updating relevant policies and controls.
- Establish incident playbooks, escalation paths, and communication protocols, including compliance-related notification procedures (e.g., data breach disclosures under LGPD).
- Work with technical teams to ensure incident detection tools (SIEM, endpoint monitoring, CASB) are properly integrated into GRC oversight and tracking systems.
- Support security operations with governance-driven use cases, ensuring security tools (e.g., SASE, SIEM, CASB) produce audit-friendly logs, evidence, and compliance metrics.
- Monitor security dashboards and alerts, reporting meaningful insights and exceptions to the GRC committee and stakeholders.
- Help evaluate vendors and third-party platforms to ensure they meet GRC criteria and supply appropriate audit documentation.
- Design and deliver targeted security awareness and compliance training programs for employees, contractors, and leadership teams.
- Act as a key liaison between Legal, Compliance, IT, and other business units to embed security governance across the organization.
- Communicate GRC posture, control effectiveness, and security metrics to senior leadership and executive stakeholders in a clear, actionable format.
- Stay abreast of regulatory changes, security threats, and GRC best practices, and recommend strategic improvements to enhance the organization's resilience.
- Identify and lead projects for automation and efficiency in compliance monitoring, policy enforcement, and audit readiness.
Experience & Qualifications Required
- Proven experience with information security tools and platforms relevant to risk management, compliance monitoring, and governance (e.g., SIEM, GRC suites, vulnerability management tools, CASB, SASE).
- Demonstrated ability to design and implement information security strategies with a strong emphasis on governance, regulatory compliance, and enterprise risk management.
- Strong understanding of information security frameworks and standards such as ISO/IEC 27001, NIST CSF, LGPD, and GDPR.
- Ability to lead cross-functional initiatives, influence control owners, and drive alignment between security goals and business requirements.
- Exceptional analytical, problem-solving, and documentation skills with a high level of attention to detail — particularly in audit preparation and risk evaluation.
- Excellent written and verbal communication skills, with the ability to translate complex security concepts into business-friendly language for executives and stakeholders
At KTO, diversity isn't just a buzzword – it's our strength. We're all about creating an inclusive environment where everyone feels valued and empowered. Together, we're not just working on projects – we're making a real impact in our communities. Join us in celebrating diversity and driving meaningful change
KTO is licensed for Brazilian sports betting and online gaming under Portaria 2.093/2024, ensuring a secure and regulated environment for our operations.
Participation is prohibited for:
Individuals under 18 (eighteen) years of age;
Public agents with duties directly related to the regulation, control, and supervision of the activity within the federative entity in whose personnel framework they perform their duties;
- Persons who have or may have any influence on the outcome of a real event with a sports theme subject to fixed-odds lottery betting, including:
- Persons holding positions as sports directors, sports coaches, trainers, and members of the technical staff;
- Referees of sports, referee assistants, or equivalents, sports entrepreneurs, agents or representatives of athletes and coaches, coaches or members of the technical staff;
- Members of the administrative or supervisory body of entities responsible for organizing competitions or sporting events;
- Athletes participating in competitions organized by entities within the National Sports System;
Individuals diagnosed with gambling addiction, according to a diagnosis from a qualified mental health professional.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
-
Security Engineer
1 semana atrás
Porto Alegre, Rio Grande do Sul, Brasil Euronext Tempo inteiroWe are looking for a Senior Security Engineer to join our team in Porto office. The successful candidate will play a key role in designing, implementing and maintaining security solutions to protect our organisation's infrastructure and data. This position requires hands-on expertise with Firewalls (e.g., Fortinet, CheckPoint, Palo Alto), proxy solutions...
-
Senior Engineer
2 semanas atrás
Porto Alegre, Rio Grande do Sul, Brasil ADP Tempo inteiroADP SBS RS division is hiring a Senior Engineer (SRE)In this role, you will build ADP's Retirement Services solutions to help our customers save time, stay compliant, offer and manage retirement plans to their employees. You will work within a Scrum team to bring the designs and ideas to life for new backend microservices, APIs and other systems.You will...
-
Senior Engineer
2 semanas atrás
Porto Alegre, Rio Grande do Sul, Brasil ADP Tempo inteiroADP SBS RS division is hiring a Senior Engineer (SRE)In this role, you will build ADP's Retirement Services solutions to help our customers save time, stay compliant, offer and manage retirement plans to their employees. You will work within a Scrum team to bring the designs and ideas to life for new backend microservices, APIs and other systems.You will...
-
Regulatory Analyst
Há 2 dias
Porto Alegre, Rio Grande do Sul, Brasil Euronext Tempo inteiroJoin Euronext Group as a Regulatory Analyst V.I.E, based in Porto, with a start date of 1st January 2026 and contribute to the strategic development of Europe's leading market infrastructure. As part of the Group Regulation team, you will support regulatory analysis, market monitoring, and strategic alignment across Euronext's diverse entities, with a...
-
Security Compliance Analyst
2 semanas atrás
Porto Alegre, Rio Grande do Sul, Brasil Azion Technologies Tempo inteiroSobre a AzionSomos uma empresa global de tecnologia especializada em aplicações e segurança digital. Nossa plataforma ajuda empresas a operar com mais agilidade, reduzindo o tempo de resposta e aumentando a confiabilidade de seus sistemas.Na Azion, nosso propósito é simplificar a construção de aplicações e transformar o futuro com tecnologia de...
-
Senior Developer
1 semana atrás
Porto Alegre, Rio Grande do Sul, Brasil ADP Tempo inteiroAt ADP we are driven by your success.We engage your unique talents and perspectives. We welcome your ideas on how to do things differently and better. In your efforts to achieve, learn and grow, we support you all the way. If success motivates you, you belong at ADP.Technology at ADP.It's the foundation of the products and services that have made us a...
-
Especialista em segurança da informação
1 semana atrás
Porto Alegre, Rio Grande do Sul, Brasil G4F Tempo inteiroEspecialista em Gestão de Segurança da Informação (Presencial - Brasília)Atribuições:Apoiar gerencialmente nas ações de segurança cibernética;Apoiar na elaboração, implantação, monitoramento, avaliação e manutenção de normativos de segurança da informação;Apoiar gerencialmente os processos de auditoria interna de segurança...
-
Gerente de segurança da informação
1 semana atrás
Porto Alegre, Rio Grande do Sul, Brasil G4F Tempo inteiroEspecialista em Gestão de Segurança da Informação (Hibrido - Brasília - 2x) Salario: R$ 20.264,93+ Benefícios CLT Se interessou? Encaminhe seu CV atualizado juntamente com sua pretensão salarial para o e-mail: Atribuições:Apoiar gerencialmente nas ações de segurança cibernética;Apoiar na elaboração, implantação, monitoramento, avaliação e...
-
Senior Networking Engineer
1 semana atrás
Porto Alegre, Rio Grande do Sul, Brasil Jolera Inc. Tempo inteiroJob Description Who We Are Jolera stands as a distinguished multinational Global Systems Integrator (GSI), a vanguard in delivering comprehensive and bespoke IT solutions to a diverse clientele, encompassing both direct customers and channel partners across the globe. We are driven by a commitment to excellence, leveraging a team of over 650 highly skilled...
-
Senior Developer
1 semana atrás
Porto Alegre, Rio Grande do Sul, Brasil ADP Tempo inteiroADP is hiring a Senior Developer You will start your day on a scrum call to sync up the sprint work and goal with your team. You will spend most of your day designing, developing and testing your code and supporting your team members. You will be able to deploy your code in production using automated continuous integration and continuous deployment.You will...