O que esta vaga pede
Come Make an Impact on Millions of Brazilians!
At RecargaPay, we’re on a mission to deliver the best payment experience for Brazilian consumers and small businesses, by building a powerful digital ecosystem where the banked and unbanked connect, and where consumers and merchants have a one-stop shop for all their financial needs.
We serve over 10 million users and process more than USD 4 billion annually. We’ve been profitable since 2022 and operate our own credit business. We are an AI-first, 100% remote team, scaling in the rapidly changing Brazilian financial market.
Our goal? Deliver the best payment experience in Brazil for people and small businesses alike.
We value autonomy, ownership, and a bias for action. We’re looking for people who are curious, hands-on, and driven by impact, who want to solve real problems, work with strong teams, and rethink what’s possible.
If you’re ready to do your best work, at scale, with purpose, this is your place.
Responsibilities
We are seeking a Chief Information Security Officer (CISO) with a strategic mindset, strong technical expertise, and exceptional leadership capabilities to protect the organization's digital assets, ensure regulatory compliance, and foster a security-first culture embedded within the business.
The CISO will be responsible for defining, leading, and executing the corporate Information Security and Business Continuity strategy, acting as a strategic partner to executive leadership. This executive is expected to influence critical product, technology, and operational decisions while balancing risk management, regulatory requirements, and innovation speed.
The successful candidate will have the autonomy to structure teams, establish security standards, define security architectures, and drive the continuous evolution of the company’s cybersecurity maturity.
- Define, implement, and continuously evolve the corporate Information Security strategy, aligning it with business objectives and sustainable organizational growth;
- Lead and develop Security Engineering, SOC, GRC, Application Security, Blue Team, and Red Team functions;
- Manage the corporate Governance and Risk Management program, including periodic cyber risk assessments and mitigation plan tracking;
- Ensure ongoing compliance with applicable regulations and standards, including the Central Bank of Brazil (BACEN Resolution No. 4,893), LGPD, PCI DSS, ISO 27001, ISO 22301, and Open Finance requirements;
- Oversee Security Operations Center (SOC) activities, ensuring effective capabilities for incident detection, response, containment, and recovery;
- Lead security initiatives across cloud environments, focusing on modern architectures, Zero Trust models, and critical infrastructure protection;
- Embed security practices throughout the software development lifecycle, promoting the adoption of DevSecOps, SAST, DAST, threat modeling, and secure code review practices;
- Communicate cybersecurity risks to the Board of Directors and C-level executives in a clear, concise, and decision-oriented manner;
- Manage relationships with regulatory authorities, external auditors, certification bodies, and other key stakeholders;
- Design and maintain corporate security awareness and culture programs for all employees;
- Evaluate, select, and manage information security vendors and strategic partners;
- Develop, test, and enhance Business Continuity and Disaster Recovery Plans (BCP/DRP), ensuring the company’s operational resilience.
Experience and Education
- Experience in Information Security and in executive or senior leadership positions;
- Experience in fintechs, digital banks, financial institutions, or companies regulated by the Central Bank of Brazil;
- Bachelor's degree in Computer Science, Engineering, Information Systems, or related fields;
- Postgraduate degree, MBA, or specializations in Information Security, Risk Management, or related areas will be considered a plus.
Technical Knowledge
- Proficiency in cloud security, especially AWS, and in highly available distributed architectures;
- Strong knowledge of industry frameworks and best practices, such as ISO 27001, NIST Cybersecurity Framework, CIS Controls, and MITRE ATT&CK;
- Hands-on experience with SOC operations, SIEM platforms, EDR, Threat Intelligence, and incident response;
- Strong understanding of DevSecOps practices, application security, SAST, DAST, and threat modeling;
- Technical capability to actively participate in architectural discussions with Engineering and Platform teams, contributing beyond a purely managerial perspective;
- Experience in securing APIs, microservices, and mission-critical digital ecosystems.
Artificial Intelligence and Emerging Technologies
- Understanding of risks associated with the corporate use of Generative AI, including Shadow AI, sensitive information leakage in LLMs, and prompt engineering-based attacks;
- Ability to define policies, controls, and guidelines for the secure use of AI tools within the organization;
- Familiarity with AI and Machine Learning applications focused on fraud detection, behavioral analytics, and incident response automation (SOAR);
- Critical thinking skills to assess opportunities and risks arising from the adoption of emerging technologies in strategic business processes.
Executive Communication and Leadership
- Excellent communication skills with Boards of Directors, Executive Committees, and other stakeholders, translating technical risks into business impacts;
- Experience delivering presentations to auditors, regulators, and risk committees;
- Ability to influence decisions in matrix organizations and multidisciplinary squads, even without direct formal authority;
- Proven track record in building, developing, and retaining high-performing technical teams;
- Ability to balance security rigor, regulatory compliance, and the agility required to support innovation and business growth.
Preferred Certifications
- CISSP (Certified Information Systems Security Professional);
- CISM (Certified Information Security Manager).
- Competitive and market-aligned salary.
- Remote work — wherever you are, you’re part of the team!
- Home office allowance through a monthly deposit in the RecargaPay app.
- Health and dental plans with no co-pay.
- Life insurance.
- Flexible meal allowance (via Flash).
- Total
- Pass membership to take care of your health.
Diversity & Inclusion at RecargaPay
At RecargaPay, you’ll have the freedom to be who you are because we believe that diverse perspectives and experiences make us more creative and stronger. Here, everyone is welcome to express themselves authentically. We value the richness of each journey and the multiple ways of seeing the world, without distinctions of gender, race, sexual orientation, age, religion, or any other characteristic that makes us unique.
About the use of your Data
By sharing your resume with us, you authorize the use of your data for analysis during the selection process and possibly for other opportunities within the RecargaPay group. You can request the update or deletion of your information at any time, in accordance with LGPD (General Data Protection Law).
Industry-Specific Knowledge
It is desirable to have practical familiarity with one or more core financial domains such as lending, payments, credit cards, open finance, fraud prevention, merchant acquiring, or investment services, along with an understanding of their fundamental wo...