Sobre esta vaga de Information Security and Business Continuity Officer na Aambience Services
Aambience Services is an innovative company, providing workflow automation solutions and information technology services. What makes us different is our strong desire to challenge the status quo, inspire and create ground-breaking solutions. We build relationships of trust with our clients, on solid foundations of quality and know-how, while creating great experiences, through great customer service.
Our team consists of experienced professionals with a passion for their work. They are the cornerstone of our company’s dynamic culture and stand as strong and reliable partners towards our customers’ concerns and needs. This is why we have built a diverse environment that maximizes employee engagement and performance, based on our key value to invest in and develop our people and teams.
The Role
We are looking for an Information Security & Business Continuity Officer to lead the design, implementation, and continuous improvement of Aambience’s Information Security Management System (ISMS) and Business Continuity Management System (BCMS).
In this role, you will ensure compliance with applicable regulations and industry standards, drive risk management initiatives, coordinate internal and external audits, and strengthen the organization’s overall security and operational resilience. Working cross-functionally, you will promote a culture of security awareness and business continuity across all levels of the organization.
Key Responsibilities
- Governance & Frameworks: Design, deploy, and maintain information security and business continuity policies, standards, and procedures in alignment with ISO 27001 and ISO 22301.
- Audit & Certification: Lead the end-to-end certification and continuous compliance processes for ISO 27001 and ISO 22301, serving as the primary interface for external auditors.
- Risk & Impact Management: Conduct security risk assessments, Business Impact Analyses (BIA), and Disaster Recovery (DR) testing. Establish a Third-Party Risk Management framework to control vendor-related exposure.
- Reporting & Metrics: Define, track, and analyze KPIs/metrics, transforming complex technical risks into actionable reporting for Top Management.
- Security Culture & Awareness: Develop and execute organization-wide training programs to enforce security, privacy, and operational resilience standards.
- Compliance: Ensure full alignment with applicable legal, regulatory, and privacy requirements (including GDPR).
Requirements
Skills
- 5+ years of progressive experience in Information Security or CISO-level responsibilities, preferably within fast-paced or scale-up environments.
- Hands-on track record of successfully obtaining and maintaining ISO 27001 and ISO 22301 certifications.
- Deep knowledge of ISO standards (27001, 22301, 27018, 27701) and regulatory frameworks (GDPR).
- Operational familiarity with Incident Management, Vulnerability Assessments, Penetration Testing, and Enterprise Security Architecture.
Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Engineering, or a relevant technical discipline.
- Required Certification (at least one): CISM, CISSP, ISO 27001 LA/LI, or ISO 22301 LA/LI.
Strategic & Execution Skills
- Proven ability to balance strategic risk evaluation ("big picture") with tactical execution ("getting things done").
- Strong stakeholder management skills; ability to communicate technical concepts to both Top Management and engineering teams.
- Leadership capacity to influence cross-functional teams without direct authority.
Benefits
- 💸 Competitive renumeration package
- 🏥 Private medical insurance
- 🎯 Performance based bonus
- 📚 Training & development opportunities
- 🤝 A team that loves innovation, quality, and having fun at work
- ⚖️ Work-life balance
If you want to actively contribute to shaping a culture of continuous learning and improvement, send us your resume and become part of our exciting journey!