- Location
- BRA_Sao_Paulo (05425-902)_Beneficios, Brazil · BRA_Sao_Paulo (05425-902)_Beneficios
- Workplace
- Hybrid
- Type
- Full-time
- Department
- IT
- Seniority
- Senior
- Experience
- 10+ years
- Source
- Workday
Description
At Pluxee, we shape the world of employee benefits and engagement by bringing to life a personalized and sustainable employee experience, at work and beyond.
Permanent RegularJob Description:
Pluxee is a global player in Employee Benefits and Engagement that operates in 28 countries. Pluxee helps companies attract, engage, and retain talent thanks to a broad range of solutions across Meal & Food, Well-being, Lifestyle, Reward & Recognition, and Public Benefits. Powered by leading technology and more than 5,600 engaged team members, Pluxee acts as a trusted partner within a highly interconnected B2B2C ecosystem made up of more than 500,000 clients, 37 million+ consumers, and 1.7 million+ merchants. Conducting business for more than 45 years, Pluxee is committed to creating a positive impact on local communities, supporting well-being at work for employees, and protecting the planet.
This role is responsible for leading the technology and payment strategy, operations, governance, and transformation agenda within a specific country. The role ensures alignment between global technology standards and local business priorities while overseeing technology delivery, operational stability, cybersecurity, infrastructure, workplace services, and business partnership activities.
The Senior Manager of Cybersecurity leads Pluxee’s cybersecurity function in Brazil, ensuring the effective local implementation of the Group cybersecurity roadmap, policies, standards, methodologies, processes, and tools.
The role provides tactical leadership and decision-making for Brazil, protects local projects, applications, information, and business activities, and aligns country priorities with Pluxee’s global cybersecurity strategy.
Also brings local business and regulatory needs into regional and global discussions, working through the Regional Cybersecurity Officer and relevant global teams to shape appropriate solutions.
🚀 What you'll be doing:
Cybersecurity & Business Responsibilities
- Ensure appropriate cybersecurity protection for local projects and applications by applying Group risk-assessment methodologies and coordinating technical security audits.
- Identify threats and coordinate or implement proportionate mitigation measures, including appropriate integration with the Security Operations Center and relevant use cases.
- Maintain visibility of local cybersecurity risks, anomalies, and vulnerabilities; coordinate remediation and escalate material exposures or delays.
- Implement and coordinate local adoption of Group cybersecurity policies, standards, methodologies, processes, and tools.
- Ensure and maintain ISO 27001 certification within the applicable local scope.
- Ensure compliance with applicable local cybersecurity regulations in collaboration with the DPO, Compliance, Safety, Legal, and other relevant stakeholders.
- Support Sales teams in presenting Pluxee’s cybersecurity maturity to customers and prospects using accurate and approved information.
- Represent Pluxee in relevant external information-security communities.
People Management
- Lead and manage the local cybersecurity team, setting priorities aligned with the Group roadmap and Brazilian business requirements.
- Provide clear direction, develop accountability, and lead the local team and multidisciplinary stakeholders.
Incident Management & Operational Responsibilities
- Own country-level cybersecurity incident-response coordination, including internal and customer communications and appropriate escalation.
- Implement regular crisis exercises aligned with the Group’s methodology and coordinate resulting improvement actions.
- Present cybersecurity risks, initiatives, remediation progress, and KPIs regularly to senior local management.
- Promote cybersecurity awareness among employees.
Cybersecurity & Data Protection
- Coordinate or implement controls based on risk and Group standards.
- Apply Group information-classification and protection requirements.
- Collaborate effectively with the DPO, Legal, and Compliance.
- Assess relevant supplier and third-party cybersecurity risks.
Data Protection & Regulatory Compliance
- Collaborate with the DPO, Compliance, and Legal to support compliance with applicable data-protection requirements.
- Ensure appropriate implementation of applicable local cybersecurity and regulatory requirements.
Health & Safety
- Collaborate with Safety and other relevant stakeholders where applicable to local cybersecurity requirements.
Performance & Reporting
- Monitor and report on cybersecurity risks, initiatives, remediation progress, incident response, crisis preparedness, ISO 27001 certification maintenance, regulatory compliance, awareness, and relevant cybersecurity KPIs in Brazil.
- Report to the Local IT Director through the direct reporting line and to the Regional Cybersecurity Officer through the dotted-line reporting relationship.
- Lead the local cybersecurity team.
🌟 You’re a match
- Master’s degree in Computer Science, Information Technology, or a related field.
- CISSP or an equivalent certification is desirable.
- Professional working proficiency in English is required (conversational level)
- At least 10 years of cybersecurity experience, including at least 3 years in a cybersecurity management role.
- Expertise working in financial services, digital banks and payments is preferred.
- Strong technical capability, with experience in cybersecurity risk management, incident response, crisis exercises, and implementation of global requirements in a local environment.
- Experience with fraud screening or interacting with fraud departments is highly valued.
- Technical Skills: Threat Modeling: Identifies credible threats and informs proportionate security measures. Risk Assessments: Applies Group methodology and coordinates risk treatment and escalation. Regulatory Frameworks: Interprets and supports implementation of applicable cybersecurity requirements. Vendor Risk Management & Third-Party Security: Assesses relevant supplier and third-party cybersecurity risks. Cloud Security: Applies relevant Group security requirements to cloud-related initiatives. Legal & Regulatory Expertise: Collaborates effectively with the DPO, Legal, and Compliance Security Controls Implementation: Coordinates or implements controls based on risk and Group standards. Incident Management: Leads local incident coordination, communication, and escalation. Data Classification & Protection: Applies Group information-classification and protection requirements.
- Soft Skills: Communication, continuous learning, leadership, problem solving skills, strategic thinking.
🔎 To get this challenge
- Video call with a Global Talent Acquisition Expert
- Video call or face-to-face with Hiring Manager
- Video call or face-to-face with Local HR Manager/ Regional HR Director
- Video call or face-to-face with Local Country Managing Director
🏅 Your team
- Report: Executive IT Director - Pluxee Brazil
- Dotted Line Report: Regional IT Security Manager
📍 Your location
Sao Paulo, BR
☀️ Happy at work
1) A meaningful job: Be the change! Help us build the future of employee benefits by bringing to life sustainable and personalized experiences and contribute to make a real impact on millions of lives. Our business model delivers not just for individuals but their communities too, by supporting local businesses and economies.
2) A great culture: People matter – a lot! Be part of a multicultural team that moves as one in a fast paced and innovative environment. We respect and care authentically about our people, we embrace wellbeing and work-life balance, new ideas and we have a lot of fun!
3) An empowering environment: Be yourself! At Pluxee we proudly embrace diversity and value the uniqueness of our talents, fostering an inclusive workplace where all abilities are celebrated, and equal learning and growing opportunities are given.
Why join Pluxee?
Join an inclusive team
Work at the heart of the community alongside 5,000 experts across 29 countries - we embrace diversity and value uniqueness, fostering a workplace where everyone can thrive.
Turn inspiration into possibility
Get space to try new ideas, experiment and move the world of work forward as you bring new digital experiences - and moments of connection - to millions of people.
Make a positive impact
Touch millions of lives and create meaningful change for people and the world we share, supporting our commitments to diversity, sustainability, and local economies.
Grow with us
Get support you need to take meaningful steps in your career, whether you're performing your work/life balance or learning new skills.