Overview

Information Security Manager Jobs in São Paulo, São Paulo, Brazil at Korn Ferry

Title: Information Security Manager

Company: Korn Ferry

Location: São Paulo, São Paulo, Brazil

Global Financial Institution

Company Overview

Our client is a leading global financial institution with operations across multiple countries. In Brazil, the company focuses on corporate and investment banking.

Globally, the organization continues to strengthen its cyber security, risk and compliance agenda, with a strong focus on audit readiness, access management, governance and consistent execution across local and global structures. In Brazil, Information Security is evolving from a predominantly reactive model into a more proactive, documented and technically grounded function.

This managerial position is part of that evolution: bringing senior technical leadership, stronger audit interface and people management capacity to support the leadership team and accelerate execution across Information Security.

Purpose of the Position

To strengthen the company’s Information Security leadership in Brazil by bringing a senior, technically grounded manager capable of leading the local structure, supporting audit and regulatory demands, and accelerating the maturation of security governance, access management and technical controls.

The manager will report to the Information Security leadership and will assume responsibility over the main fronts of the area: technical security, governance and access management. The role will directly lead the coordinators/consultants responsible for these pillars and influence the broader team, including analysts and third-party vendors.

This position is being created at a moment of relevant transformation. The company is addressing audit issues, documenting and strengthening processes, building its master plan, and implementing a significant Access Management initiative in partnership with global stakeholders, including a new global framework and potential deployment of market-leading IAM tools after the initial phase.

The role requires a manager who is more technical and senior than the current team configuration, able to challenge assumptions, propose pragmatic solutions, review technical topics, and represent Information Security in discussions with technology, audit, risk, global stakeholders and business areas.

A key expectation is to reduce dependency on the senior leadership in audit and global interactions. The person must be capable of taking the front seat in English, navigating internal and external audits, influencing local and global stakeholders, and saying no when needed through alignment, diplomacy and fact-based arguments.

Main Challenges

  • Assume leadership of the Information Security team structure, directly guiding the leaders of technical security, governance and access management, influencing analysts and third-party vendors.
  • Become the main front-facing point for audit-related discussions, reducing dependency on senior leadership in internal, external and global audit interactions.
  • Drive the evolution of open audit issues and remediation plans, ensuring that owners, deadlines, evidence, dependencies and risks are clearly managed and escalated when needed.
  • Lead and support the Access Management transformation with global stakeholders, including new frameworks, tooling, IAM governance, access reviews, SoD and alignment with global practices.
  • Provide senior technical input to the Information Security master plan, process documentation and control maturity agenda, bringing best practices and pragmatic solutions.
  • Challenge and influence technology, audit, risk and business stakeholders with clear arguments, strong communication and the ability to manage conflict without creating unnecessary friction.
  • Navigate multicultural dynamics across local and global stakeholders, using pre-alignment, stakeholder mapping and diplomatic communication before formal decision forums.
  • Ensure day-to-day security activities remain stable across technical controls, governance processes, access management and vendor execution.
  • Help shift the area from a reactive posture to a more proactive, documented and audit-ready operating model.

Experiences and Professional Qualifications

  • Senior experience in Information Security within regulated environments, from banks, financial institutions, insurance companies or organizations exposed to strong audit and regulatory pressure.
  • Solid technical background in cyber security, including infrastructure security, networks, vulnerability management, hardening, security tools, incident response and IS controls.
  • Proven experience dealing with internal and external audits, with the ability to explain technical topics, negotiate remediation plans, anticipate findings and produce reliable evidence.
  • Knowledge of financial services regulation and Central Bank expectations is highly desirable, especially in environments with complex controls, governance and risk management requirements.
  • Experience with IAM, access governance, access reviews, SoD, privileged access concepts and security impacts across infrastructure, data and application environments.
  • People leadership experience, managing from coordinators to multidisciplinary teams, with the maturity to influence direct reports, peers, vendors and global stakeholders.
  • Advanced English is mandatory, including the ability to lead discussions, challenge positions, align expectations and represent Information Security with global stakeholders.
  • Bachelor's degree or higher in Technology, Engineering, Computer Science, Information Security or related areas.
  • Experience in banking environments, global institutions, audit-intensive organizations and tools such as IAM platforms, SIEM, DLP, EDR, vulnerability scanners and security monitoring solutions is considered a differential.

Behavioral

  • Senior Technical Leadership & Judgment — Demonstrates enough technical depth to challenge, prioritize and validate security decisions, while leading teams through ambiguity and pressure.
  • Diplomatic Influence & Conflict Management — Navigates difficult discussions with audit, technology, business and global stakeholders, saying no when necessary, through facts, alignment and constructive alternatives.
  • Ownership, Accountability & Execution Rhythm — Takes responsibility for issues, follows through on remediation plans, keeps stakeholders aligned and creates discipline around deadlines, evidence and risk decisions.
  • Global Communication & Cultural Navigation — Communicates clearly in Portuguese and English, understands the importance of pre-alignment, and adapts effectively to local and global working styles.
Upload your CV/resume or any other relevant file. Max. file size: 800 MB.