Connect with a cause that needs you!

Senior Information Security Engineer

Remote
Full-time
16th August 2026
Listed today

Salary 

Competitive, depending on experience

Location

Brazil (remote)

Summary of the role

The Senior Information Security Engineer leads the protection of Lhasa’s internal environment: the infrastructure, platforms, SaaS solutions, and tools that the organisation depends on to operate. This role owns specific security control domains, drives compliance programmes, and governs the AI tool adoption risk that is central to Lhasa’s evolving workplace.

At senior level, the expectation shifts from executing defined tasks to owning outcomes. You will work with significant autonomy, making independent judgements on risk and control decisions, orchestrating external specialist capability where skills are not held in-house, and setting the standard for how AI tools are assessed and governed across the organization.

You will also provide mentorship across IT and Software Development, modelling AI-first ways of working and supporting the function’s evolution. Where decisions carry material business risk or require architectural authority, you will engage the Lead Security Engineer.

You will report to the Lead Security Engineer.

Main Responsibilities

Infrastructure and Environment Security
  • Own the security of Lhasa’s cloud infrastructure, internal systems, and colleague-facing tooling, maintaining a continuously improving security posture.
  • Lead vulnerability management across the corporate environment: designing assessment processes, prioritising findings by risk, and driving remediation through to closure.
  • Manage and optimise AI-powered security platforms (SIEM, MDR, DLP, IAM), evaluating coverage, tuning alert quality, and decommissioning or replacing tools as the landscape evolves.
  • Lead incident investigation and response for corporate environment incidents, coordinating containment, technical recovery, and post-incident improvement.
  • Conduct and commission penetration testing of Lhasa’s operational environment, managing scope, reviewing findings, and tracking remediation.
  • Monitor the threat landscape proactively, adjusting controls in response to new attack patterns – with particular attention to AI-enabled threats targeting corporate environments.
AI Tool Governance and Shadow IT
  • Develop and own Lhasa’s framework for assessing new AI tools, covering data handling, model training policies, API security, vendor contractual obligations, and supply chain risk.
  • Lead all AI tool security assessments, producing clear risk verdicts and recommended usage conditions for business stakeholders.
  • Maintain Lhasa’s inventory of approved AI tools, associated data handling conditions, and review schedules.
  • Monitor for shadow AI activity across the organisation, identifying unapproved tool use and managing it through the governance framework rather than as a compliance failure.
  • Advise the Leadership team on emerging AI governance obligations and recommend updates to Lhasa’s risk appetite as the tool landscape evolves.
Compliance, Regulatory, and Member Assurance
  • Own Lhasa’s compliance with ISO 27001, leading control implementation, evidence management, and preparation for external audits and certification renewals.
  • Manage Lhasa’s obligations under GDPR, UK data protection law, and the EU AI Act, ensuring controls remain current as regulatory requirements evolve.
  • Produce and maintain member-facing assurance materials that accurately reflect Lhasa’s security posture and data handling practices.
  • Lead supplier security assessments and manage the ongoing security obligations in key third-party relationships.
  • Engage with external auditors, certification bodies, and regulators on corporate security matters, preparing evidence and representing Lhasa’s position.
Policy, Governance, and Stakeholder Engagement
  • Develop and maintain corporate security policies, ensuring they reflect AI-era threats, current regulatory obligations, and Lhasa’s operational context.
  • Own the guardrail documentation governing how colleagues interact with AI tools, refreshing it as the tool landscape and threat patterns change.
  • Translate complex security risk into clear business language for non-technical stakeholders and senior leadership.
  • Advise Tech teams on security requirements for infrastructure, tooling, and platform decisions.
  • Lead security awareness initiatives, building colleague understanding of AI tool risk and corporate security responsibilities.
AI Adoption and Ways of Working
  • Design corporate security workflows around AI-directed processes, with human expertise concentrated on judgement, governance, and exception handling.
  • Actively use AI tools to expand vulnerability coverage, automate compliance documentation, and accelerate risk assessment cycles.
  • Provides mentorship across IT and Software Development, modelling AI-first ways of working and supporting capability development across the function.
  • Continuously recalibrate Lhasa’s corporate security controls as AI changes both the internal tool landscape and the external threat environment.

Skills and Knowledge

Professional Experience
  • Extensive information security experience, particularly in corporate or operational environments.
  • Proven experience leading ISO 27001 compliance programmes independently, including audit preparation and certification maintenance.
  • Demonstrated experience managing and optimising security platforms (SIEM, MDR, DLP, IAM).
  • Experience leading vulnerability management programmes and coordinating penetration testing activities.
  • Experience assessing third-party and AI tool security risk, with clear accountability for findings and recommendations.
  • Track record of working autonomously on complex security problems and delivering outcomes without close supervision.
Knowledge and Frameworks
  • Deep understanding of cloud security principles and tools
  • Strong working knowledge of NIST, ISO 27001, CSA, GDPR, and UK data protection law.
  • Solid understanding of AI-specific security risks: data leakage, model training on customer inputs, API security, shadow AI risk, and supply chain exposure.
  • Working knowledge of the EU AI Act and its implications for AI tool governance within an organisation.
  • Expertise in security testing methodologies including vulnerability scanning, penetration testing, and red teaming.
Behaviours and Ways of Working
  • Outcome ownership: accountable for the security posture of Lhasa’s corporate environment, not just for running defined activities.
  • Proactivity: identifies emerging risks and governance gaps before they become incidents, proposing remediation with a clear rationale.
  • Orchestration: directs external specialists effectively, integrating their outputs into Lhasa’s security posture rather than treating them as isolated deliverables.
  • Communication: translates technical risk findings into business language for senior stakeholders
  • Mentorship: builds colleagues’ security capability and strengthens expertise across the organization.
  • Adaptability: continuously recalibrates as AI changes the internal tool landscape and external threat environment.
Desired
  • CISSP, CISM, or equivalent professional certification.
  • Experience in a regulated industry or compliance-intensive environment.
  • Familiarity with ISO 42001 or EU AI Act governance obligations.