RecargaPay
Chief Information Security Officer (CISO)
About this role
Come Make an Impact on Millions of Brazilians! At RecargaPay, we’re on a mission to deliver the best payment experience for Brazilian consumers and small businesses, by building a powerful digital ecosystem where the banked and unbanked connect, and where consumers and merchants have a one-stop shop for all their financial needs. We serve over 10 million users and process more than USD 4 billion annually. We’ve been profitable since 2022 and operate our own credit business. We are an AI-first, 100% remote team, scaling in the rapidly changing Brazilian financial market. Our goal? Deliver the best payment experience in Brazil for people and small businesses alike. We value autonomy, ownership, and a bias for action. We’re looking for people who are curious, hands-on, and driven by impact, who want to solve real problems, work with strong teams, and rethink what’s possible. If you’re ready to do your best work, at scale, with purpose, this is your place. Responsibilities We are seeking a Chief Information Security Officer (CISO) with a strategic mindset, strong technical expertise, and exceptional leadership capabilities to protect the organization's digital assets, ensure regulatory compliance, and foster a security-first culture embedded within the business. The CISO will be responsible for defining, leading, and executing the corporate Information Security and Business Continuity strategy, acting as a strategic partner to executive leadership. This executive is expected to influence critical product, technology, and operational decisions while balancing risk management, regulatory requirements, and innovation speed. The successful candidate will have the autonomy to structure teams, establish security standards, define security architectures, and drive the continuous evolution of the company’s cybersecurity maturity.
- Define, implement, and continuously evolve the corporate Information Security strategy, aligning it with business objectives and sustainable organizational growth;
- Lead and develop Security Engineering, SOC, GRC, Application Security, Blue Team, and Red Team functions;
- Manage the corporate Governance and Risk Management program, including periodic cyber risk assessments and mitigation plan tracking;
- Ensure ongoing compliance with applicable regulations and standards, including the Central Bank of Brazil (BACEN Resolution No. 4,893), LGPD, PCI DSS, ISO 27001, ISO 22301, and Open Finance requirements;
- Oversee Security Operations Center (SOC) activities, ensuring effective capabilities for incident detection, response, containment, and recovery;
- Lead security initiatives across cloud environments, focusing on modern architectures, Zero Trust models, and critical infrastructure protection;
- Embed security practices throughout the software development lifecycle, promoting the adoption of DevSecOps, SAST, DAST, threat modeling, and secure code review practices;
- Communicate cybersecurity risks to the Board of Directors and C-level executives in a clear, concise, and decision-oriented manner;
- Manage relationships with regulatory authorities, external auditors, certification bodies, and other key stakeholders;
- Design and maintain corporate security awareness and culture programs for all employees;
Benefits
- Competitive and market-aligned salary.
- Remote work — wherever you are, you’re part of the team!
- Home office allowance through a monthly deposit in the RecargaPay app.
- Health and dental plans with no co-pay.
- Life insurance.
- Flexible meal allowance (via Flash).
- TotalPass membership to take care of your health. Diversity & Inclusion at RecargaPay At RecargaPay, you’ll have the freedom to be who you are because we believe that diverse perspectives and experiences make us more creative and stronger. Here, everyone is welcome to express themselves authentically. We value the richness of each journey and the multiple ways of seeing the world, without distinctions of gender, race, sexual orientation, age, religion, or any other characteristic that makes us unique. About the use of your Data By sharing your resume with us, you authorize the use of your data for analysis during the selection process and possibly for other opportunities within the RecargaPay group. You can request the update or deletion of your information at any time, in accordance with LGPD (General Data Protection Law). Industry-Specific Knowledge It is desirable to have practical familiarity with one or more core financial domains such as lending, payments, credit cards, open finance, fraud prevention, merchant acquiring, or investment services, along with an understanding of their fundamental workflows and business drivers. Experience in how these domains intersect to influence revenue, risk management, and customer satisfaction is highly valued. Ideally, candidates will have applied this knowledge to deliver solutions such as loan-origination engines with real-time decisioning; scalable payment-processing platforms integrated with core banking systems and third-party gateways; secure open-finance interfaces compliant with industry regulations; automated fraud-detection pipelines leveraging behavioral analytics; or financial reporting and reconciliation engines for regulatory compliance. The ability to translate complex compliance mandates (e.g., KYC/AML, PCI-DSS, GDPR) into resilient, high-performance systems without compromising user experience is considered a strong asset.