{"id":7283,"date":"2026-07-23T23:53:59","date_gmt":"2026-07-23T23:53:59","guid":{"rendered":"https:\/\/www.hexa-group.pt\/jobs\/cybersecurity-governance-and-operations-specialist-senior\/"},"modified":"2026-08-06T22:52:36","modified_gmt":"2026-08-06T22:52:36","slug":"cybersecurity-governance-and-operations-specialist-senior","status":"publish","type":"company_job","link":"https:\/\/www.hexa-group.pt\/pt\/jobs\/cybersecurity-governance-and-operations-specialist-senior\/","title":{"rendered":"Cybersecurity Governance and Operations Specialist | Senior"},"content":{"rendered":"<p>Idiomas: PT<br \/>\nLocal de Trabalho: Campo Grande<br \/>\nModelo de Trabalho: H\u00edbrido 2x semana<br \/>\nSal\u00e1rio L\u00edquido m\u00e1ximo: N\/D | Fixed Fee: Valor anual indicativo 48 K\u20ac<br \/>\nDisponibilidade M\u00e1xima: N\/D<\/p>\n<p>Seguran\u00e7a <\/p>\n<p>Procuramos um recurso para refor\u00e7ar a equipa de Gest\u00e3o Acessos e Seguran\u00e7a, com o objetivo de ser o Interface do IT para o SOC da NOS, definir pol\u00edticas de seguran\u00e7a de informa\u00e7\u00e3o da empresa e identificar e resolver fragilidades de seguran\u00e7a no ecossistema aplicacional da NOS.<\/p>\n<p>Compet\u00eancias espec\u00edficas:<br \/>\n&#8211; Elevada capacidade para definir e estruturar a Pol\u00edtica de Seguran\u00e7a da Informa\u00e7\u00e3o da Companhia<br \/>\n&#8211; Capacidade para definir e implementar pol\u00edticas de recolha, guarda e tratamento de logs em ambientes aplicacionais complexos<br \/>\n&#8211; Compet\u00eancia para definir a pol\u00edtica e acompanhar a sua execu\u00e7\u00e3o, associadas a um servi\u00e7o de Security Operations Center \u2013 SOC em SIEM IBM-QRADAR<br \/>\n&#8211; Experi\u00eancia na gest\u00e3o de ferramentas de UBA- User Behavior Analysis e NBA \u2013 Network Behavior Analysis<br \/>\n&#8211; Conhecimento de gest\u00e3o de ferramentas de MDM e Endpoint Security (ex: Crowdstrike, TrendMicro)<br \/>\n&#8211; Conhecimentos da norma ISO 27001<br \/>\n&#8211; Capacidade para definir um modelo de gest\u00e3o de acessos assente em perfis funcionais baseado numa pol\u00edtica de role based access control \u2013 RBAC<br \/>\n&#8211; Experi\u00eancia na gest\u00e3o de vulnerabilidade<br \/>\n&#8211; Conhecimento dos processos de desenvolvimento aplicacional de CI\/CD<\/p>\n<p>Valor anual indicativo 48 K\u20ac<\/p>","protected":false},"excerpt":{"rendered":"<p>AO6880 \u00b7 Portugal \u00b7 telecommunications \u00b7 Open<\/p>","protected":false},"featured_media":0,"template":"","meta":{"_acf_changed":false,"boond_id":"6880","boond_reference":"AO6880","boond_place":"","boond_place_label":"Portugal","boond_state":12,"boond_state_label":"Open","boond_start_date":"immediate","boond_closing_date":"","boond_answer_date":"","boond_duration":255,"boond_raw_description":"Idiomas: PT\nLocal de Trabalho: Campo Grande\nModelo Trabalho: H\u00edbrido 2x semana\nSal\u00e1rio L\u00edquido m\u00e1ximo: N\/D | Fixed Fee: Valor anual indicativo 48 K\u20ac\nDisponibilidade M\u00e1xima: N\/D\n\n\nSeguran\u00e7a \n\nProcuramos um recurso para refor\u00e7ar a equipa de Gest\u00e3o Acessos e Seguran\u00e7a, com o objetivo de ser o Interface do IT para o SOC da NOS, definir pol\u00edticas de seguran\u00e7a de informa\u00e7\u00e3o da empresa e identificar e resolver fragilidades de seguran\u00e7a no ecossistema aplicacional da NOS.\n  \nCompet\u00eancias espec\u00edficas:\n- Elevada capacidade para definir e estruturar a Pol\u00edtica de Seguran\u00e7a da Informa\u00e7\u00e3o da Companhia\n- Capacidade para definir e implementar pol\u00edticas de recolha, guarda e tratamento de logs em ambientes aplicacionais complexos\n- Compet\u00eancia para definir a pol\u00edtica e acompanhar a sua execu\u00e7\u00e3o, associadas a um servi\u00e7o de Security Operations Center \u2013 SOC em SIEM IBM-QRADAR\n- Experi\u00eancia na gest\u00e3o de ferramentas de UBA- User Behavior Analysis e NBA \u2013 Network Behavior Analysis\n- Conhecimento de gest\u00e3o de ferramentas de MDM e Endpoint Security (ex: Crowdstrike, TrendMicro)\n- Conhecimentos da norma ISO 27001\n- Capacidade para definir um modelo de gest\u00e3o de acessos assente em perfis funcionais baseado numa pol\u00edtica de role based access control \u2013 RBAC\n- Experi\u00eancia na gest\u00e3o de vulnerabilidade\n- Conhecimento dos processos de desenvolvimento aplicacional de CI\/CD\n\nValor anual indicativo 48 K\u20ac","boond_criteria":"ABOUT THE OPPORTUNITY\n\nWe are looking for a Senior Cybersecurity Governance and Operations Specialist to support a hybrid opportunity in Lisbon within the telecommunications sector, strengthening information security governance, access management and application security practices across complex technology environments.\n\nWHAT YOU WILL DO\n\n- Act as the IT interface with Security Operations Center teams, supporting alignment between operational security monitoring and internal information security requirements.\n- Define, structure and maintain information security policies, ensuring alignment with business, technology and compliance needs.\n- Establish policies for log collection, retention and processing across complex application environments.\n- Support the definition and execution of SOC-related policies in SIEM environments.\n- Identify, analyze and support the resolution of security weaknesses across the application ecosystem.\n- Define and promote an access management model based on functional profiles and role-based access control principles.\n- Contribute to vulnerability management activities, supporting prioritization, remediation follow-up and continuous security improvement.\n\nWHAT WE ARE LOOKING FOR\n\n- Senior professional experience in cybersecurity governance, security operations, access management or application security within complex IT environments.\n- Strong ability to structure security policies, translate requirements into practical controls and follow through on implementation.\n- Experience working with multidisciplinary IT, security and operations stakeholders.\n- Responsible, analytical and solution-oriented mindset, with the autonomy required to manage sensitive security topics.\n- Ability to work in a hybrid model in Lisbon.\n\nTECHNICAL SKILLS\n\n- Information security policy definition and governance.\n- SOC operating models and SIEM-based monitoring processes.\n- IBM QRadar.\n- User Behavior Analysis and Network Behavior Analysis tools.\n- Mobile Device Management and endpoint security tools.\n- CrowdStrike or Trend Micro.\n- ISO\/IEC 27001.\n- Role-based access control and identity and access management principles.\n- Vulnerability management.\n- CI\/CD application development processes.\n- Log collection, retention and processing policies.\n\nCOMPENSATION TRANSPARENCY\n\nBase salary range: EUR 28,000 - EUR 40,000 gross\/year\nTotal compensation: up to EUR 50,000\/year\nThe salary range is based on objective and gender-neutral criteria, including required competencies, professional experience, level of responsibility and role requirements. Final compensation will be determined according to the candidate's profile and position requirements.\n\nWHAT WE OFFER\n\n- Private health insurance from the first day, with no waiting periods and optional family extension.\n- Confidential mental health support through TEAM 24, including psychological support, content and live sessions.\n- Continuous development and learning opportunities, including structured training and certification support.\n- Flexibility whenever the role and context allow it, supporting sustainable delivery and daily balance.\n- Childcare vouchers and practical family support measures.\n- Team moments, shared milestones and leadership presence when it matters most.\n- Opportunities to strengthen knowledge in information security, cybersecurity best practices and governance-oriented delivery.\n\nEQUAL OPPORTUNITY\n\nHexa is committed to equal opportunity, inclusion and respectful recruitment practices, aligned with the principles of the Portuguese Diversity Charter. We welcome applications from people with different backgrounds, experiences and perspectives.\n\nHEXA LIFE\n\nAt Hexa, every professional is a Builder. We work with honesty, mutual support and agility, contributing to projects, solutions and professional relationships that are built with responsibility, transparency and long-term impact.","boond_expertise_area":"telecommunications","boond_is_visible":true,"boond_created_at":"2026-07-23T13:53:30+0200","boond_created_ts":1784807610,"boond_updated_at":"2026-07-30T18:59:32+0200","boond_type_of":1,"boond_mode":1,"boond_active_positionings":1,"boond_manager_id":"17496","boond_agency_id":"1","boond_agency_label":"Hexa Consulting","boond_pole_id":"1","job_location":"Portugal","job_contract":"telecommunications","job_business_unit":"Hexa Consulting","job_seniority":"Senior","job_title_without_seniority":"Cybersecurity Governance and Operations Specialist","job_remote_url":"","job_source":"boond","manatal_hash":"","manatal_status":"","job_last_synced_at":"2026-08-06 22:52:36"},"class_list":["post-7283","company_job","type-company_job","status-publish","hentry"],"blocksy_meta":[],"acf":[],"_links":{"self":[{"href":"https:\/\/www.hexa-group.pt\/pt\/wp-json\/wp\/v2\/company_job\/7283","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexa-group.pt\/pt\/wp-json\/wp\/v2\/company_job"}],"about":[{"href":"https:\/\/www.hexa-group.pt\/pt\/wp-json\/wp\/v2\/types\/company_job"}],"version-history":[{"count":1,"href":"https:\/\/www.hexa-group.pt\/pt\/wp-json\/wp\/v2\/company_job\/7283\/revisions"}],"predecessor-version":[{"id":7289,"href":"https:\/\/www.hexa-group.pt\/pt\/wp-json\/wp\/v2\/company_job\/7283\/revisions\/7289"}],"wp:attachment":[{"href":"https:\/\/www.hexa-group.pt\/pt\/wp-json\/wp\/v2\/media?parent=7283"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}