Senior Information Security Governance Analyst

Job not on LinkedIn

🔥 4 minutes ago

🇧🇷 Brazil – Remote

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 12%

infoinfo

🗣️🇧🇷🇵🇹 Portuguese Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of IPIRANGA

IPIRANGA

51 - 200 employees

Founded 1969

🏭 Manufacturing

🚘 Automotive

Manufacturing • Automotive

IPIRANGA is a specialist in the design and manufacture of high precision ball screws, resulting from a merger of Shuton and Ipiranga. With over 50 years of experience each, they provide a comprehensive product portfolio divided into three main families: XP Xtrem Position for high-performance positioning applications, XL Xtrem Load for heavy-duty applications, and XT Xtrem Transport for automation technologies. In 2023, IPIRANGA joined The Timken Company, enhancing its product offerings and market reach.

📋 Description

• Support and enhance Information Security Governance, Risk, and Compliance (GRC) processes • Ensure compliance with corporate policies, regulatory requirements, internal controls, and industry best practices • Lead activities involving risk management, audits, metrics, awareness, documentation, third-party management, and tracking of Information Security action plans • Draft, review, and maintain Information Security policies, standards, procedures, and controls • Support internal and external audit processes • Track nonconformities and remediation plans • Produce evidence for audits and regulatory assessments • Support initiatives related to ISO 27001, SOX, and other compliance requirements • Perform cybersecurity risk identification, assessment, and monitoring activities • Support maintenance of the risk register • Monitor risk treatment plans and risk acceptances • Prepare executive reports on the evolution of Information Security risks • Conduct security assessments of vendors and partners • Support third-party onboarding and approval processes • Review Information Security requirements in contracts • Track remediation activities for critical vendors • Plan and execute Information Security awareness campaigns • Coordinate simulated phishing campaigns • Develop communications and training materials • Monitor the effectiveness metrics of awareness programs • Keep departmental documentation up to date • Structure evidence for audits and certifications • Support the organization of the repository for processes, controls, and standards • Ensure compliance with corporate documentation standards • Consolidate Information Security metrics • Prepare dashboards and executive presentations • Track risk, audit, third-party, and awareness metrics • Support governance forums and internal committees

🎯 Requirements

• Bachelor's degree in Information Technology, Information Security, Engineering, Information Systems, or a related field • Experience in Governance, Risk, and Compliance (GRC) • Experience with IT audits • Experience in risk management and internal controls • Experience drafting policies, standards, and procedures • Experience leading Information Security awareness programs • Required knowledge of risk management • Required knowledge of Information Security governance • Required knowledge of IT auditing • Required knowledge of ISO 27001 • Required knowledge of internal controls • Required knowledge of third-party management • Required knowledge of metrics and key performance indicators • Required knowledge of developing documentation and audit evidence

🏖️ Benefits

• Flexible working hours • Support for children with disabilities • Variable compensation program • Private pension plan • Tenure-based additional pay • Online therapy and nutritional guidance • Newborn care package • Corporate university • Gympass • Meal and food vouchers • Transportation voucher • Health and dental insurance • Life insurance

Apply Now

Similar Jobs

🕒 Yesterday

CI&T

5001 - 10000

💼 Consulting

🏥 Healthcare

📣 Marketing

Senior GRC Security Analyst managing cybersecurity risk, controls, audits, and compliance for CI&T, a technology company transforming enterprises through AI and digital solutions.

Cyber Security

🕒 Yesterday

ROIT

51 - 200

💼 Consulting

⚖️ Legal

☁️ SaaS

Analista de Segurança Ofensiva e Detecção fortalecendo a cibersegurança da ROIT. Simulação de adversários, engenharia de detecção e evolução de controles Purple Team.

🗣️🇧🇷🇵🇹 Portuguese Required

Cyber Security

Python

🕒 Yesterday

ROIT

51 - 200

💼 Consulting

⚖️ Legal

☁️ SaaS

Gerente previdenciário liderando equipe técnica e projetos de consultoria previdenciária. Gestão de entregas, riscos, legislação, compensações e recuperação de créditos para clientes.

🗣️🇧🇷🇵🇹 Portuguese Required

🕒 Yesterday

NinjaOne

1001 - 5000

☁️ SaaS

🔒 Cybersecurity

🤝 B2B

Application Security Architect securing NinjaOne’s endpoint management platform across Brazil, Colombia, Ecuador, and Mexico. Leading threat modeling, secure architecture reviews, and software security initiatives.

AWS

Cloud

Java

Kotlin

Linux

C++

🕒 3 days ago

ROIT

51 - 200

💼 Consulting

⚖️ Legal

☁️ SaaS

TAX Manager liderando a área previdenciária, equipes e projetos para clientes empresariais. Gestão de conformidade, recuperação de créditos e eficiência operacional.

🗣️🇧🇷🇵🇹 Portuguese Required