Senior Information Security Risk and Controls Analyst

🔥 19 hours ago

🇧🇷 Brazil – Remote

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 10%

infoinfo

🗣️🇧🇷🇵🇹 Portuguese Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of ASAAS

ASAAS

501 - 1000 employees

Founded 2010

💼 Consulting

🏥 Healthcare

🏨 Hospitality

Consulting • Healthcare • Hospitality

ASAAS is a leading producer of 360° virtual tours in virtual reality. The company specializes in creating customized virtual tours, utilizing advanced technologies, including 360° video, drone technology, and interactive features, to enhance business visibility and engagement. With a commitment to quality and customer satisfaction, ASAAS offers immersive experiences for various industries, including schools, hotels, museums, and healthcare facilities, and aims to elevate online presence through innovative virtual solutions.

📋 Description

• Lead the full cycle of information security risk identification, analysis, assessment, and treatment based on ISO/IEC 27005 • Apply and evolve the organization’s risk methodology, including qualitative matrices and quantitative models where applicable • Define and track risk treatment plans through closure or formal acceptance • Maintain and test the information security controls framework, assessing effectiveness, exceptions, and corrective action plans • Conduct maturity assessments and gap analyses based on ISO/IEC 27001/27002, NIST CSF, and CIS Controls • Conduct vendor and third-party risk assessments (TPRM) • Structure and maintain KRIs/KPIs and produce technical and executive reports • Serve as a technical advisor to Product, Engineering, Cloud, Compliance, and Legal teams • Support formal risk acceptance and exception management processes through documentation, governance, and periodic reviews

🎯 Requirements

• Demonstrated experience in information security risk management • Strong practical and in-depth knowledge of ISO/IEC 27005 • Solid knowledge of ISO/IEC 27001/27002, NIST CSF, and CIS Controls • Experience managing vendor and third-party risk (TPRM), including due diligence, criticality assessments, and monitoring contractual requirements • Ability to design control effectiveness testing, manage evidence, and track action plans through closure • Strong technical writing and communication skills, with the ability to translate complex risks into clear language for executive audiences • Highly organized, self-directed, and sufficiently senior to lead complex analyses with minimal supervision • Preferred: certifications such as ISO 27005 Risk Manager, CRISC, or ISO 27001 Lead Implementer/Auditor • Preferred: experience with quantitative risk modeling (FAIR or equivalent) • Preferred: experience in regulated environments, particularly payment institutions or financial institutions subject to regulations issued by the Central Bank of Brazil

🏖️ Benefits

• Medical and dental insurance with no copayment • Life insurance • Medication assistance • Fitness allowance • Four free monthly therapy or nutritionist sessions through Zenklub • Quick massage at the headquarters • Flexible meal benefit on a Visa card • Free food at the headquarters • Childcare assistance • Parental support program • Extended maternity and paternity leave • In-company training platform • Education assistance covering 70% of tuition for undergraduate programs and language courses, as well as courses and books • Home office allowance • Work equipment • Furniture allowance • Partnership with WOBA for coworking access throughout Brazil • Birthday month day off • Happy hour allowance • Referral bonus for new hires • Annual performance-based bonus • Stock options plan • No dress code

Apply Now

Similar Jobs

🕒 Yesterday

GFT Technologies

10,000+ employees

💼 Consulting

🛡️ Insurance

🔒 Cybersecurity

Senior Cloud Security Engineer securing complex AWS infrastructure for GFT Technologies' regulated financial-services clients. Automating controls, managing vulnerabilities, and supporting compliance audits.

🗣️🇧🇷🇵🇹 Portuguese Required

AWS

Cloud

Terraform

VMware

🕒 Yesterday

Neon

1001 - 5000

💼 Consulting

🛡️ Insurance

💳 Fintech

Engenheiro especialista em segurança cloud liderando redes AWS, firewalls Palo Alto e soluções Zscaler na Neon. Automatização com Terraform e estratégia SASE/Zero Trust para proteger serviços financeiros.

🗣️🇧🇷🇵🇹 Portuguese Required

AWS

Azure

Cloud

Firewalls

Google Cloud Platform

TCP/IP

Terraform

🕒 2 days ago

ROIT

51 - 200

💼 Consulting

⚖️ Legal

☁️ SaaS

Analista de Segurança Ofensiva e Detecção na ROIT, empresa que fortalece sua estrutura de Cybersecurity. Simulando adversários e convertendo resultados em detecção e resposta.

🗣️🇧🇷🇵🇹 Portuguese Required

Cyber Security

Python

🕒 2 days ago

Montreal Oficial

1001 - 5000

🔒 Cybersecurity

☁️ SaaS

Arquiteto de Segurança em TI definindo arquiteturas para redes, telecomunicações, ambientes híbridos e multicloud na Montreal. Avaliação técnica de soluções e elaboração de pareceres especializados.

🗣️🇧🇷🇵🇹 Portuguese Required

🕒 2 days ago

Montreal Oficial

1001 - 5000

🔒 Cybersecurity

☁️ SaaS

Arquiteto de Segurança em TI na Montreal, empresa brasileira de tecnologia. Definindo arquiteturas, criptografia e estratégias DevSecOps para aplicações móveis.

🗣️🇧🇷🇵🇹 Portuguese Required