
Cybersecurity Analyst
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Brazil.
• Perform risk evaluations of vendors and third-party partners.
• Assess the security measures established by third parties and pinpoint potential vulnerabilities.
• Ensure compliance with corporate information security and risk management policies.
• Identify, document, and monitor mitigation strategies for recognized risks.
• Collaborate with the Governance, Risk, and Compliance (GRC) team in managing information security risks.
• Review documentation, certifications, and compliance attestations provided by vendors.
• Evaluate alignment with industry standards and best practices, including NIST.
• Assist in the implementation and monitoring of security controls.
• Engage in contract evaluations between the company and vendors, ensuring that information security requirements are integrated and adhered to.
• Work closely with Legal and Procurement teams to reduce contractual risks related to security.
• Prepare executive summaries and technical assessments on identified risks.
• Present assessment findings to business areas, managers, and stakeholders.
• Support risk-informed decision-making by offering mitigation suggestions.
• Aid in simultaneous investigations of security incidents.
• Contribute to threat and vulnerability monitoring efforts.
• Generate incident reports and assist senior teams with the analysis and resolution of incidents.
• Background in Information Security, Governance, Risk, or Compliance.
• Familiarity with Third-Party Risk Management (TPRM).
• Proven experience in conducting risk assessments and evaluating security controls.
• Knowledge of security frameworks, particularly: NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001 (preferred).
• Understanding of Governance, Risk, and Compliance (GRC) processes.
• Experience in preparing risk reports and relevant documentation.
• Capability to communicate effectively with both technical and non-technical stakeholders.
• Awareness of vulnerability management and concepts related to security incidents.
• Remote work
Stefanini Brasil
Varicent
Get handpicked remote jobs straight to your inbox weekly.