
GRC Consultant
Posted Aug 31

Posted Aug 31
This is a fully remote position, open to applicants in Brazil.
• Oversee strategic governance, compliance, risk management, audit, and resilience efforts across Pismo's worldwide operations.
• Create, uphold, and consistently enhance governance frameworks, policies, standards, and procedures.
• Ensure compliance with ISO 27001, SOC 1, SOC 2, PCI DSS, PCI PIN Security, data localization mandates, and other relevant frameworks.
• Perform compliance evaluations, gap analyses, and maturity assessments.
• Organize internal and external audits and assist in the remediation of findings.
• Facilitate enterprise, operational, technology, and cybersecurity risk assessments.
• Maintain risk registers while supporting risk treatment, monitoring, and reporting.
• Work collaboratively with stakeholders to implement mitigation strategies and oversee risk exposure.
• Prepare risk reports and dashboards for executive-level review.
• Assist with security due diligence, client assessments, and assurance requests.
• Manage responses to regulatory inquiries and examinations.
• Articulate Pismo's security, compliance, and resilience capabilities to clients and external stakeholders.
• Compile reports, executive summaries, and evidence packages for customer and regulatory evaluations.
• Promote continuous improvement through automation, AI-driven processes, and operational efficiency initiatives.
• Aid in the development of new compliance and security initiatives stemming from regulatory or business shifts.
• Contribute to security awareness and compliance maturity initiatives.
• Mentor junior GRC professionals and participate in organizational knowledge sharing.
• 5 years of relevant experience with a Bachelor's degree, or 2 years of relevant experience with an Advanced degree (e.g., Masters, MBA, JD, MD), or no relevant experience with a PhD; OR 8 years of relevant experience.
• Preferred Bachelor's degree in Information Security, Cybersecurity, Risk Management, Information Technology, Law, Business Administration, or a related discipline.
• At least 5 years of experience in Governance, Risk & Compliance, Information Security, Risk Management, Internal Audit, or similar consulting roles.
• Experience in supporting audits, regulatory reviews, or certification programs.
• Strong grasp of risk management methodologies and principles of information security governance.
• Experience engaging with senior stakeholders and executive leadership.
• Excellent analytical, communication, presentation, and report-writing skills.
• Professional certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor or Lead Implementer, or CGRC.
• Experience in banking, payments, fintech, or other highly regulated sectors.
• Familiarity with cloud-native environments and contemporary software development practices.
• Understanding of privacy and data protection regulations.
• Fully remote work arrangement.
• Opportunity to make a significant impact at scale.
• Opportunities for skills growth and professional development through engaging challenges.
• Scheduled-notice Visa office attendance may be required for remote positions.
Consertus
Cartpanda
Syneos Health
Ardent
Get handpicked remote jobs straight to your inbox weekly.