Information Security Governance Analyst (Mid-Level)

Posted 9 hours ago

This is a fully remote position, open to applicants in Brazil.

📋 Description

• Create and implement awareness campaigns and training, tailoring content and methodologies to cater to the various audiences within the company.

• Oversee responses to customer security questionnaires, audits, and assessments by analyzing requirements, collecting information, and verifying responses with the relevant teams.

• Organize and maintain control evidence, ensuring its alignment with requirements and encouraging its reuse in assessments, audits, and certification processes.

• Monitor action plans, deadlines, and pending items related to risks, controls, and audits, coordinating with owners and relevant teams, and highlighting any deviations.

• Develop and evaluate Information Security policies, regulations, and procedures, considering business needs and applicable controls.

• Conduct control assessments based on frameworks like CIS Controls and ISO/IEC 27001, identifying gaps and suggesting enhancements.

• Contribute to efforts aimed at establishing and enhancing the Information Security Management System (ISMS).

• Compile metrics, reports, and presentations, effectively communicating results, risks, and priorities to various audiences, including managers and senior leadership.

• Spot opportunities to enhance governance processes, streamlining request tracking and evidence management.


⛳️ Requirements

• A completed bachelor’s degree or further education in Information Security, Technology, Governance, Risk, Audit, or a related discipline.

• Hands-on experience in GRC, Information Security, IT audit, or security-related internal controls.

• Certifications related to Information Security, GRC, or auditing, particularly with respect to ISO/IEC 27001.

• Experience in developing or reviewing policies and other normative documents, along with organizing and analyzing control evidence.

• Proven experience in responding to security questionnaires, audits, or assessments.

• Capability to interpret requirements, evaluate controls, pinpoint gaps, and monitor action plans.

• Strong, assertive verbal and written communication skills, with the ability to modify language for technical, business, and executive audiences.

• Competence in engaging with various departments and organizational levels, aligning expectations, and managing requests with courtesy, active listening, and objectivity.

• Analytical mindset to connect information, spot inconsistencies, and propose solutions suitable for the organization's context.

• Organizational skills and independence to handle multiple requests, negotiate deadlines and priorities, and signal when guidance or decisions are necessary.

• Proficiency in Excel, Word, and PowerPoint, or equivalent software.

• Involvement in projects relating to the implementation, maintenance, or certification of an ISMS based on ISO/IEC 27001.

• Experience in assessing control maturity and monitoring improvement initiatives.

• Familiarity with awareness campaigns, training, and measuring their effectiveness.

• Understanding of privacy, personal data protection, and Brazil’s General Data Protection Law (LGPD).

• Knowledge of vulnerability management, business continuity, and identity and access management.

• Proficient in English for reading requirements and preparing responses to security questionnaires and assessments.

• Familiarity with tools for managing requests, action plans, and documentation.


🏝️ Benefits

• Health and dental insurance.

• Pharmacy benefit: Funcional subsidizes part of the cost of your medications.

• Life insurance.

• Flu vaccination.

• Integrated health management program for employees and their dependents.

• TotalPass: access to gyms and wellness services.

• Childcare assistance.

• Extended maternity and paternity leave.

• Home office allowance (for remote positions).

• Transportation allowance (for on-site positions).

• Meal and food allowance.

• Annual profit-sharing program (for eligible positions).

• Birthday day off.

• Ongoing professional development initiatives.

• Partnerships with educational institutions.

• Collaborative environment.

• Agile culture focused on continuous evolution.

People also viewed

OpenLoop9 hours ago

Staff Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Salesforce9 hours ago

Security Architect Lead

US flagArizona, +13 more statesFull-timeCybersecurity / Security Engineer$150.1k – $227k/year
ApplyView job
CNO Financial Group9 hours ago

Lead IT Security Architect – SailPoint

US flagIllinois, +6 more statesFull-timeCybersecurity / Security Engineer$130.5k – $195.7k/year
ApplyView job
GuidePoint Security11 hours ago

Security Architect – AD/Entra ID

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Applied Research Solutions14 hours ago

Information System Security Engineer – ISSE

US flagOhio OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
RTX14 hours ago

Associate Director, HCM Core – Workday Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$157.2k – $298.8k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers