
Senior Information Security Governance Analyst
Posted 12 hours ago

Posted 12 hours ago
This is a fully remote position, open to applicants in Brazil.
• Assist in the improvement and support of Information Security Governance, Risk, and Compliance (GRC) processes.
• Ensure adherence to corporate policies, regulatory obligations, internal controls, and industry best practices.
• Lead initiatives related to risk management, audits, metrics, awareness, documentation, third-party management, and monitoring of Information Security action plans.
• Draft, review, and maintain Information Security policies, standards, procedures, and controls.
• Facilitate both internal and external audit processes.
• Monitor nonconformities and develop remediation plans.
• Provide documentation for audits and regulatory assessments.
• Assist with initiatives pertaining to ISO 27001, SOX, and other compliance mandates.
• Conduct activities for identifying, assessing, and monitoring cybersecurity risks.
• Aid in the upkeep of the risk register.
• Supervise risk treatment plans and risk acceptances.
• Prepare executive reports detailing the progression of Information Security risks.
• Conduct security evaluations of vendors and partners.
• Assist in the onboarding and approval processes for third parties.
• Review Information Security stipulations in contracts.
• Track remediation efforts for critical vendors.
• Plan and implement Information Security awareness campaigns.
• Coordinate simulated phishing exercises.
• Develop communication and training materials.
• Monitor the effectiveness of awareness program metrics.
• Keep departmental documentation current.
• Organize evidence for audits and certifications.
• Support the structuring of the repository for processes, controls, and standards.
• Ensure compliance with corporate documentation standards.
• Consolidate Information Security metrics.
• Prepare dashboards and executive presentations.
• Monitor risk, audit, third-party, and awareness metrics.
• Provide support for governance forums and internal committees.
• A Bachelor's degree in Information Technology, Information Security, Engineering, Information Systems, or a related discipline.
• Experience in Governance, Risk, and Compliance (GRC).
• Background in IT audits.
• Experience in risk management and internal controls.
• Proven experience in drafting policies, standards, and procedures.
• Experience in leading Information Security awareness initiatives.
• Required understanding of risk management principles.
• Required knowledge of Information Security governance frameworks.
• Required knowledge of IT auditing practices.
• Required familiarity with ISO 27001 standards.
• Required knowledge of internal controls.
• Required understanding of third-party management processes.
• Required knowledge of metrics and key performance indicators.
• Required experience in developing documentation and audit evidence.
• Flexible working hours.
• Support for children with disabilities.
• Variable compensation program.
• Private pension plan.
• Additional pay based on tenure.
• Online therapy and nutritional guidance.
• Newborn care package.
• Access to a corporate university.
• Gympass membership.
• Meal and food vouchers.
• Transportation vouchers.
• Health and dental insurance.
• Life insurance.
InPost Group
Grupo Boticário
Dental Speed Graph
ClassLink
Get handpicked remote jobs straight to your inbox weekly.