
Senior Information Security Risk and Controls Analyst
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Brazil.
• Oversee the comprehensive process of identifying, analyzing, assessing, and addressing information security risks in accordance with ISO/IEC 27005.
• Implement and enhance the organization’s risk methodology, incorporating qualitative matrices and quantitative models as needed.
• Establish and monitor risk treatment plans until completion or formal acceptance.
• Maintain and evaluate the information security controls framework, assessing its effectiveness, identifying exceptions, and developing corrective action plans.
• Perform maturity assessments and gap analyses aligned with ISO/IEC 27001/27002, NIST CSF, and CIS Controls.
• Execute vendor and third-party risk assessments (TPRM).
• Organize and maintain KRIs/KPIs, and generate both technical and executive reports.
• Act as a technical consultant to Product, Engineering, Cloud, Compliance, and Legal teams.
• Facilitate formal risk acceptance and exception management processes through thorough documentation, governance, and regular reviews.
• Proven experience in managing information security risk.
• Extensive practical knowledge of ISO/IEC 27005.
• Strong understanding of ISO/IEC 27001/27002, NIST CSF, and CIS Controls.
• Experience in managing vendor and third-party risk (TPRM), which includes conducting due diligence, criticality assessments, and monitoring contractual obligations.
• Capability to design control effectiveness testing, manage evidence, and oversee action plans until closure.
• Exceptional technical writing and communication skills, with the ability to convey complex risks in a clear manner for executive audiences.
• Highly organized, self-motivated, and sufficiently experienced to lead intricate analyses with minimal oversight.
• Preferred: certifications such as ISO 27005 Risk Manager, CRISC, or ISO 27001 Lead Implementer/Auditor.
• Preferred: experience with quantitative risk modeling (FAIR or similar).
• Preferred: background in regulated environments, specifically payment institutions or financial institutions governed by regulations from the Central Bank of Brazil.
• Medical and dental insurance with no copayment.
• Life insurance.
• Medication assistance.
• Fitness allowance.
• Four complimentary monthly therapy or nutritionist sessions via Zenklub.
• Quick massage services available at the headquarters.
• Flexible meal benefits provided on a Visa card.
• Free meals at the headquarters.
• Childcare assistance.
• Parental support program.
• Extended maternity and paternity leave.
• In-house training platform.
• Education assistance covering 70% of tuition for undergraduate programs, language courses, and other educational materials.
• Home office allowance.
• Provision of work equipment.
• Furniture allowance.
• Partnership with WOBA for coworking space access across Brazil.
• Day off during the birthday month.
• Happy hour allowance.
• Referral bonus for new hires.
• Annual performance-based bonus.
• Stock options plan.
• No dress code policy.
Cloudiax
Cisco
Cisco
Skylight
Get handpicked remote jobs straight to your inbox weekly.