7 часов назад
Information Security Manager (GRC)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Information Security Manager (GRC) (Cybersecurity/GRC): Building and leading a strategic GRC program for a cloud-native technology organization with an accent on cyber risk accountability, AI governance, IAM governance, and third-party resilience. Focus on quantifying cyber risk with FAIR, operationalizing continuous compliance, automating controls and evidence collection, and communicating security metrics to executive leadership.
Location: Remote-first within Brazil, with the option to work from São Paulo offices or partner coworking spaces up to twice a week.
Company
Grupo is a Latin American real estate technology ecosystem developing products and solutions across the housing journey.
What you will do
- Define and execute the GRC strategy, roadmap, budget, risk appetite, security service channel, and security portfolio.
- Lead information security governance, AI governance, IAM governance, policy management, and continuous compliance programs.
- Manage end-to-end cyber risk, including identification, treatment, monitoring, remediation, and financial quantification using FAIR.
- Lead third-party risk management, cyber resilience, vendor assessments, and supply-chain security initiatives.
- Manage and develop a high-performance GRC team and coordinate third-party partners.
- Report KPIs, KRIs, maturity metrics, and risk evolution to executive leadership and security committees while partnering with Technology, Engineering, Product, Legal, Privacy, Finance, Compliance, and Audit.
Requirements
- 10+ years of experience in Information Security GRC, including at least 5 years in leadership and team management roles.
- Experience in complex, dynamic, and multinational corporate environments, preferably technology companies, scale-ups, or financial organizations.
- Strong knowledge of NIST CSF 2.0, ISO 27001/27002, CIS Controls, SOX, ISO 31000, ITGC, IAM governance, TPRM, and security metrics.
- Ability to translate technical cyber risks into financial and operational impacts using FAIR.
- Experience designing security awareness programs, maturity models, vendor risk methodologies, and executive reporting frameworks.
- Fluency in Portuguese and advanced English required. Ability to use automation and AI to operationalize GRC at scale.
Nice to have
- CISSP, CISM, CRISC, or ISO 27001 Lead Auditor certification.
Culture & Benefits
- Remote-first work model within Brazil with home office allowance.
- Competitive salary and profit sharing.
- Meal, health, dental, and life insurance benefits.
- Childcare and atypical parenthood subsidies, Wellhub, and employee assistance support.
- Extended parental leave, birthday and family-related days off, benefits discounts, and educational institution discounts.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →