Назад
Company hidden
7 часов назад

Information Security Manager (GRC)

Формат работы
remote (только Brazil)
Тип работы
fulltime
Грейд
lead
Английский
c1
Страна
Brazil
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Security Manager (GRC) (Cybersecurity/GRC): Building and leading a strategic GRC program for a cloud-native technology organization with an accent on cyber risk accountability, AI governance, IAM governance, and third-party resilience. Focus on quantifying cyber risk with FAIR, operationalizing continuous compliance, automating controls and evidence collection, and communicating security metrics to executive leadership.

Location: Remote-first within Brazil, with the option to work from São Paulo offices or partner coworking spaces up to twice a week.

Company

Grupo hirify.global is a Latin American real estate technology ecosystem developing products and solutions across the housing journey.

What you will do

  • Define and execute the GRC strategy, roadmap, budget, risk appetite, security service channel, and security portfolio.
  • Lead information security governance, AI governance, IAM governance, policy management, and continuous compliance programs.
  • Manage end-to-end cyber risk, including identification, treatment, monitoring, remediation, and financial quantification using FAIR.
  • Lead third-party risk management, cyber resilience, vendor assessments, and supply-chain security initiatives.
  • Manage and develop a high-performance GRC team and coordinate third-party partners.
  • Report KPIs, KRIs, maturity metrics, and risk evolution to executive leadership and security committees while partnering with Technology, Engineering, Product, Legal, Privacy, Finance, Compliance, and Audit.

Requirements

  • 10+ years of experience in Information Security GRC, including at least 5 years in leadership and team management roles.
  • Experience in complex, dynamic, and multinational corporate environments, preferably technology companies, scale-ups, or financial organizations.
  • Strong knowledge of NIST CSF 2.0, ISO 27001/27002, CIS Controls, SOX, ISO 31000, ITGC, IAM governance, TPRM, and security metrics.
  • Ability to translate technical cyber risks into financial and operational impacts using FAIR.
  • Experience designing security awareness programs, maturity models, vendor risk methodologies, and executive reporting frameworks.
  • Fluency in Portuguese and advanced English required. Ability to use automation and AI to operationalize GRC at scale.

Nice to have

  • CISSP, CISM, CRISC, or ISO 27001 Lead Auditor certification.

Culture & Benefits

  • Remote-first work model within Brazil with home office allowance.
  • Competitive salary and profit sharing.
  • Meal, health, dental, and life insurance benefits.
  • Childcare and atypical parenthood subsidies, Wellhub, and employee assistance support.
  • Extended parental leave, birthday and family-related days off, benefits discounts, and educational institution discounts.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →