9 часов назад
Information Security Governance Manager (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Information Security Governance Manager (Fintech): Leading information security risk management, governance, compliance, and awareness programs with an accent on ISO standards, PCI DSS, audits, and executive-level risk reporting. Focus on designing security controls, coordinating remediation, embedding security requirements into products and third-party relationships, and using AI and automation to improve governance effectiveness.
Location: Curitiba, Brazil — onsite
Company
is an AI-powered fintech company providing cross-border payment infrastructure across 29 countries and connecting global businesses with more than 1 billion consumers.
What you will do
- Lead and develop the Information Security team focused on risk management and security governance.
- Identify, assess, prioritize, and treat information security risks, communicating risk exposure to senior leadership.
- Maintain and continuously improve compliance programs and certifications, including ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27018, and PCI DSS.
- Define governance policies, standards, procedures, controls, KPIs, KRIs, and program effectiveness metrics.
- Coordinate internal and external audits, security assessments, remediation plans, and responses to regulatory demands.
- Build security awareness through training, phishing simulations, targeted campaigns, and cross-functional initiatives.
Requirements
- Experience leading, motivating, coaching, and developing teams.
- Strong expertise in information security risk management, governance, internal controls, and security frameworks.
- Hands-on experience with ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27018, and PCI DSS.
- Experience managing audits, assessments, remediation, and external regulatory requirements.
- Strong communication and analytical skills, including translating technical risks into business impact for executive audiences.
- Advanced English required for regular interaction with international stakeholders.
Nice to have
- ISO/IEC 27001 Lead Auditor or Lead Implementer, CRISC, CISM, CISSP, or similar certification.
- Experience in global or multicultural environments and with international operations.
- Knowledge of NIST CSF, COBIT, SOX, third-party risk management, cloud security standards, or secure development practices.
- Experience with awareness platforms, phishing simulation tools, incident response, and executive security presentations.
- Experience using AI or machine learning to automate governance, risk analysis, controls management, or compliance monitoring.
Culture & Benefits
- Annual performance-based bonuses through the WAVES Program.
- Medical, dental, life insurance, childcare assistance, extended parental leave, and family support programs.
- Education, professional development, workshops, courses, certifications, and language classes.
- Meal or food allowance, transportation assistance, and parking support.
- Semi-flexible working hours, birthday day off, and year-end recess without using vacation days.
- Well-being programs and discounts through Play and Blue Club.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →