4 дня назад
GRC Consultant
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
GRC Consultant (Security Governance and Compliance): Leading governance, risk, compliance, audit, and operational resilience initiatives across global payments operations with an accent on information security frameworks, regulatory assurance, and stakeholder management. Focus on conducting risk assessments, coordinating audits, preparing executive reporting, and driving automation and AI-enabled compliance improvements.
Location: Remote in Brazil; occasional presence at a office may be required with scheduled notice.
Company
is a global payments technology company facilitating transactions among consumers, merchants, financial institutions, and government entities.
What you will do
- Lead the development and continuous improvement of governance frameworks, policies, standards, and procedures.
- Support compliance with ISO 27001, SOC 1, SOC 2, PCI DSS, PCI PIN Security, data localisation requirements, and other applicable regulations.
- Conduct enterprise, operational, technology, and cybersecurity risk assessments; maintain risk registers and monitor remediation.
- Coordinate internal and external audits, regulatory reviews, client assessments, and security due diligence requests.
- Prepare executive-level risk reports, dashboards, evidence packages, and responses for customers, regulators, and payment networks.
- Drive automation, AI-enabled compliance processes, security awareness initiatives, and operational resilience improvements while mentoring junior GRC professionals.
Requirements
- At least 5 years of relevant experience with a bachelor's degree, 2 years with an advanced degree, 0 years with a PhD, or 8 years of relevant experience without a stated degree requirement.
- Experience in governance, risk and compliance, information security, risk management, internal audit, or related consulting.
- Experience supporting audits, regulatory reviews, or certification programmes.
- Strong understanding of risk management methodologies and information security governance principles.
- Experience presenting complex risk and compliance matters to senior stakeholders and executive leadership.
- Strong analytical, communication, presentation, and report-writing skills.
Nice to have
- Certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor or Lead Implementer, or CGRC.
- Experience in banking, payments, fintech, or other highly regulated industries.
- Familiarity with cloud-native environments, modern software development practices, privacy regulations, and data protection requirements.
Culture & Benefits
- Remote work arrangement that does not require duties to be performed near a office.
- Work with security, engineering, legal, privacy, product, infrastructure, and business stakeholders.
- Opportunity to contribute to security and compliance maturity across global operations.
- Work on initiatives supporting client, regulatory, and requirements.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
35 минут назад
GRC Subject Matter Expert
171 000 - 201 000$
4 дня назад
Internal Control Consultant (Information Security)
34 минуты назад
Subject Matter Expert, GTM (GRC)
171 000 - 201 000$
1 день назад
GRC Engineer (Cybersecurity)
DeepL
1 день назад
Senior Information Security Manager (Cybersecurity)
6 дней назад