Governance Specialist handling information security and access management strategies. Ensuring compliance and risk management within the organization located in São Paulo.
Responsibilities
Work on Information Security governance with a strategic focus on documentation and identity and access management
Ensure access controls are aligned with regulatory requirements, the company’s risk appetite, and business needs
Define and maintain the organization’s access governance strategy
Create, review and maintain Information Security, Identity and Access Management, and Privileged Access (PAM) policies and standards
Govern the onboarding, role changes/movements and offboarding processes for employees and third parties
Requirements
Experience in Information Security Governance, GRC or IAM
Experience in regulated environments (fintech, banking, payments, insurance)
Knowledge of frameworks, documentation and standards (ISO 27001/27002, CIS, LGPD)
Strong risk awareness and decision-making skills
Ability to communicate with technical teams, business stakeholders and executives
Organized, with a strong sense of priorities and focus on predictability
Benefits
N/A
Job title
Mid-level Information Security and Access Governance Specialist (IAM)
Technical Lead in Cybersecurity focusing on threat monitoring and vulnerability assessments for the company. Collaborate with analysts and stakeholders to enhance cybersecurity measures.
Technical Specialist in Cybersecurity managing endpoint protection, email filtering, and workload security. Collaborating with SOC teams and presenting findings effectively.
Facility Security Officer managing Industrial Security at Curtiss - Wright. Overseeing physical, personnel, and information security while ensuring compliance with government regulations.
Cybersecurity Engineer protecting organizational systems and data at Legends Global. Designing secure infrastructures and automating security tooling in a dynamic tech environment.
Security Architect providing expertise to secure software development ecosystems including CI/CD pipelines and code repositories. Ensuring security principles are integrated throughout the Software Development Lifecycle (SSDL).
Security Architect designing security frameworks to protect industrial control and IoT systems. Collaborating with teams to ensure compliance and mitigate cyber threats in OT environments.
Security Engineer at G+D Group ensuring secure service delivery across IT environments. Collaborating with teams to translate security policies into operational solutions while monitoring threats.
ICT & Security Risk Manager managing ICT risk framework and assessments in BCR, a leading banking organization. Ensuring effective risk monitoring and reporting for secure operations.