Gerente de Governança de Segurança da Informação na C&A. Envolvendo políticas de segurança e gestão de riscos para fortalecer governança de informações.
Responsibilities
Define and maintain corporate Information Security policies aligned with best practices such as ISO 27001/2, NIST, PCI, and BACEN regulations
Lead information communication and promote a security culture across the organization
Manage the governance lifecycle: planning, execution, monitoring, and continuous improvement
Ensure compliance with LGPD, BACEN Resolution 4,893/2021, and other applicable regulations
Coordinate internal and external audits, responding to regulatory bodies and clients
Define metrics and indicators (KPIs/KRIs) to monitor security posture
Oversee risk management processes, including analysis, mitigation, and reporting to senior management
Design, implement, and monitor IT General Controls (ITGC) to ensure integrity, availability, and reliability of corporate systems
Manage third-party risk (Third-Party Risk Management), including supplier assessments, due diligence, continuous monitoring, and regulatory compliance
Establish guidelines for AI governance, including ethical principles, security, privacy, and regulatory compliance
Plan and conduct Information Security and Privacy training and awareness programs for employees, suppliers, and partners.
Requirements
Strong experience in Information Security governance and risk management
Experience managing an Information Security and/or GRC team
Advanced knowledge of NIST CSF, ISO 27001, COBIT frameworks and BACEN regulations
Familiarity with LGPD, SOX, and compliance best practices
Experience in designing and monitoring ITGC
Knowledge of AI governance and related frameworks (e.g., FATE)
Preferred certifications: ISO 27001 Lead Implementer/Auditor, CISM or CISA
** Differentials:**
Experience with cyber resilience frameworks and continuity management
Participation in regulatory audits and executive committees
Knowledge of governance for hybrid and cloud environments
DPO (Data Protection Officer) certification or equivalent.
Benefits
Healthcare and Dental insurance (employee and dependents)
Dr. C&A - Telemedicine and teletherapy
Annual bonus
Parking or commuter allowance (Work location: Alphaville – Barueri/SP)
Birthday Off — one day off during your birthday month
Network Security Engineer at Eurobank leading the design of network security architectures. Collaborating with teams to ensure compliance and effective network security implementations in a banking environment.
Patrol Officer creating a secure environment for patients at Health Sciences Centre. Enforcing laws and assisting in medical and nursing staff in Winnipeg, Canada.
OT (Cyber) Security Officer responsible for securing IT and OT systems in large infrastructure projects. Collaborating with a security team to develop cybersecurity strategies and incident responses.
Cyber Security Consultant at NewTec aiding clients in implementing security measures and management plans. Engaging in project diversity with experienced specialists in a supportive environment.
Technical Security Engineer supporting national security by implementing security solutions for government clients. Collaborating with teams to assess vulnerabilities and protect mission data.
Lead Information Systems Security Manager at Booz Allen managing Risk Management Framework authorization and continuous monitoring of IT systems in compliance with security policies.
ISSO providing advanced cyber solutions for government clients. Leading security assessments and mitigation planning to secure mission - critical systems.
Cybersecurity Senior Associate analyzing complex cybersecurity issues and mentoring junior team members. Building client relationships while contributing to threat intelligence and vulnerability management initiatives.
Cybersecurity Manager leading threat intelligence and SIEM solutions initiatives for a global accounting firm based in Taguig. Plan and direct resources for successful project outcomes while mentoring junior staff.
Senior IT - Security Engineer responsible for implementing cyber security solutions in complex IT infrastructures for clients. Leading technical security projects with focus on customer support and security strategy development.