Hybrid Information Security Governance Manager

Posted 15 hours ago

Apply now

About the role

  • Gerente de Governança de Segurança da Informação na C&A. Envolvendo políticas de segurança e gestão de riscos para fortalecer governança de informações.

Responsibilities

  • Define and maintain corporate Information Security policies aligned with best practices such as ISO 27001/2, NIST, PCI, and BACEN regulations
  • Lead information communication and promote a security culture across the organization
  • Manage the governance lifecycle: planning, execution, monitoring, and continuous improvement
  • Ensure compliance with LGPD, BACEN Resolution 4,893/2021, and other applicable regulations
  • Coordinate internal and external audits, responding to regulatory bodies and clients
  • Define metrics and indicators (KPIs/KRIs) to monitor security posture
  • Oversee risk management processes, including analysis, mitigation, and reporting to senior management
  • Design, implement, and monitor IT General Controls (ITGC) to ensure integrity, availability, and reliability of corporate systems
  • Manage third-party risk (Third-Party Risk Management), including supplier assessments, due diligence, continuous monitoring, and regulatory compliance
  • Establish guidelines for AI governance, including ethical principles, security, privacy, and regulatory compliance
  • Plan and conduct Information Security and Privacy training and awareness programs for employees, suppliers, and partners.

Requirements

  • Strong experience in Information Security governance and risk management
  • Experience managing an Information Security and/or GRC team
  • Advanced knowledge of NIST CSF, ISO 27001, COBIT frameworks and BACEN regulations
  • Familiarity with LGPD, SOX, and compliance best practices
  • Experience in designing and monitoring ITGC
  • Knowledge of AI governance and related frameworks (e.g., FATE)
  • Preferred certifications: ISO 27001 Lead Implementer/Auditor, CISM or CISA
  • ** Differentials:**
  • Experience with cyber resilience frameworks and continuity management
  • Participation in regulatory audits and executive committees
  • Knowledge of governance for hybrid and cloud environments
  • DPO (Data Protection Officer) certification or equivalent.

Benefits

  • Healthcare and Dental insurance (employee and dependents)
  • Dr. C&A - Telemedicine and teletherapy
  • Annual bonus
  • Parking or commuter allowance (Work location: Alphaville – Barueri/SP)
  • Birthday Off — one day off during your birthday month
  • Flexible working hours
  • On-site cafeteria
  • Flexible Meal Benefit (meal allowance and/or meal voucher)
  • Gympass
  • Semi-annual vacation
  • Discounts on purchases at C&A stores and e-commerce.

Job title

Information Security Governance Manager

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

No Education Requirement

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job