Analista de Segurança da Informação focusing on IAM at Cruzeiro do Sul Educacional. Responsible for strengthening IAM processes and compliance.
Responsibilities
Act as a leading figure in the design and evolution of IAM processes, proposing improvements that increase operational efficiency and robustness.
Ensure evidence, controls, and responses for audits and regulatory bodies, meeting deadlines and delivering high-quality results.
Create and standardize documentation, internal procedures, templates, and workflows, bringing organization and governance to the team.
Develop and maintain effective internal controls capable of anticipating risks and ensuring compliance.
Collaborate with internal teams and external partners to improve processes, integrations, and automations.
Prepare and maintain operational procedures, standards, and IAM documentation (runbooks, playbooks, manuals, process diagrams, etc.).
Execute and enhance internal controls, ensuring traceability, evidence, and compliance with policies and regulations.
Support internal/external audit responses and communications with regulatory bodies, including preparing replies, submitting evidence, and tracking action plans.
Support the identity lifecycle (Joiners, Movers, Leavers), ensuring adherence to access policies.
Advise internal teams on implementing security best practices related to identities and access.
Monitor metrics, access reports, exceptions, and team indicators, suggesting continuous improvements.
Collaborate on automation initiatives, process reviews, and implementation of new controls.
Identify access-related security gaps and propose mitigations and structural improvements.
Participate in the development and evolution of access models and standards (RBAC, SoD, periodic reviews, etc.).
Requirements
Solid knowledge of IAM controls and governance
Access policies and standards
Audit and compliance practices
Preparation of technical and procedural documentation
Experience responding to audits, regulatory requests, or certifications (e.g., ISO 27001, NIST, LGPD)
Knowledge of IAM tools (e.g., SailPoint, Azure AD, CyberArk, or similar)
Strong written and verbal communication skills, with the ability to produce clear and robust documentation
Security certifications (e.g., ISO 27001 Lead Implementer/Lead Auditor, CompTIA Security+, CSF, ITIL, IDPro)
Experience with SailPoint IdentityNow or other SaaS IAM platforms
Experience with automations using scripting (Python, PowerShell, or GAS)
Knowledge of RBAC, ABAC, SoD, and segregation of duties in corporate environments
Experience implementing or reviewing periodic access review processes (Access Review)
Familiarity with audit requirements in regulated industries (education, financial, telecom, healthcare, etc.)
Benefits
Health insurance
Dental insurance
Meal allowance
Transportation allowance
Pharmacy benefit
Total Pass
Full tuition scholarship (Undergraduate or Graduate — after 3 months of employment)
Life insurance
Birthday day off
Job title
Mid-level Information Security Analyst, Focus on IAM
Cyber Security Analyst at Ideagen monitoring threats and investigating security events. Supporting incident response and helping operate key security tools in a hybrid role.
Information Security Analyst responsible for ISMS structures and cybersecurity compliance at IT Sonix. Collaborating with departments and authorities in a professional environment
Analista de Segurança da Informação para monitorar e responder a incidentes de segurança cibernética usando SIEM. Interação com equipes internas e elaboração de relatórios para clientes.
Tier 3 Cyber Threat Intelligence Analyst providing security analysis as part of a DHS program. Analyzing cyber threats and supporting incident response and threat hunting activities.
Security Analyst responsible for data systems security at ITA Group. Ensure integrity and confidentiality of sensitive data while providing technical leadership and responding to security incidents.
Cybersecurity Monitoring Analyst protecting Thales' information systems by detecting and responding to cyber threats. Responsibilities include monitoring, investigation, incident response, and threat communication.
Information Security Analyst supporting Navy Qualified Validator activities for Norfolk Naval Shipyard. Engaging in cybersecurity compliance, security assessments, and risk management tasks.
Senior Information Security Analyst provides security solutions and policy guidance while managing technology controls on moderate to high complexity projects at TD.
Information Security Risk Advisory professional assessing and managing technology risks at Grainger. Collaborating with teams on risk assessments and technology initiatives in a hybrid work environment.
Security Analyst at NovaSource safeguarding digital assets and responding to cyber threats. Collaborating across IT and operational technology to monitor and mitigate risks.