Consultor GRC responsável pela implementação de projetos de Governança, Riscos e Compliance na Redbelt Security. Avaliação de processos e controles para segurança cibernética e melhoria contínua.
Responsibilities
Support the team in leading projects, processes, and monitoring the GRC area's KPIs and KRIs to improve perceived value for Redbelt Security's investors, clients, and commercial partners.
Implement GRC projects for Redbelt Security clients by conducting comprehensive assessments of existing governance, risk, and compliance processes, policies, and controls related to cybersecurity; provide strategic improvement recommendations addressing technology and process controls, as well as training and capacity-building programs for personnel to maximize the effectiveness of controls within the client's corporate cybersecurity framework.
Work on Redbelt Security's internal projects by performing comprehensive assessments of existing governance, risk, and compliance processes, policies, and controls related to cybersecurity; propose strategic improvement recommendations covering technology and process controls, and develop training programs for staff to maximize the effectiveness of controls within Redbelt Security's corporate cybersecurity framework.
Support Redbelt Security internal areas with GRC-related requests by participating in meetings, reviewing documentation, and providing technical GRC opinions aimed at aligning with market best practices, legal/regulatory requirements, and internationally recognized frameworks.
Continuously monitor publications of new regulations, frameworks, laws, and industry best practices related to GRC services to recommend updates to the product portfolio and keep it up to date.
Draft Redbelt Security policies and standards focused on Information Security to standardize processes and mitigate risks that those processes expose the company to.
Requirements
Bachelor's degree in Business Administration, Engineering, Technology, or Information Security.
Knowledge of industry frameworks such as, but not limited to, ITIL, COBIT, NIST, ISO 27000 series, ISO 22301, ISA/IEC 62443.
Familiarity with Cyber Risk Assessment, Business Continuity Plan (BCP), Incident Response Plan, Tabletop Exercises, Privacy and Data Protection, and Cybersecurity.
Knowledge of Information Technology (IT) and Operational Technology (OT) environments.
Preferred certifications in IT Governance (ISO 38500), Risk Management (ISO 31000), or Compliance (ISO 37301).
Benefits
Meal allowance (iFood Benefícios card) — no employee contribution;
Food allowance (iFood Benefícios card) — no employee contribution;
Transportation voucher — as required by law;
Medical assistance/health insurance — no copayment and no employee contribution;
Dental assistance/dental insurance — no copayment and no employee contribution;
Well-being: Wellhub and Totalpass;
Group life insurance;
Piwi support;
Starbem: healthtech platform for care;
Avus: health benefits platform;
Childcare assistance;
Assistance for dependents with special needs;
Company Citizen program: extended maternity and paternity leave;
Day off on your birthday;
Redbelt Referral Program: your referral matters;
Redbelt School: educational sponsorship for courses and certifications;
Redbelt Celebra: tenure awards;
Agreement with SESC;
Partnerships with educational and language institutions for discounts;
PLR (profit-sharing): subject to achievement of company targets.
Compliance Analyst role at Leve Saúde ensuring adherence to regulations in the health sector. Responsibilities include audits, policy management, and due diligence processes.
Governance, Risk & Compliance Specialist at Quilter providing oversight on governance, risk, and compliance activities, strengthening Quilter Invest’s risk management culture across the organization.
Regulatory Specialist responsible for contributions in public consultations and regulatory studies. Engaging with institutional relations and ensuring adherence to energy regulations in Brazil.
Working Student supporting regulatory and compliance efforts at Paymenttools' e - money institution. Collaborating on risk management and compliance projects in a hybrid role based in Cologne.
Senior Consultant Regulatory Affairs participating in pharmaceutical projects focused on market access and regulatory compliance. Joining Deloitte's sector regulation team based in Madrid.
Trade Compliance Officer managing stakeholder compliance with UK and US export laws. Contributing to trade policies and documentation for international imports and exports in a hybrid role.
Expert HSE Compliance role focused on environmental regulations and safety in energy production at EniBioch4in. Overseeing compliance, audits, and promoting HSE culture across facilities.
Junior Regulatory Reporting Operations Specialist analyzing vast trade reporting data and ensuring regulatory reporting quality at SEB. Collaborating with teams to resolve reporting issues for regulatory compliance.
Risk & Compliance Advisory Practice Lead at Netwealth providing risk and compliance advice across investment and product governance. Leading advisory teams while ensuring regulatory compliance and risk management standards.
Director Compliance role at Manulife managing the Complaints & Regulatory Investigations team. Overseeing investigations and ensuring compliance with regulatory standards.