Analista de Riscos e Controles de Segurança da Informação Sênior

Added
2 hours ago
Type
Full time
Salary
Salary not provided

Related skills

security nist csf fair third-party risk management kris

📋 Description

  • Lead the end-to-end information security risk management lifecycle, including risk identification
  • Apply and continuously improve risk management methodologies, including qualitative
  • Define and monitor risk treatment plans covering mitigation, transfer, acceptance, or avoidance
  • Maintain and test the information security controls framework, assessing control effectiveness
  • Conduct security control maturity assessments and gap analyses based on frameworks such as ISO/IEC
  • Lead third-party and supplier risk assessments, including due diligence, criticality

🎯 Requirements

  • Proven professional experience in information security risk management.
  • Strong practical and in-depth knowledge of ISO/IEC 27005, including risk identification, analysis
  • Solid understanding of ISO/IEC 27001/27002, NIST CSF, and CIS Controls and their relationship to
  • Experience with third-party risk management (TPRM), including supplier due diligence, criticality
  • Demonstrated ability to design and perform control effectiveness testing, manage supporting
  • Strong technical writing and communication skills, with the ability to translate complex security

🎁 Benefits

  • Full-time CLT employment.
  • Monday to Friday schedule, 8 hours per day.
  • Fully remote/home-office work within Brazil.
  • Medical and dental insurance with no copay.
  • Life insurance.
  • Medication assistance.
Share job

Meet JobCopilot: Your Personal AI Job Hunter

Automatically Apply to Engineering Jobs. Just set your preferences and Job Copilot will do the rest — finding, filtering, and applying while you focus on what matters.

Related Engineering Jobs

See more Engineering jobs →