Information Security Manager - GRC in Brazil at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Information Security Manager - GRC based in Brazil.
This leadership role is focused on shaping and advancing the Information Security Governance, Risk, and Compliance function within a fast-paced technology environment.
You will define the GRC vision, build scalable security practices, and transform governance into a strategic business enabler.
The role combines cybersecurity expertise, risk management, leadership, and operational execution to strengthen organizational resilience.
Working closely with senior security and business stakeholders, you will drive initiatives across governance, compliance, AI security, IAM, and third-party risk.
You will help translate complex cyber risks into actionable business decisions while improving security maturity and efficiency.
This is an opportunity for an experienced security leader to create meaningful impact in a cloud-native, innovation-driven environment.
The Information Security Manager - GRC will lead the development and execution of a comprehensive security governance strategy, ensuring alignment between cybersecurity objectives, business priorities, and risk appetite. This role requires a strategic mindset combined with strong execution capabilities to build scalable processes, reduce operational complexity, and enable secure business growth.
- Define and execute the GRC strategy, roadmap, priorities, and investment plans in alignment with organizational objectives.
- Own the security service intake channel and portfolio management process, ensuring visibility, prioritization, and effective coordination of security initiatives.
- Lead information security governance, including the development of AI governance models, policies, controls, and responsible technology adoption practices.
- Drive cyber risk management activities, including risk identification, treatment plans, monitoring, remediation, and financial risk quantification using methodologies such as FAIR.
- Manage IAM governance initiatives, ensuring identity and access management processes support security, compliance, and business requirements.
- Build and maintain third-party risk management and cyber resilience programs to strengthen supply chain security.
- Ensure continuous compliance with regulations and frameworks, including LGPD, SOX, GDPR, NIST, ISO standards, and other relevant requirements.
- Develop security metrics, KPIs, KRIs, and maturity models to support executive reporting and decision-making.
- Lead security awareness initiatives that improve security culture and reduce human-related risks.
- Structure and maintain information security policies, standards, procedures, and governance documentation.
- Manage, mentor, and develop a high-performing GRC team while coordinating third-party partners and external resources.
- Act as a strategic partner for Technology, Engineering, Product, Legal, Privacy, Finance, Compliance, Internal Audit, and business leadership on security risk topics.
The ideal candidate is an experienced cybersecurity leader with a strong background in governance, risk, and compliance, capable of operating strategically while delivering practical security solutions in complex technology environments.
- 10+ years of experience in Information Security GRC, including at least 5 years in leadership and team management roles.
- Experience working in complex, dynamic environments such as technology companies, scale-ups, financial organizations, or multinational companies.
- Strong expertise in security frameworks and standards, including NIST CSF 2.0, ISO 27001/27002, CIS Controls, SOX, and ISO 31000.
- Proven ability to translate cybersecurity risks into financial and operational business impacts.
- Experience applying risk quantification methodologies such as FAIR.
- Experience designing security KPI/KRI frameworks, maturity assessments, and executive-level reporting.
- Experience building vendor risk assessment methodologies and third-party risk management programs.
- Experience leading IAM governance initiatives and supporting IT General Controls (ITGC) within SOX compliance programs.
- Experience designing security awareness and behavior change programs.
- Ability to apply automation and AI solutions to improve GRC processes, including evidence collection, continuous monitoring, and risk analysis.
- Strong communication, stakeholder management, strategic thinking, and leadership skills.
- Fluency in Portuguese and advanced English.
- Certifications such as CISSP, CISM, CRISC, or ISO 27001 Lead Auditor are considered a plus.
- Competitive salary package.
- Profit-sharing opportunities.
- Meal allowance.
- Health insurance.
- Dental plan.
- Life insurance.
- Childcare subsidy and atypical parenthood support.
- Wellhub membership.
- Home office allowance.
- Employee assistance program offering mental health, social, legal, and financial support.
- Extended parental leave.
- Additional days off for birthdays, Mother’s Day, and Father’s Day.
- Benefits club with discounts on everyday services.
- Discounts at educational institutions.
- Children’s reading kit program.