JobTarget Logo

Analista de Riscos e Controles de Segurança da Informação Sênior in Brazil at Jobgether

New
Jobgether
Brazil, Brazil
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

Analista de Riscos e Controles de Segurana da Informao Snior

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Analista de Riscos e Controles de Segurança da Informação Sênior based in Brazil.

As a Senior Information Security Risk and Controls Analyst, you will play a key role in identifying, assessing, and treating information security risks across the organization. You will help strengthen security controls, evaluate their effectiveness, and drive remediation initiatives through to completion. The role also includes third-party risk management, security maturity assessments, and governance activities. You will work closely with Product, Engineering, Cloud, Compliance, and Legal teams to embed security and risk management into projects from the beginning. Your ability to investigate complex scenarios and translate technical risks into clear recommendations will support both operational and executive decision-making. This is a highly autonomous role in a collaborative, agile environment where technical expertise and attention to detail are valued.

Accountabilities:
  • Lead the end-to-end information security risk management lifecycle, including risk identification, analysis, evaluation, and treatment in accordance with ISO/IEC 27005.
  • Apply and continuously improve risk management methodologies, including qualitative probability-versus-impact matrices and, where appropriate, quantitative approaches such as FAIR.
  • Define and monitor risk treatment plans covering mitigation, transfer, acceptance, or avoidance, ensuring appropriate follow-up through formal closure or acceptance.
  • Maintain and test the information security controls framework, assessing control effectiveness, documenting exceptions, and monitoring corrective action plans.
  • Conduct security control maturity assessments and gap analyses based on frameworks such as ISO/IEC 27001/27002, NIST CSF, and CIS Controls.
  • Lead third-party and supplier risk assessments, including due diligence, criticality classification, and monitoring of contractual security requirements.
  • Develop and maintain risk and control indicators, including KRIs and KPIs, and prepare technical and executive-level reports to support decision-making.
  • Act as a technical advisor to Product, Engineering, Cloud, Compliance, and Legal teams, promoting security-by-design and risk mitigation throughout project development.
  • Support formal risk acceptance and exception management processes through appropriate documentation, governance, and periodic reviews.
Requirements:
  • Proven professional experience in information security risk management.
  • Strong practical and in-depth knowledge of ISO/IEC 27005, including risk identification, analysis, evaluation, probability and impact criteria, and treatment planning.
  • Solid understanding of ISO/IEC 27001/27002, NIST CSF, and CIS Controls and their relationship to information security risk management.
  • Experience with third-party risk management (TPRM), including supplier due diligence, criticality assessments, and contractual security requirements.
  • Demonstrated ability to design and perform control effectiveness testing, manage supporting evidence, and track remediation plans through completion.
  • Strong technical writing and communication skills, with the ability to translate complex security risks into clear language for executive and business audiences.
  • Strong organization, autonomy, analytical thinking, and senior-level judgment when handling complex assessments with limited supervision.
  • Bachelor's degree or equivalent professional background in information security, technology, risk management, or a related field is desirable.
  • Certifications such as ISO 27005 Risk Manager, CRISC, or ISO 27001 Lead Implementer/Auditor are desirable.
  • Experience with quantitative risk modeling, such as FAIR or equivalent methodologies, is a plus.
  • Experience in regulated environments, particularly financial or payment institutions subject to Central Bank of Brazil regulations, is a plus.
  • Ability to translate regulatory requirements into practical security and risk management processes is desirable.
Benefits:
  • Full-time CLT employment.
  • Monday to Friday schedule, 8 hours per day.
  • Fully remote/home-office work within Brazil.
  • Medical and dental insurance with no copay.
  • Life insurance.
  • Medication assistance.
  • Physical activity and wellness assistance.
  • Financial wellness support.
  • Four free monthly sessions with therapy or nutrition professionals.
  • Flexible food allowance through a Visa card.
  • Childcare assistance.
  • Parental support program.
  • Extended maternity and paternity leave.
  • Education assistance covering 70% of eligible undergraduate, language, course, and book expenses.
  • Access to professional training and development programs.
  • Home-office allowance and work equipment.
  • Furniture allowance for remote work.
  • Access to coworking spaces across Brazil.
  • Birthday Day Off.
  • Happy Hour allowance.
  • Employee referral bonuses.
  • Annual goal-based bonus opportunities.
  • Stock option plan.
  • Flexible, collaborative work environment with no formal dress code.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

Job Location

Brazil, Brazil

Frequently asked questions about this position

Similar Jobs In Brazil, Other

Information Security Analyst

K2 Integrity
London, Other

System Analyst

South China Morning Post
Other

Threat Response Coordinator (Makati Site)

Genfinity Philippines, Inc.
Makati City, Other
Continue to apply
Enter your email to continue. You’ll be redirected to the employer’s application.
By clicking Continue, you understand and agree to JobTarget's Terms of Use and Privacy Policy.