Senior GRC Analyst (Business Resilience) in São Paulo, São Paulo at Tractian
NewEmployment Type: Full-Time
Tractian
São Paulo, São Paulo, Brazil
Posted on
New job! Apply early to increase your chances of getting hired.
Explore Related Opportunities
Job Description
GRC at TRACTIAN
The Engineering team at Tractian is at the forefront of developing cutting-edge infrastructure, technologies, and products to harness the power of IoT data. Our team of talented Engineers collaborates to build robust systems, innovative solutions, and scalable platforms that drive Tractian's success. We are instrumental in shaping the company's decision-making process, optimizing operational efficiency, and delivering exceptional experiences to our consumers.
What you'll do
As a GRC Analyst, you will be responsible for developing and implementing robust governance, risk management, and compliance (GRC) practices within our technology-driven organization. You will play a key role in establishing frameworks and processes that ensure the security, integrity, and regulatory compliance of our technology systems. You will collaborate with cross-functional teams to assess risks, implement controls, and drive continuous improvement of our GRC program.
Key Responsibilities
- Lead and continuously improve the organization's operational resilience, business continuity, and risk management activities – including identifying, assessing, documenting, monitoring, and reviewing operational, technology, cybersecurity risks.
- Perform Business Impact Analysis (BIA), define recovery objectives (RTO/RPO), develop disruption scenarios, and establish contingency, recovery, and business continuity strategies for critical business services.
- Develop, implement, maintain, and continuously improve the organization's Business
- Continuity (BCM), Disaster Recovery (DR), and Incident Response (IR) activities, including policies, standards, procedures, recovery plans, and playbooks, aligned with corporate objectives, regulatory requirements, and industry best practices.
- Plan, facilitate, execute, and document tabletop exercises, recovery tests, backup and recovery validation, failover exercises, and other resilience testing activities, ensuring lessons learned and corrective actions are tracked.
- Maintain the enterprise risk register, controls, mitigation plans, and audit evidence within the organization's GRC/compliance platform, partnering with control owners to drive remediation activities through completion.
- Collaborate with Engineering, Development, Infrastructure, Security, and business stakeholders to design, implement, and continuously improve risk, resilience, recovery, and incident management processes.
- Support and continuously improve compliance with ISO 27001, ISO 27002, ISO 22301, and ISO 22313 through assessments, internal controls, audits, and remediation activities.
- Support customer security and compliance due diligence activities, including responding to security questionnaires (e.g., SIG, CAIQ, RFPs) in collaboration with the GRC team and subject matter experts.
- Provide guidance to business and technology teams on governance, risk, operational resilience, and compliance matters.
- Partner closely with Engineering, Infrastructure, Product, Security, and business teams to integrate governance, risk, and compliance practices into business and technology initiatives.
- Collaborate with cross-functional teams on a variety of Security GRC initiatives, contributing to governance, risk, compliance, and assurance programs in support of shared organizational goals.
Requirements
- Background in Information Technology, Information Security, Governance, Risk & Compliance (GRC), Internal Audit, Compliance, or Quality Management.
- Experience implementing and operating Business Continuity Management (BCM) and
- Disaster Recovery (DR) programs based on ISO 22301 and ISO 22313.
- Experience conducting Business Impact Analysis (BIA), defining RTO/RPO, recovery strategies, contingency planning, and business disruption scenarios.
- Experience planning and facilitating tabletop exercises and technical recovery tests for Business Continuity, Disaster Recovery, and Incident Response.
- Experience developing and maintaining policies, standards, procedures, and playbooks related to Business Continuity, Disaster Recovery, and Incident Response.
- Experience with ISO 27001 / ISO 27002 compliance.
- Knowledge of data protection best practices and compliance requirements under the LGPD and GDPR.
- Hands-on experience implementing controls and managing remediation plans.
- Knowledge of risk management frameworks (e.g., ISO 27005, NIST).
- Experience collaborating with Engineering and Development teams on resilience and compliance initiatives.
- Advanced English proficiency.
Nice to Have
- Experience with compliance automation and GRC platforms (e.g., Vanta, Drata, etc.).
- Experience with Business Continuity Management (BCM) tools.
- Experience working with multiple security frameworks and regulatory environments.
- Experience using task and project management platforms (e.g., Jira, Linear, Monday, etc.) to manage remediation plans and compliance initiatives.
- Market-recognized security certifications.
- Experience leveraging automation and Artificial Intelligence (AI) to improve GRC processes, evidence collection, reporting, and compliance operations.
Soft Skills
- Ability to collaborate effectively across technical and business teams.
- Excellent communication skills.
- Proactive, analytical, and solution-oriented.
- Highly organized, with strong attention to documentation and audit evidence.
- Team-oriented mindset (one person’s problem is everyone’s problem).
- Comfortable working in dynamic environments and navigating ambiguity.
- Ability to independently drive assigned initiatives and deliver high-quality results.
- Continuous improvement mindset focused on strengthening organizational resilience.
- Competitive salary and stock options
- 30 days of paid annual leave
- Education and courses stipend
- Earn a trip anywhere in the world every 4 years
- R$1.035/month for meals allowance
- Health plan with national coverage and without coparticipation
- Dental Insurance: we help you with dental treatment for a better quality of life.
- Wellhub and Sports Incentive: R$300/mo extra if you practice activities
Scan to Apply
Just scan this QR code to apply from your phone.
Job Location
São Paulo, São Paulo, Brazil
Frequently asked questions about this position
Similar Jobs In São Paulo, São Paulo
Marketing Analyst
Tractian
São Paulo, São Paulo
Continue to apply
Enter your email to continue. You’ll be redirected to the employer’s application.By clicking Continue, you understand and agree to JobTarget's Terms of Use and Privacy Policy.