Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
ASAAS

Senior Information Security Risk and Controls Analyst

ASAAS

. Lead the full cycle of information security risk identification, analysis, assessment, and treatment based on ISO/IEC 27005 .

Posted 9/25/2026full-timeRemote • BrazilSeniorWebsite

Tech Stack

Tools & technologies
Cloud

About the role

Key responsibilities & impact
  • Lead the full cycle of information security risk identification, analysis, assessment, and treatment based on ISO/IEC 27005
  • Apply and evolve the organization’s risk methodology, including qualitative matrices and quantitative models where applicable
  • Define and track risk treatment plans through closure or formal acceptance
  • Maintain and test the information security controls framework, assessing effectiveness, exceptions, and corrective action plans
  • Conduct maturity assessments and gap analyses based on ISO/IEC 27001/27002, NIST CSF, and CIS Controls
  • Conduct vendor and third-party risk assessments (TPRM)
  • Structure and maintain KRIs/KPIs and produce technical and executive reports
  • Serve as a technical advisor to Product, Engineering, Cloud, Compliance, and Legal teams
  • Support formal risk acceptance and exception management processes through documentation, governance, and periodic reviews

Requirements

What you’ll need
  • Demonstrated experience in information security risk management
  • Strong practical and in-depth knowledge of ISO/IEC 27005
  • Solid knowledge of ISO/IEC 27001/27002, NIST CSF, and CIS Controls
  • Experience managing vendor and third-party risk (TPRM), including due diligence, criticality assessments, and monitoring contractual requirements
  • Ability to design control effectiveness testing, manage evidence, and track action plans through closure
  • Strong technical writing and communication skills, with the ability to translate complex risks into clear language for executive audiences
  • Highly organized, self-directed, and sufficiently senior to lead complex analyses with minimal supervision
  • Preferred: certifications such as ISO 27005 Risk Manager, CRISC, or ISO 27001 Lead Implementer/Auditor
  • Preferred: experience with quantitative risk modeling (FAIR or equivalent)
  • Preferred: experience in regulated environments, particularly payment institutions or financial institutions subject to regulations issued by the Central Bank of Brazil

Benefits

Comp & perks
  • Medical and dental insurance with no copayment
  • Life insurance
  • Medication assistance
  • Fitness allowance
  • Four free monthly therapy or nutritionist sessions through Zenklub
  • Quick massage at the headquarters
  • Flexible meal benefit on a Visa card
  • Free food at the headquarters
  • Childcare assistance
  • Parental support program
  • Extended maternity and paternity leave
  • In-company training platform
  • Education assistance covering 70% of tuition for undergraduate programs and language courses, as well as courses and books
  • Home office allowance
  • Work equipment
  • Furniture allowance
  • Partnership with WOBA for coworking access throughout Brazil
  • Birthday month day off
  • Happy hour allowance
  • Referral bonus for new hires
  • Annual performance-based bonus
  • Stock options plan
  • No dress code