Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Funcional Health Tech

Information Security Governance Analyst (Mid-Level)

Funcional Health Tech

. Develop and deliver awareness campaigns and training, adapting content and approaches to the company’s different audiences .

Posted 10/8/2026full-timeRemote • BrazilMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Information Security Management System (ISMS) implementation and maintenance, with a strong focus on compliance with ISO/IEC 27001 and effective governance processes. Proficient in developing policies, managing security audits, and communicating complex information to diverse audiences.

Highest-signal resume keywords
Information Security Management System (ISMS)ISO/IEC 27001 CertificationGovernance, Risk, and Compliance (GRC)Control Assessment and ImprovementAnalytical Thinking

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Information Security PoliciesControl Evidence AnalysisSecurity Questionnaire ResponseAudit ManagementRisk AssessmentControl Maturity AssessmentAwareness Campaign DevelopmentTraining EvaluationDocumentation ManagementVulnerability Management
Soft Skills
Clear CommunicationActive ListeningOrganizational SkillsNegotiationAdaptability
Tools & Technologies
ExcelWordPowerPointDocumentation Management ToolsRequest Tracking Tools
Certifications & Qualifications
Information Security CertificationGRC CertificationISO/IEC 27001 Certification
Industry Keywords
GovernanceRisk ManagementAuditControl FrameworksBrazil’s General Data Protection Law (LGPD)PrivacyPersonal Data ProtectionBusiness ContinuityIdentity and Access Management

About the role

Key responsibilities & impact
  • Develop and deliver awareness campaigns and training, adapting content and approaches to the company’s different audiences
  • Manage responses to customer security questionnaires, audits, and assessments by interpreting requirements, gathering information, and validating responses with the responsible teams
  • Organize and keep control evidence up to date, assessing its alignment with requirements and promoting its reuse in assessments, audits, and certification initiatives
  • Track action plans, deadlines, and outstanding items related to risks, controls, and audits, coordinating owners and next steps with the relevant teams and flagging deviations
  • Develop and review Information Security policies, regulations, and procedures, taking business needs and applicable controls into account
  • Perform control assessments based on frameworks such as CIS Controls and ISO/IEC 27001, identifying gaps and proposing improvements
  • Contribute to initiatives to establish and mature the Information Security Management System (ISMS)
  • Consolidate metrics, reports, and presentations, communicating results, risks, and priorities to different audiences, including managers and senior leadership
  • Identify opportunities to improve governance processes, making request tracking and evidence management more efficient

Requirements

What you’ll need
  • Completed bachelor’s degree or additional education related to Information Security, Technology, Governance, Risk, Audit, or a related field
  • Practical experience in GRC, Information Security, IT audit, or security-related internal controls
  • Certifications in Information Security, GRC, or auditing, particularly those related to ISO/IEC 27001
  • Experience developing or reviewing policies and other normative documents, as well as organizing and analyzing control evidence
  • Experience responding to security questionnaires, audits, or assessments
  • Ability to interpret requirements, assess controls, identify gaps, and track action plans
  • Clear, assertive verbal and written communication, with the ability to adapt language for technical, business, and executive audiences
  • Ability to engage with different departments and organizational levels, align expectations, and manage requests with courtesy, active listening, and objectivity
  • Analytical thinking to connect information, identify inconsistencies, and propose solutions appropriate to the organization’s context
  • Organization and autonomy to manage multiple requests, negotiate deadlines and priorities, and flag when guidance or a decision is needed
  • Proficiency in Excel, Word, and PowerPoint, or equivalent tools
  • Participation in projects involving the implementation, maintenance, or certification of an ISMS based on ISO/IEC 27001
  • Experience assessing control maturity and tracking improvement initiatives
  • Experience with awareness campaigns, training, and evaluating their effectiveness
  • Knowledge of privacy, personal data protection, and Brazil’s General Data Protection Law (LGPD)
  • Familiarity with vulnerability management, business continuity, and identity and access management
  • English proficiency for reading requirements and preparing responses to security questionnaires and assessments
  • Familiarity with tools for managing requests, action plans, and documentation

Benefits

Comp & perks
  • Health and dental insurance
  • Pharmacy benefit: Funcional subsidizes part of the cost of your medications
  • Life insurance
  • Flu vaccination
  • Integrated health management program for employees and their dependents
  • TotalPass: access to gyms and wellness services
  • Childcare assistance
  • Extended maternity and paternity leave
  • Home office allowance (for remote positions)
  • Transportation allowance (for on-site positions)
  • Meal and food allowance
  • Annual profit-sharing program (for eligible positions)
  • Birthday day off
  • Ongoing professional development initiatives
  • Partnerships with educational institutions
  • Collaborative environment
  • Agile culture focused on continuous evolution