Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
IPIRANGA

Senior Information Security Governance Analyst

IPIRANGA

. Support and enhance Information Security Governance, Risk, and Compliance (GRC) processes .

Posted 10/3/2026full-timeRemote • BrazilSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Information Security Governance, Risk, and Compliance (GRC) processes, with a strong focus on risk management, IT auditing, and compliance with ISO 27001 and other regulatory requirements. Proficient in drafting policies, leading awareness programs, and developing documentation for audits and assessments.

Highest-signal resume keywords
Governance, Risk, And Compliance (GRC)IT AuditingRisk ManagementISO 27001Information Security Awareness Programs

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk ManagementIT AuditingPolicy DraftingInternal ControlsThird-Party ManagementMetrics And Key Performance IndicatorsDocumentation DevelopmentAudit Evidence PreparationSecurity AssessmentsCompliance Monitoring
Soft Skills
CommunicationLeadershipOrganizational SkillsCollaborationTraining Development
Industry Keywords
Information Security GovernanceCompliance RequirementsISO 27001SOXRisk RegisterExecutive ReportingPhishing CampaignsAudit ProcessesAwareness MetricsDocumentation Standards

About the role

Key responsibilities & impact
  • Support and enhance Information Security Governance, Risk, and Compliance (GRC) processes
  • Ensure compliance with corporate policies, regulatory requirements, internal controls, and industry best practices
  • Lead activities involving risk management, audits, metrics, awareness, documentation, third-party management, and tracking of Information Security action plans
  • Draft, review, and maintain Information Security policies, standards, procedures, and controls
  • Support internal and external audit processes
  • Track nonconformities and remediation plans
  • Produce evidence for audits and regulatory assessments
  • Support initiatives related to ISO 27001, SOX, and other compliance requirements
  • Perform cybersecurity risk identification, assessment, and monitoring activities
  • Support maintenance of the risk register
  • Monitor risk treatment plans and risk acceptances
  • Prepare executive reports on the evolution of Information Security risks
  • Conduct security assessments of vendors and partners
  • Support third-party onboarding and approval processes
  • Review Information Security requirements in contracts
  • Track remediation activities for critical vendors
  • Plan and execute Information Security awareness campaigns
  • Coordinate simulated phishing campaigns
  • Develop communications and training materials
  • Monitor the effectiveness metrics of awareness programs
  • Keep departmental documentation up to date
  • Structure evidence for audits and certifications
  • Support the organization of the repository for processes, controls, and standards
  • Ensure compliance with corporate documentation standards
  • Consolidate Information Security metrics
  • Prepare dashboards and executive presentations
  • Track risk, audit, third-party, and awareness metrics
  • Support governance forums and internal committees

Requirements

What you’ll need
  • Bachelor's degree in Information Technology, Information Security, Engineering, Information Systems, or a related field
  • Experience in Governance, Risk, and Compliance (GRC)
  • Experience with IT audits
  • Experience in risk management and internal controls
  • Experience drafting policies, standards, and procedures
  • Experience leading Information Security awareness programs
  • Required knowledge of risk management
  • Required knowledge of Information Security governance
  • Required knowledge of IT auditing
  • Required knowledge of ISO 27001
  • Required knowledge of internal controls
  • Required knowledge of third-party management
  • Required knowledge of metrics and key performance indicators
  • Required knowledge of developing documentation and audit evidence

Benefits

Comp & perks
  • Flexible working hours
  • Support for children with disabilities
  • Variable compensation program
  • Private pension plan
  • Tenure-based additional pay
  • Online therapy and nutritional guidance
  • Newborn care package
  • Corporate university
  • Gympass
  • Meal and food vouchers
  • Transportation voucher
  • Health and dental insurance
  • Life insurance