FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior GRC Security Analyst
Stefanini Brasil. Establish governance, risk, and compliance processes for the new security function .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in establishing governance, risk, and compliance processes, along with a strong foundation in information security policies and frameworks. Proficient in conducting audits, managing vendor risks, and leading crisis management initiatives.
Highest-signal resume keywords
Governance, Risk, And Compliance (GRC)ISO 27001 Lead AuditorRisk ManagementInternal And External AuditsCrisis Management
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Information Security PoliciesRisk AssessmentAudit Framework DevelopmentVendor Risk ManagementRisk Metrics AutomationSecurity InspectionsCrisis Management ExercisesExecutive PresentationsContractual ImprovementsIncident Response
Soft Skills
Strong Communication SkillsNegotiation Skills
Tools & Technologies
GRC Tools
Certifications & Qualifications
ISO 27001CRISCInformation Security Certifications
Industry Keywords
NISTCIS ControlsInternational Information Security LawsCompliance Standards
About the role
Key responsibilities & impact- Establish governance, risk, and compliance processes for the new security function
- Map processes and risks across corporate operations
- Develop and review information security policies
- Define the internal audit framework and execute the scheduled audit program
- Support audits requested by clients and market regulatory bodies
- Lead business continuity assessments, including practical DR and BCP exercises
- Conduct vendor security assessments (vendor risk management)
- Build dashboards with risk indicators and ratings specific to each operation
- Mitigate risks by recommending compensating plans and tracking the implementation of action plans
- Issue formal letters and risk communications to provide legal protection for the company when clients fail to meet requirements
- Develop executive presentations for clients
- Support the establishment of risk committees
- Create vendor catalogs focused on incident response
- Lead corporate crisis management
- Support direct technical communications with clients during incident response crises
- Review and propose contractual improvements focused on security
Requirements
What you’ll need- Bachelor's degree in Computer Science, Information Systems, or a related field
- Knowledge of ISO 27001 Lead Auditor or CRISC
- Experience automating risk and compliance metrics
- Knowledge of ISO 27001, NIST, and CIS Controls frameworks
- Knowledge of risk management and auditing
- Experience in security GRC/compliance
- Experience conducting internal and external audits and certification audits
- Experience conducting security inspections to assess maturity and compliance
- Additional information security certifications are a plus
- Experience delivering information security training and workshops is a plus
- Demonstrated experience in crisis management is a plus
- Knowledge of international information security laws and standards is a plus
- Experience with GRC tools is a plus
- Strong communication and negotiation skills for engaging with diverse stakeholders are a plus
Benefits
Comp & perks- Meal allowance or food voucher
- Discounts on courses, universities, and language institutions
- Stefanini Academy — a platform offering free, up-to-date online courses with certificates
- Mentoring
- Benefits club offering discounts on consultations and medical tests
- Medical insurance
- Dental insurance
- Benefits and discounts at leading establishments
- Travel club
- Pet benefits program