Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Stone & Company

IT Specialist – Internal Controls, Technology Risk

Stone & Company

. Lead the technology workstream of the SOX program, including IT general controls (ITGCs) and automated process controls (ITACs) .

Posted 10/6/2026full-timeSão Paulo • BrazilMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in leading SOX compliance initiatives, including IT general controls and automated process controls, while ensuring adherence to Bacen regulations and the Brazilian General Data Protection Law. Proficient in managing technology risks, conducting audits, and providing strategic guidance to business and technology teams.

Highest-signal resume keywords
SOX Compliance ManagementIT General Controls (ITGCs)Automated Process Controls (ITACs)Bacen Regulations ComplianceCISA Certification

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
IT AuditTechnology Risk ManagementData AnalysisSQLExcelControl DesignChange Control AssessmentAutomated Control TestingCI/CD PipelinesSegregation of Duties
Soft Skills
LeadershipCommunicationProblem ResolutionConsultative GuidanceCollaboration
Tools & Technologies
AWSAzurePower BITableauAlteryxServiceNow IRMAuditBoardSAP GRCArcherRPA
Certifications & Qualifications
CISACRISCCISMCISSPCloud Certifications (AWS/Azure)
Industry Keywords
BacenLGPDCOSO 2013COBIT 2019PCAOB AS 2201ISO 31000NIST CSFISO 27001ISO 27005ITIL

Tech Stack

Tools & technologies
AWSAzureCloudRPAServiceNowSQLTableau

About the role

Key responsibilities & impact
  • Lead the technology workstream of the SOX program, including IT general controls (ITGCs) and automated process controls (ITACs)
  • Ensure that ITGCs, automated controls, system-generated reports (IPE), and interfaces are properly designed, tested, and effectively maintained
  • Ensure compliance with Bacen regulations, the Brazilian General Data Protection Law (LGPD), and other applicable regulations
  • Define the IT scope of the SOX program, including relevant systems, databases, infrastructure, and service providers
  • Plan and manage implementation and ongoing support schedules, including interim testing and roll-forward procedures
  • Coordinate analysts and consulting firms, reviewing workpapers
  • Serve as the technical focal point for external and internal audits
  • Manage access controls, privileged access management (PAM), service accounts, and periodic reviews
  • Assess change controls, segregation between development and production, CI/CD pipelines, and emergency changes
  • Design and test automated controls using ITGC-supported baselines and benchmarks
  • Conduct tests of design (TOD) and tests of operating effectiveness (TOE)
  • Define and track remediation plans with IT and business teams
  • Align SOX controls with applicable CMN and Bacen regulations for S3 institutions
  • Assess critical service providers and SOC 1/SOC 2 reports, ensuring that applicable complementary user entity controls (CUECs) are implemented by the institution
  • Integrate this workstream with operational risk, information security, and LGPD initiatives
  • Prepare periodic reports and executive materials, communicating risks to leadership
  • Lead analysts and consulting firms and translate complex technology risks for the CTO, CRO, and Audit Committee
  • Act as an internal consultant for business and technology teams, providing guidance on control design and problem resolution

Requirements

What you’ll need
  • Bachelor’s degree in Information Systems, Computer Science, or a related field
  • Experience in IT audit, technology risk, or IT internal controls, including leading full SOX cycles
  • Experience working at a financial institution regulated by Bacen
  • Knowledge of COSO 2013, COBIT 2019, PCAOB AS 2201, and ISO 31000
  • Knowledge of data analysis tools, including Excel, SQL, and similar platforms
  • Advanced English proficiency
  • Graduate degree in IT Governance, Information Security, Systems Auditing, or Risk Management
  • CISA, CRISC, CISM, CISSP, or cloud certifications (AWS/Azure)
  • Big Four experience
  • Experience with Bacen supervisory cycles
  • Knowledge of NIST CSF, ISO 27001, ISO 27005, and ITIL
  • Experience with AWS or Azure environments (IAM, logging, and cloud changes), Power BI, Tableau, or Alteryx
  • Knowledge of GRC platforms (ServiceNow IRM, AuditBoard, SAP GRC, Archer), analytics, and test automation (RPA)
  • Spanish proficiency

Benefits

Comp & perks
  • Base salary
  • Variable compensation package (profit sharing, long-term incentive plan, or commission), subject to role eligibility
  • Health and dental insurance with co-payment
  • Hospital Virtual Verde: telemedicine team available 24 hours a day, 7 days a week
  • Medication allowance
  • Meal and/or grocery allowance – Pluxee
  • Childcare allowance for children up to 5 years and 11 months old
  • Allowance for children with disabilities
  • Life insurance
  • Fuel allowance or commuting allowance
  • Home-office allowance for hybrid or remote contracts
  • Welcome kit for new parents
  • SESC partnership
  • Education benefit: internal self-development platform (Studa and Stone Library)
  • Acolhe360º: free emotional support
  • Quick massage and on-site clinic
  • Wellhub
  • TotalPass
  • Pet Club
  • Flash
  • Férias&Co
  • Transportation voucher
  • Allya
  • Educational partnerships