Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Swap

Senior Privacy and Data Protection Analyst

Swap

. Structure, implement, operate, and continuously improve Swap’s Privacy and Personal Data Protection Program .

Posted 10/10/2026full-timeSão Paulo • BrazilSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Privacy and Data Protection, ensuring compliance with Brazil's LGPD and other regulatory requirements. Proficient in conducting privacy risk assessments, managing data subject rights requests, and implementing Information Security Management Systems aligned with ISO standards.

Highest-signal resume keywords
LGPD ComplianceData Protection Impact Assessments (DPIAs)Information Security Management System (ISMS)GRC and Risk ManagementISO 27001 and PCI DSS Knowledge

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Privacy Risk AssessmentsPersonal Data MappingRecords of Processing ActivitiesCorporate Policy ManagementAudit Preparation and SupportRisk Control MatricesDocument GovernanceThird-Party Risk Management (TPRM)Impact AssessmentsRegulatory Compliance
Soft Skills
Strong Written CommunicationStrong Verbal CommunicationOrganizational SkillsAutonomyCollaboration
Tools & Technologies
GRC ToolsDocument Management SystemsProcess Automation ToolsEvidence Tracking Systems
Certifications & Qualifications
ISO 27001 CertificationISO 27701 KnowledgePCI DSS Knowledge
Industry Keywords
FintechBanking as a Service (BaaS)Central Bank of BrazilCybersecurityRegulated Financial Services

About the role

Key responsibilities & impact
  • Structure, implement, operate, and continuously improve Swap’s Privacy and Personal Data Protection Program
  • Ensure compliance with the requirements of Brazil’s General Data Protection Law (LGPD) and other applicable legal, regulatory, and contractual obligations
  • Maintain an up-to-date inventory of personal data and records of processing activities, including purposes, legal bases, sharing, retention, and disposal
  • Conduct privacy risk assessments and prepare or coordinate DPIAs (Data Protection Impact Assessments)
  • Support the handling of data subject rights requests and other privacy-related matters
  • Participate in the assessment of new products, projects, processes, integrations, and vendors, incorporating privacy requirements from the outset (Privacy by Design)
  • Support the management of incidents involving personal data, including impact assessments, documentation, and assistance with applicable communications and notifications
  • Promote privacy and data protection awareness and training initiatives
  • Support the development of the GRC program by integrating regulatory requirements, enterprise risks, and Information Security controls
  • Identify, assess, document, and monitor risks, control deficiencies, action plans, and related evidence
  • Maintain risk and control matrices, ensuring accountability, deadlines, metrics, and follow-up on corrective actions
  • Support the maintenance and continuous improvement of the Information Security Management System (ISMS) aligned with ISO 27001
  • Monitor requirements from regulatory authorities, such as the Central Bank of Brazil, as well as contractual commitments and requirements from customers and partners
  • Support third-party risk management (TPRM) processes
  • Plan, coordinate, and monitor internal and external audits, independent assessments, and certification processes
  • Organize and maintain compliance evidence for audits related to the Central Bank of Brazil, PCI DSS, ISO 27001, and other applicable requirements
  • Act as the focal point for internal teams, auditors, consultants, and other stakeholders in collecting evidence and clarifying controls
  • Track findings, nonconformities, recommendations, and remediation plans through completion
  • Assess the effectiveness of implemented controls, identifying improvement opportunities and residual risks
  • Support responses to security questionnaires, customer assessments, and requests for compliance evidence
  • Manage the lifecycle of corporate policies, standards, procedures, and guidelines, from drafting through approval, publication, review, and communication
  • Ensure documentation is aligned with regulatory requirements, internal policies, and Information Security practices
  • Maintain document governance, including version control, ownership, review frequency, and approval history
  • Support responsible teams in defining corporate procedures and controls
  • Monitor adherence to policies and support the handling of deviations and exceptions

Requirements

What you’ll need
  • Bachelor’s degree in Information Security, Law, Business Administration, Information Systems, Risk Management, or a related field
  • Strong experience in Privacy and Data Protection, with hands-on experience implementing and maintaining LGPD compliance programs
  • Applied knowledge of personal data mapping, legal bases, records of processing activities, and privacy risk assessments
  • Experience preparing DPIAs (Data Protection Impact Assessments) and analyzing risks associated with the processing of personal data
  • Experience with GRC, risk management, internal controls, action plans, and process governance
  • Experience preparing for and supporting internal and external audits, including the collection and validation of evidence
  • Knowledge of frameworks and standards such as ISO 27001, ISO 27701, and PCI DSS, as well as regulatory requirements applicable to the financial sector
  • Experience drafting and managing the lifecycle of corporate policies, standards, and procedures
  • Ability to collaborate with Technical, Legal, Compliance, Product, Operations, Engineering, and vendor teams
  • Strong written and verbal communication, organization, autonomy, and the ability to manage multiple initiatives simultaneously
  • Previous experience in fintechs, payment institutions, Banking as a Service (BaaS), or regulated financial services companies is a plus
  • Experience with audits and Central Bank of Brazil requirements, including matters related to Pix, cybersecurity, and the outsourcing of relevant services is a plus
  • Experience implementing or maintaining an ISMS and preparing for ISO 27001 certification is a plus
  • Knowledge of SOC 2, ISO 27701, and risk management frameworks is a plus
  • Experience with TPRM, vendor assessments, and reviewing contractual clauses related to security and privacy is a plus
  • Familiarity with GRC tools, document management, process automation, and evidence tracking is a plus
  • Experience defining metrics and executive reports on risk, compliance, and privacy is a plus

Benefits

Comp & perks
  • SulAmérica health insurance (including dependents, with no monthly premium or copayment)
  • SulAmérica dental insurance (with no monthly premium or copayment)
  • Meal/Food Allowance (flexible card)
  • Childcare assistance for parents with children up to 5 years and 11 months old
  • Financial assistance for parents of children with disabilities
  • Prudential group life insurance
  • Wellhub partnership
  • Onhappy partnership (leisure travel)
  • Variable Compensation Program (according to the department and role)