Dlocal
Dlocal13h ago
New

GRC Leader - Governance, Awareness & TPRM

ArgentinaArgentina·Buenos AiresFull Timelead
OtherGrc Lead
0 views0 saves0 applied

Quick Summary

Requirements Summary

Policies only have value if people know they exist and can realistically follow them. Your job is to align documented policy with day-to-day practice.

Technical Tools
OtherGrc Lead
Why should you join dLocal?
 
dLocal enables the biggest companies in the world to collect payments in 40 countries in emerging markets. Global brands rely on us to increase conversion rates and simplify payment expansion effortlessly. As both a payments processor and a merchant of record where we operate, we make it possible for our merchants to make inroads into the world’s fastest-growing, emerging markets. 
 
By joining us you will be a part of an amazing global team that makes it all happen. Being a part of dLocal means working with 1000+ teammates from 30+ different nationalities and developing an international career that impacts millions of people’s daily lives. We are builders, we never run from a challenge, we are customer-centric, and if this sounds like you, we know you will thrive in our team.
 
 
 

dLocal enables the biggest companies in the world to collect payments in 40 countries in emerging markets. Global brands rely on us to increase conversion rates and simplify payment expansion effortlessly. As both a payments processor and a merchant of record where we operate, we make it possible for our merchants to make inroads into the world's fastest-growing, emerging markets.

We do not do "check-box" compliance, and we don’t do corporate fluff.

Within the Security Department, reporting to the Head of GRC & Cyber Assurance, we are looking for a high-agency GRC Leader to own and uplift our Governance, Security Awareness, and Third-Party Risk Management programs across a complex, fast-moving global business.

This is not a caretaker role. We need a sharp operator who leads from the front, takes full ownership of delivery, and acts as the tactical bridge between regulatory requirements and operational reality. You will be measured on whether things actually change, not on whether documents exist.

  • Operationalize Governance: Policies only have value if people know they exist and can realistically follow them. Your job is to align documented policy with day-to-day practice. That means renegotiating existing policies and standards to make them practical, risk-calibrated, and enforceable. You will run the stakeholder process across security, engineering, and the business to land on controls that reduce risk without grinding operations to a halt. Once agreed, you own the rollout and track whether adoption is real.

  • Drive Security Awareness & Champions: Redefine how security expectations are communicated across the organization. No generic broadcasts. You will build targeted, high-ROI interventions using modern tools (including AI-assisted delivery) that actually change behavior. Alongside this, you will build and run a Security Champions program: recruiting motivated individuals embedded in engineering and business teams who act as the first line of security awareness and a feedback loop back to the security team.

  • Own TPRM & Payment Processor Risk: Take direct ownership of our global Third-Party Risk Management program, including the Payment Processor Assessment Framework. You will implement tiered, context-based reviews, eliminate unnecessary overhead, and clearly communicate residual risk positions to business stakeholders in language they can act on.

  • Run the Risk Register & Shift Left: Identify risks, quantify them in business terms, assign owners, and track remediation to closure. You will be in regular contact with business and engineering stakeholders to ensure risks are understood and actioned. When a risk needs to be formally accepted or escalated, you draft the paperwork and ensure the business owner (the first line of defense) actually signs it.

  • Lead Your Team & Execute Hands-On: Lead and mentor a sub-team across governance, awareness, and TPRM. You set a high delivery standard and own your team's output. When audit season hits or the workload requires it, you roll up your sleeves alongside your team to execute manual framework mapping across PCI DSS, SOX, and DORA.

  • Pragmatic Operator Mentality: You move fast and fix broken processes. You know the difference between what genuinely needs to change and what is noise. You are not a methodology presenter; you get things done where ambiguity and speed are the norm.

  • Stakeholder Navigation (High EQ & IQ): You read people and complex situations perfectly. You negotiate with VP-level commercial leaders, engineering directors, and external vendors. You find pragmatic compromises between security requirements and business velocity, and you know how to bring people along rather than impose.

  • Disciplined Multi-Threading: You are ruthlessly organized. You can manage a Payment Processor security review, a policy overhaul, and a team of direct reports simultaneously without dropping the ball.

  • AI Fluency: Deeply comfortable using LLMs to automate administrative governance work and move your team faster, expertly leveraging AI capabilities while ensuring strict data accuracy and hallucination governance.

  • Regulatory Knowledge: Strong working knowledge of PCI DSS, SOX, DORA, ISO 27001, and SOC 2. You can map controls, prepare audit evidence, and hold a credible conversation with an examiner.

  • Exceptional Communication: Fluent English is mandatory. You distill complex risk and governance topics into clear language for non-technical executive audiences and are equally comfortable in a policy workshop and a board-level risk briefing.

  • Prior experience leading GRC or Cyber Assurance teams in a fintech, payments, or tech scale-up environment.

  • Direct experience assessing or securing payment processors and financial institutions in emerging markets.

  • High autonomy, high accountability. You take direction from security leadership, figure out the "how," and execute. This is a senior leadership role for someone who wants to build programs that are practical, scalable, and genuinely trusted by the business.
    What do we offer?
     
    Besides the tailored benefits we have for each country, dLocal will help you thrive and go that extra mile by offering you:
    - Flexibility: we have flexible schedules and we are driven by performance.
    - Fintech industry: work in a dynamic and ever-evolving environment, with plenty to build and boost your creativity.
    - Referral bonus program: our internal talents are the best recruiters - refer someone ideal for a role and get rewarded.
    - Social budget: you'll get a monthly budget to chill out with your team (in person or remotely) and deepen your connections!
    - dLocal Houses: want to rent a house to spend one week anywhere in the world coworking with your team? We’ve got your back!
     
    Flexibility in how you work: We focus on impact and productivity over fixed hours. This means our teams have flexible schedules and, depending on your role and location, you will combine self‑managed focus time with moments of in‑person connection in our collaboration hubs.
     
    What happens after you apply?
    Our Talent Acquisition team is invested in creating the best candidate experience possible, so don’t worry, you will definitely hear from us. We will review your CV and keep you posted by email at every step of the process!
     
    Also, you can check out our webpageLinkedin and Youtube for more about dLocal!

    Location & Eligibility

    Where is the job
    Buenos Aires, Argentina
    Hybrid — some on-site time required
    Who can apply
    Open to applicants worldwide

    Listing Details

    Posted
    May 26, 2026
    First seen
    May 27, 2026
    Last seen
    May 27, 2026

    Posting Health

    Days active
    0
    Repost count
    0
    Trust Level
    70%
    Scored at
    May 27, 2026

    Signal breakdown

    freshnesssource trustcontent trustemployer trust
    Dlocal
    Dlocal
    lever

    dLocal is a Uruguayan company that specializes in cross-border payments, providing innovative local payment solutions for emerging markets.

    Employees
    750
    Founded
    2016
    View company profile
    Newsletter

    Stay ahead of the market

    Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

    A
    B
    C
    D
    Join 12,000+ marketers

    No spam. Unsubscribe at any time.

    DlocalGRC Leader - Governance, Awareness & TPRM