12h ago
New

Analista de Riscos e Controles de Segurança da Informação Sênior

BrazilBrazilRemoteFull-timemid
OtherAnalista
2 views0 saves0 applied

Quick Summary

Requirements Summary

Proven professi

Technical Tools
OtherAnalista

As a Senior Information Security Risk and Controls Analyst, you will play a key role in identifying, assessing, and treating information security risks across the organization. You will help strengthen security controls, evaluate their effectiveness, and drive remediation initiatives through to completion. The role also includes third-party risk management, security maturity assessments, and governance activities. You will work closely with Product, Engineering, Cloud, Compliance, and Legal teams to embed security and risk management into projects from the beginning. Your ability to investigate complex scenarios and translate technical risks into clear recommendations will support both operational and executive decision-making. This is a highly autonomous role in a collaborative, agile environment where technical expertise and attention to detail are valued.

  • Lead the end-to-end information security risk management lifecycle, including risk identification, analysis, evaluation, and treatment in accordance with ISO/IEC 27005.
  • Apply and continuously improve risk management methodologies, including qualitative probability-versus-impact matrices and, where appropriate, quantitative approaches such as FAIR.
  • Define and monitor risk treatment plans covering mitigation, transfer, acceptance, or avoidance, ensuring appropriate follow-up through formal closure or acceptance.
  • Maintain and test the information security controls framework, assessing control effectiveness, documenting exceptions, and monitoring corrective action plans.
  • Conduct security control maturity assessments and gap analyses based on frameworks such as ISO/IEC 27001/27002, NIST CSF, and CIS Controls.
  • Lead third-party and supplier risk assessments, including due diligence, criticality classification, and monitoring of contractual security requirements.
  • Develop and maintain risk and control indicators, including KRIs and KPIs, and prepare technical and executive-level reports to support decision-making.
  • Act as a technical advisor to Product, Engineering, Cloud, Compliance, and Legal teams, promoting security-by-design and risk mitigation throughout project development.
  • Support formal risk acceptance and exception management processes through appropriate documentation, governance, and periodic reviews.

Requirements

~1 min read
  • Proven professional experience in information security risk management.
  • Strong practical and in-depth knowledge of ISO/IEC 27005, including risk identification, analysis, evaluation, probability and impact criteria, and treatment planning.
  • Solid understanding of ISO/IEC 27001/27002, NIST CSF, and CIS Controls and their relationship to information security risk management.
  • Experience with third-party risk management (TPRM), including supplier due diligence, criticality assessments, and contractual security requirements.
  • Demonstrated ability to design and perform control effectiveness testing, manage supporting evidence, and track remediation plans through completion.
  • Strong technical writing and communication skills, with the ability to translate complex security risks into clear language for executive and business audiences.
  • Strong organization, autonomy, analytical thinking, and senior-level judgment when handling complex assessments with limited supervision.
  • Bachelor's degree or equivalent professional background in information security, technology, risk management, or a related field is desirable.
  • Certifications such as ISO 27005 Risk Manager, CRISC, or ISO 27001 Lead Implementer/Auditor are desirable.
  • Experience with quantitative risk modeling, such as FAIR or equivalent methodologies, is a plus.
  • Experience in regulated environments, particularly financial or payment institutions subject to Central Bank of Brazil regulations, is a plus.
  • Ability to translate regulatory requirements into practical security and risk management processes is desirable.

What We Offer

~2 min read
✓Full-time CLT employment.
✓Monday to Friday schedule, 8 hours per day.
✓Fully remote/home-office work within Brazil.
✓Medical and dental insurance with no copay.
✓Life insurance.
✓Medication assistance.
✓Physical activity and wellness assistance.
✓Financial wellness support.
✓Four free monthly sessions with therapy or nutrition professionals.
✓Flexible food allowance through a Visa card.
✓Childcare assistance.
✓Parental support program.
✓Extended maternity and paternity leave.
✓Education assistance covering 70% of eligible undergraduate, language, course, and book expenses.
✓Access to professional training and development programs.
✓Home-office allowance and work equipment.
✓Furniture allowance for remote work.
✓Access to coworking spaces across Brazil.
✓Birthday Day Off.
✓Happy Hour allowance.
✓Employee referral bonuses.
✓Annual goal-based bonus opportunities.
✓Stock option plan.
✓Flexible, collaborative work environment with no formal dress code.

Location & Eligibility

Where is the job
Brazil
Remote within one country
Who can apply
BR

Listing Details

Posted
September 29, 2026
First seen
September 29, 2026
Last seen
September 29, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
68%
Scored at
September 29, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Analista de Riscos e Controles de Segurança da Informação Sênior