Jobgether

Analista de Riscos e Controles de Segurança da Informação Sênior

Jobgether

ISO/IEC 27005ISO/IEC 27001NIST CSFCIS Controlsthird-party risk managementrisk identificationRisk Analysisrisk treatment planningcontrol effectiveness testingquantitative risk modeling

About the Role

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Analista de Riscos e Controles de Segurança da Informação Sênior based in Brazil. As a Senior Information Security Risk and Controls Analyst, you will play a key role in identifying, assessing, and treating information security risks across the organization. You will help strengthen security controls, evaluate their effectiveness, and drive remediation initiatives through to completion. The role also includes third-party risk management, security maturity assessments, and governance activities. You will work closely with Product, Engineering, Cloud, Compliance, and Legal teams to embed security and risk management into projects from the beginning. Your ability to investigate complex scenarios and translate technical risks into clear recommendations will support both operational and executive decision-making. This is a highly autonomous role in a collaborative, agile environment where technical expertise and attention to detail are valued. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Analista de Riscos e Controles de Segurança da Informação Sênior based in Brazil. As a Senior Information Security Risk and Controls Analyst, you will play a key role in identifying, assessing, and treating information security risks across the organization. You will help strengthen security controls, evaluate their effectiveness, and drive remediation initiatives through to completion. The role also includes third-party risk management, security maturity assessments, and governance activities. You will work closely with Product, Engineering, Cloud, Compliance, and Legal teams to embed security and risk management into projects from the beginning. Your ability to investigate complex scenarios and translate technical risks into clear recommendations will support both operational and executive decision-making. This is a highly autonomous role in a collaborative, agile environment where technical expertise and attention to detail are valued. Accountabilities: Lead the end-to-end information security risk management lifecycle, including risk identification, analysis, evaluation, and treatment in accordance with ISO/IEC 27005. Apply and continuously improve risk management methodologies, including qualitative probability-versus-impact matrices and, where appropriate, quantitative approaches such as FAIR. Define and monitor risk treatment plans covering mitigation, transfer, acceptance, or avoidance, ensuring appropriate follow-up through formal closure or acceptance. Maintain and test the information security controls framework, assessing control effectiveness, documenting exceptions, and monitoring corrective action plans. Conduct security control maturity assessments and gap analyses based on frameworks such as ISO/IEC 27001/27002, NIST CSF, and CIS Controls. Lead third-party and supplier risk assessments, including due diligence, criticality classification, and monitoring of contractual security requirements. Develop and maintain risk and control indicators, including KRIs and KPIs, and prepare technical and executive-level reports to support decision-making. Act as a technical advisor to Product, Engineering, Cloud, Compliance, and Legal teams, promoting security-by-design and risk mitigation throughout project development. Support formal risk acceptance and exception management processes through appropriate documentation, governance, and periodic reviews. Requirements: Proven professional experience in information security risk management. Strong practical and in-depth knowledge of ISO/IEC 27005, including risk identification, analysis, evaluation, probability and impact criteria, and treatment planning. Solid understanding of ISO/IEC 27001/27002, NIST CSF, and CIS Controls and their relationship to information security risk management. Experience with third-party risk management (TPRM), including supplier due diligence, criticality assessments, and contractual security requirements. Demonstrated ability to design and perform control effectiveness testing, manage supporting evidence, and track remediation plans through completion. Strong technical writing and communication skills, with the ability to translate complex security risks into clear language for executive and business audiences. Strong organization, autonomy, analytical thinking, and senior-level judgment when handling complex assessments with limited supervision. Bachelor's degree or equivalent professional background in information security, technology, risk management, or a related field is desirable. Certifications such as ISO 27005 Risk Manager, CRISC, or ISO 27001 Lead Implementer/Auditor are desirable. Experience with quantitative risk modeling, such as FAIR or equivalent methodologies, is a plus. Experience in regulated environments, particularly financial or payment institutions subject to Central Bank of Brazil regulations, is a plus. Ability to translate regulatory requirements into practical security and risk management processes is desirable. Benefits: Full-time CLT employment. Monday to Friday schedule, 8 hours per day. Fully remote/home-office work within Brazil. Medical and dental insurance with no copay. Life insurance. Medication assistance. Physical activity and wellness assistance. Financial wellness support. Four free monthly sessions with therapy or nutrition professionals. Flexible food allowance through a Visa card. Childcare assistance. Parental support program. Extended maternity and paternity leave. Education assistance covering 70% of eligible undergraduate, language, course, and book expenses. Access to professional training and development programs. Home-office allowance and work equipment. Furniture allowance for remote work. Access to coworking spaces across Brazil. Birthday Day Off. Happy Hour allowance. Employee referral bonuses. Annual goal-based bonus opportunities. Stock option plan. Flexible, collaborative work environment with no formal dress code. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1

You'll be redirected to Jobgether's application page

Job Details

Salary

Not disclosed

Location

Brazil

Job type

Full-time

Category

Security Engineering

Experience

Senior

Posted

Today

Job Highlights

  • Senior level role
  • 100% Remote — open to candidates in Brazil
  • Full-time position

About Jobgether

This job is hosted by Jobgether. Clicking Apply opens their site.

More jobs from Jobgether on RC9

Remote Work Style

Mixed

Mix of flexible and scheduled meetings

Your Match

See how well your skills line up with this role, and what you're missing.

AI Cover Letter

Generate a cover letter tailored to this job from your profile.