Grupo QuintoAndar | Information Security Manager - GRC

8 hours, 6 minutes ago
Full-time
Lead
Cybersecurity
QuintoAndar

QuintoAndar

QuintoAndar: Simplifying home search with online rental and purchase services, secure payments, and free rental insurance. Revolutionizing Brazil's real estate market with a talented team and innovative business model.

Real Estate
1K-5K
Founded 2012
$755M raised

Description

  • Develop and lead the GRC strategy and roadmap in alignment with business objectives, budget, and risk appetite.
  • Own the security service channel and security portfolio, prioritizing and coordinating security requests and initiatives.
  • Lead information security governance, including AI governance policies, guidelines, and controls.
  • Lead IAM governance initiatives aligned with risk management and SOX compliance requirements.
  • Manage and develop a high-performing team of GRC specialists and third-party partners.
  • Lead the end-to-end cyber risk management program, including identification, treatment, monitoring, and remediation.
  • Quantify cyber risk financially using methodologies such as FAIR.
  • Lead third-party risk management and cyber resilience programs for vendors and the supply chain.
  • Ensure continuous compliance with regulations and frameworks, and represent the company in audits and regulatory interactions.
  • Define, report, and present KPIs, KRIs, and maturity metrics to executive leadership and security committees.
  • Lead security awareness programs and track behavioral risk reduction.
  • Structure, simplify, review, and maintain information security policies, standards, procedures, and processes.
  • Partner with Technology, Engineering, Product, Legal, Privacy, Finance, Compliance, Internal Audit, and business leaders to reduce risk and improve processes.

Requirements

  • 10+ years of experience in Information Security GRC, including at least 5 years in leadership and team management roles.
  • Experience in complex, dynamic, multinational environments, preferably in tech companies, scale-ups, or the financial sector.
  • Experience managing security demand intake and portfolio prioritization, ideally using ITSM practices.
  • Deep knowledge of frameworks and standards such as NIST CSF 2.0, ISO 27001/27002, CIS Controls, SOX, and ISO 31000.
  • Ability to translate cyber risks into financial and operational impact using methodologies such as FAIR.
  • Experience designing security KPI/KRI frameworks and maturity models for executive reporting.
  • Experience designing vendor risk assessment methodologies and third-party risk management programs.
  • Experience leading IAM governance initiatives and aligning access controls with risk and compliance requirements.
  • Experience supporting SOX compliance programs, including IT General Controls (ITGC).
  • Experience designing and running security awareness and behavior change programs.
  • Ability to use automation and AI to scale GRC processes, such as automated evidence collection and continuous controls monitoring.
  • Fluency in Portuguese and advanced English.
  • CISSP, CISM, CRISC, or ISO 27001 Lead Auditor certification is preferred.

Benefits

  • Competitive salary.
  • Profit sharing.
  • Meal allowance.
  • Health insurance.
  • Dental plan.
  • Life insurance.
  • Childcare subsidy and atypical parenthood subsidy.
  • Wellhub.
  • Home office allowance.
  • Employee assistance program with mental health, social, legal, and financial support.
  • Extended parental leave.
  • Day off on birthday, Mother’s Day, and Father’s Day.
  • Benefits club with discounts on everyday services.
  • Discounts at educational institutions.
  • Reading kit for children via PlayKids.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Vulnerability Researchers / Security Researchers

SevenPro 51-250 Internet Software & Services

Barcelona-based R&D center is hiring a Vulnerability Researcher / Security Researcher to perform hands-on research, exploitation, and validation of vulnerabilities in complex software systems.

Android Embedded Systems iOS Linux macOS
1 day, 8 hours ago

Principal Consultant - Security

TEECOM 51-250 Construction & Engineering

TEECOM is hiring a Principal, Consultant to lead complex multi-discipline project delivery, provide technical leadership, and strengthen discipline standards and client relationships.

Agile Asana GitHub
2 days, 8 hours ago

Senior Security Researcher

Cobalt 251-1K Internet Software & Services

Cobalt.io is hiring a Senior Security Researcher to lead advanced vulnerability research and offensive security assessments across modern software, cloud, and enterprise environments.

AWS Azure Bash Docker GCP Go Java Kubernetes Linux macOS Node.js Python Rust
3 days, 7 hours ago

Offensive Security Engineer

ClickHouse 51-250 IT Services

ClickHouse is hiring an experienced Security practitioner to strengthen the security posture of its cloud data platform, products, and services through offensive security, incident response, and security automation.

AWS Azure GCP Kubernetes Penetration Testing
4 days, 7 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers