Grupo QuintoAndar | Information Security Manager - GRC

4 weeks, 2 days ago
Full-time
Lead
Cybersecurity
QuintoAndar

QuintoAndar

QuintoAndar: Simplifying home search with online rental and purchase services, secure payments, and free rental insurance. Revolutionizing Brazil's real estate market with a talented team and innovative business model.

Real Estate
1K-5K
Founded 2012
$755M raised

Description

  • Develop and lead the GRC strategy and roadmap in alignment with business objectives, budget, and risk appetite.
  • Own the security service channel and security portfolio, prioritizing and coordinating security requests and initiatives.
  • Lead information security governance, including AI governance policies, guidelines, and controls.
  • Lead IAM governance initiatives aligned with risk management and SOX compliance requirements.
  • Manage and develop a high-performing team of GRC specialists and third-party partners.
  • Lead the end-to-end cyber risk management program, including identification, treatment, monitoring, and remediation.
  • Quantify cyber risk financially using methodologies such as FAIR.
  • Lead third-party risk management and cyber resilience programs for vendors and the supply chain.
  • Ensure continuous compliance with regulations and frameworks, and represent the company in audits and regulatory interactions.
  • Define, report, and present KPIs, KRIs, and maturity metrics to executive leadership and security committees.
  • Lead security awareness programs and track behavioral risk reduction.
  • Structure, simplify, review, and maintain information security policies, standards, procedures, and processes.
  • Partner with Technology, Engineering, Product, Legal, Privacy, Finance, Compliance, Internal Audit, and business leaders to reduce risk and improve processes.

Requirements

  • 10+ years of experience in Information Security GRC, including at least 5 years in leadership and team management roles.
  • Experience in complex, dynamic, multinational environments, preferably in tech companies, scale-ups, or the financial sector.
  • Experience managing security demand intake and portfolio prioritization, ideally using ITSM practices.
  • Deep knowledge of frameworks and standards such as NIST CSF 2.0, ISO 27001/27002, CIS Controls, SOX, and ISO 31000.
  • Ability to translate cyber risks into financial and operational impact using methodologies such as FAIR.
  • Experience designing security KPI/KRI frameworks and maturity models for executive reporting.
  • Experience designing vendor risk assessment methodologies and third-party risk management programs.
  • Experience leading IAM governance initiatives and aligning access controls with risk and compliance requirements.
  • Experience supporting SOX compliance programs, including IT General Controls (ITGC).
  • Experience designing and running security awareness and behavior change programs.
  • Ability to use automation and AI to scale GRC processes, such as automated evidence collection and continuous controls monitoring.
  • Fluency in Portuguese and advanced English.
  • CISSP, CISM, CRISC, or ISO 27001 Lead Auditor certification is preferred.

Benefits

  • Competitive salary.
  • Profit sharing.
  • Meal allowance.
  • Health insurance.
  • Dental plan.
  • Life insurance.
  • Childcare subsidy and atypical parenthood subsidy.
  • Wellhub.
  • Home office allowance.
  • Employee assistance program with mental health, social, legal, and financial support.
  • Extended parental leave.
  • Day off on birthday, Mother’s Day, and Father’s Day.
  • Benefits club with discounts on everyday services.
  • Discounts at educational institutions.
  • Reading kit for children via PlayKids.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Cybersecurity, Incident Response & Hands-On Training Contract IT Instructor (Onsite and virtual live classes) (copy)

Pluralsight 1K-5K Internet Software & Services

Pluralsight is seeking independent contract cybersecurity instructors and scenario developers worldwide to deliver remote and onsite incident-response training, tabletop exercises, and Capture the Flag events for enterprise clients.

Bash Burp Suite Cybersecurity Docker Metasploit Penetration Testing Python Splunk Wireshark
10 hours, 44 minutes ago

Professional Services Consultant, GRC

Mitratech 1K-5K Professional Services

Mitratech is seeking a Services Consultant in Mexico to support client implementations of its GRC suite through requirements analysis, configuration, testing, training, and go-live support.

SQL
2 days, 9 hours ago

Staff Offensive Security Engineer

Greenlight 251-1K Capital Markets

Greenlight is hiring a Staff Offensive Security Engineer to lead continuous offensive security validation across its fintech platforms, cloud infrastructure, corporate environments, mobile applications, and emerging hardware products.

Android AWS Bash CI/CD Go iOS Kubernetes Node.js Penetration Testing Python
5 days, 9 hours ago

Principal Technical Consultant - Network Security

AHEAD 1K-5K IT Services

AHEAD is seeking a Principal Technical Consultant to lead complex, client-facing network security engagements spanning firewalls, network access control, application delivery, SASE, and Zero Trust, from architecture through implementation and knowledge transfer.

Ansible AWS Azure CI/CD CloudFormation DNS GCP HIPAA JSON Kubernetes Microservices Network Security OpenAPI SIEM Splunk Terraform XML
6 days, 10 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers