Grupo QuintoAndar | Information Security Manager - GRC

3 weeks, 1 day ago
Full-time
Lead
Cybersecurity
QuintoAndar

QuintoAndar

QuintoAndar: Simplifying home search with online rental and purchase services, secure payments, and free rental insurance. Revolutionizing Brazil's real estate market with a talented team and innovative business model.

Real Estate
1K-5K
Founded 2012
$755M raised

Description

  • Develop and lead the GRC strategy and roadmap in alignment with business objectives, budget, and risk appetite.
  • Own the security service channel and security portfolio, prioritizing and coordinating security requests and initiatives.
  • Lead information security governance, including AI governance policies, guidelines, and controls.
  • Lead IAM governance initiatives aligned with risk management and SOX compliance requirements.
  • Manage and develop a high-performing team of GRC specialists and third-party partners.
  • Lead the end-to-end cyber risk management program, including identification, treatment, monitoring, and remediation.
  • Quantify cyber risk financially using methodologies such as FAIR.
  • Lead third-party risk management and cyber resilience programs for vendors and the supply chain.
  • Ensure continuous compliance with regulations and frameworks, and represent the company in audits and regulatory interactions.
  • Define, report, and present KPIs, KRIs, and maturity metrics to executive leadership and security committees.
  • Lead security awareness programs and track behavioral risk reduction.
  • Structure, simplify, review, and maintain information security policies, standards, procedures, and processes.
  • Partner with Technology, Engineering, Product, Legal, Privacy, Finance, Compliance, Internal Audit, and business leaders to reduce risk and improve processes.

Requirements

  • 10+ years of experience in Information Security GRC, including at least 5 years in leadership and team management roles.
  • Experience in complex, dynamic, multinational environments, preferably in tech companies, scale-ups, or the financial sector.
  • Experience managing security demand intake and portfolio prioritization, ideally using ITSM practices.
  • Deep knowledge of frameworks and standards such as NIST CSF 2.0, ISO 27001/27002, CIS Controls, SOX, and ISO 31000.
  • Ability to translate cyber risks into financial and operational impact using methodologies such as FAIR.
  • Experience designing security KPI/KRI frameworks and maturity models for executive reporting.
  • Experience designing vendor risk assessment methodologies and third-party risk management programs.
  • Experience leading IAM governance initiatives and aligning access controls with risk and compliance requirements.
  • Experience supporting SOX compliance programs, including IT General Controls (ITGC).
  • Experience designing and running security awareness and behavior change programs.
  • Ability to use automation and AI to scale GRC processes, such as automated evidence collection and continuous controls monitoring.
  • Fluency in Portuguese and advanced English.
  • CISSP, CISM, CRISC, or ISO 27001 Lead Auditor certification is preferred.

Benefits

  • Competitive salary.
  • Profit sharing.
  • Meal allowance.
  • Health insurance.
  • Dental plan.
  • Life insurance.
  • Childcare subsidy and atypical parenthood subsidy.
  • Wellhub.
  • Home office allowance.
  • Employee assistance program with mental health, social, legal, and financial support.
  • Extended parental leave.
  • Day off on birthday, Mother’s Day, and Father’s Day.
  • Benefits club with discounts on everyday services.
  • Discounts at educational institutions.
  • Reading kit for children via PlayKids.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Officer

European Dynamics 251-1K IT Services

European Dynamics is seeking a remote Security Officer to support a major client’s IT team by leading information security, risk management, governance, and resilience activities.

Agile Cybersecurity DevSecOps
1 day, 9 hours ago

Vendor Security & Standards Manager

Nebius 51-250 Internet Software & Services

Nebius is seeking a Vendor Security & Standards Manager to globally enforce security compliance across its external supply chain partners, including carriers, 3PLs, freight forwarders, guarding companies, and last-mile providers.

5 days, 9 hours ago

Research Security Consultant

Attain Partners 251-1K Media

Attain Partners is seeking a Research Security Officer to manage university research security and export controls compliance programs within a higher-education and research environment.

1 week ago

Global Safety and Security Lead, Workplace and Facilities

Gong 251-1K Internet Software & Services

Gong is hiring a Global Safety and Security Lead to build and run worldwide safety, security, and business continuity programs that keep employees and offices safe, compliant, and resilient as the company scales globally.

1 week, 1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers