IT Security & Compliance Lead
New
B
B LabInformation security
This job ad is for São Paulo, Brazil. While this is a remote-first opportunity, the candidate filling this role must be a resident of Brazil at the start of employment.Full-TimeLead
Salary212,960 - 261,030 BRL per year
Apply NowOpens the employer's application page
Job Details
- Experience
- 3+ years of experience in information security, IT governance, risk and compliance (GRC), or a closely related field
- Required Skills
- Networking
Requirements
- Have 3+ years of experience in information security, IT governance, risk and compliance (GRC), or a closely related field.
- Have a strong understanding of networking concepts and cybersecurity.
- Understand at least one recognized cybersecurity framework.
- Have experience conducting security audits, risk assessments, and vendor security reviews.
- Have working knowledge of data protection regulations relevant to a global organization, such as GDPR or LGPD.
- Have experience developing or maintaining incident response and business continuity plans.
- Have hands-on familiarity with cloud and SaaS security, especially Google Workspace administration and identity and access management.
- Be able to explain security risk to non-technical colleagues and write clear policies.
- Be a resident of Brazil at the start of employment and hold Brazilian work authorization without time limitations or other restrictions.
- Be within commuting distance of São Paulo.
Responsibilities
- Conduct security audits and risk assessments of network systems, applications, and processes, and maintain a prioritized risk register.
- Establish and maintain a network-wide security baseline aligned to a recognized framework, and report security posture and maturity to Technology leadership.
- Review vendors and technology platforms for third-party risk, and coordinate penetration testing and vulnerability scanning.
- Define and monitor access control standards across core platforms, including Google Workspace and Salesforce.
- Partner with Regional IT Administrators on endpoint and device security standards and advise Product & Platform Engineering on secure-by-design practices.
- Maintain the information security policy set and supporting standards and procedures, and communicate policy changes to staff.
- Own the KnowBe4 security awareness program, including training, phishing simulations, and completion reporting.
- Maintain the incident response plan and coordinate security incidents with Legal, Communications, and affected regions.
- Support business continuity and disaster recovery planning, including backup and recovery testing.
- Support data protection compliance and maintain evidence for audits, due diligence, and regulatory inquiries.
View Full Description & ApplyYou'll be redirected to the employer's site