IT Security & Compliance Lead

New
B
B LabIT security
This job ad is for São Paulo, Brazil. While this is a remote-first opportunity, the candidate filling this role must be a resident of Brazil at the start of employment.Full-TimeLead
Salary212,960 - 261,030 BRL per year
Apply NowOpens the employer's application page

Job Details

Experience
3+ years of experience in information security, IT governance, risk and compliance (GRC), or a closely related field

Requirements

  • Have 3+ years of experience in information security, IT governance, risk and compliance (GRC), or a closely related field.
  • Have a strong understanding of networking concepts and cybersecurity best practices.
  • Have a strong understanding of at least one recognized cybersecurity framework.
  • Have experience conducting security audits, risk assessments, and vendor security reviews.
  • Have working knowledge of data protection regulations relevant to a global organization, such as GDPR or LGPD.
  • Have experience developing or maintaining incident response and business continuity plans.
  • Have hands-on familiarity with cloud and SaaS security, especially Google Workspace administration and identity and access management.
  • Be able to explain security risk in plain language to non-technical colleagues and write clear policies.

Responsibilities

  • Conduct security audits and risk assessments of network systems, applications, and processes, and maintain a prioritized risk register.
  • Establish and maintain a network-wide security baseline aligned with a recognized framework, and report security posture and maturity metrics.
  • Review vendors and technology platforms for security risks, and coordinate penetration testing and vulnerability scanning.
  • Define and monitor access control standards, including MFA, SSO, least privilege, and joiner/mover/leaver processes.
  • Partner with Regional IT Administrators on endpoint and device security standards and advise engineering on secure-by-design practices.
  • Own and maintain information security policies, standards, and procedures, and communicate policy changes across regions.
  • Manage the KnowBe4 security awareness program, including training, phishing simulations, and completion reporting.
  • Maintain the incident response plan and coordinate security incidents with Legal, Communications, and affected regions.
  • Support data protection compliance, business continuity and disaster recovery planning, and audit and regulatory documentation.
View Full Description & ApplyYou'll be redirected to the employer's site
212,960 - 261,030 BRL per year
Apply Now