Analista de Segurança da Informação Pleno at Evertec, ensuring compliance with information security standards. Supporting ISO certifications and risk management in financial technology environment.
Responsibilities
Support the maintenance of ISO 27001 and PCI DSS certifications, as well as SOX compliance requirements and Business Continuity;
Contribute to compliance with Resolution 498 and other applicable regulatory standards;
Develop, review and maintain information security policies, standards, procedures and guidelines;
Participate in information security risk assessment activities, including assessments of suppliers, partners, acquisitions and third parties (TPRM);
Support ISMS (PDSI) management, monitoring indicators and metrics (KPIs);
Participate in information security awareness initiatives and training;
Support business continuity management activities, including plans, tests and reviews;
Provide support for internal and external audits, assisting with evidence collection, action plans and the follow-up of nonconformities.
Requirements
Bachelor’s degree;
Solid fundamentals in Information Security and GRC;
Practical knowledge of ISO/IEC 27001 (controls, ISMS, audits);
Basic understanding of PCI DSS (concepts and general requirements);
Experience developing and maintaining security policies, standards and procedures;
Understanding of risk management (identification, analysis, treatment and monitoring);
Knowledge of Third-Party Risk Management (TPRM);
Familiarity with internal and external audits and evidence management;
Basic to intermediate knowledge of business continuity (BCM/DRP);
Ability to monitor and report information security indicators and KPIs.
Benefits
Meal or food allowance;
Flexible Benefit (Flash);
Health insurance;
Partners for psychological, legal, financial and nutritional support (CLUDE, C4LIFE and ASQ);
Psicologia Viva (telepsychology service);
Dental care;
Daycare assistance;
Support for children with special needs;
Fertility treatment assistance;
Extended maternity and paternity leave;
Transportation voucher or Home Office Allowance (for telework contracts);
Gympass (Wellhub) and TotalPass;
Flexible working hours;
Life insurance;
Employee partnerships club;
Partnership with Sesc;
Just dress — no dress code;
Day off on your birthday;
Beca (education incentive program);
PPR or bonus — based on achievement of goals and results.
Job title
Mid-level Information Security Analyst – GRC, White Team
Managing Environmental Permitting Lead at Anchor QEA leading waterfront development projects. Responsible for permitting strategies and regulatory approvals in the San Francisco Bay Area and beyond.
Associate for managing relationships with clients requiring FATCA/CRS compliance. Conducting documentation review and maintaining client portfolios while supporting team processes.
Regulatory Affairs Manager handling drug approval processes and regulatory affairs. Working with authorities and ensuring compliance for a leading international pharmaceutical firm in Munich.
Referent in Organisationsentwicklung and Governance supporting compliance and development at Diakonie Mark - Ruhr. Involved in building internal controls and quality frameworks in a social organization.
Lead compliance and AML efforts at Onafriq, a fintech company, overseeing FCA regulations. Act as MLRO ensuring robust compliance culture while supporting UK business growth.
Vendor Compliance Analyst coordinating Oracle solutions and troubleshooting customer scorecards at Helen of Troy. Collaborating with internal teams to ensure compliance and address issues efficiently.
Product Development & Regulatory Specialist in an innovative nutricosmetic company. Supporting product innovation and regulatory compliance for collagen - based supplements in global markets.
Director of Compliance leading compliance initiatives across the US Commercial organization at Organon. Implementing tools and processes to drive compliance and risk management initiatives.
GRC Analyst responsible for assessing vendor security risk and compliance for SysLogic. Strengthening third - party risk management program aligned with regulatory and industry standards.