Senior GRC Analyst (Business Resilience)

TRACTIAN

São Paulo

Presencial

BRL 120 000 - 190 000

Tempo integral

14 dias+
Gerador de candidaturas

Destaca-te para esta função — cria um currículo personalizado e uma carta de apresentação em cerca de um minuto.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Stock options
30 days paid annual leave
Education stipend
Meal allowance
Health plan with national coverage
Dental insurance
Wellhub and Sports Incentive

Resumo da oferta

TRACTIAN is seeking a GRC Analyst to develop and implement governance, risk management, and compliance programs across its technology platforms. You will collaborate with Engineering, Security, and product teams to assess risks, implement controls, and drive continuous improvement of the GRC program.

You will support ISO 27001, ISO 27002, and ISO 22301 initiatives, respond to security questionnaires, and guide business teams on governance and risk matters in a dynamic, fast-paced environment in

Qualificações

  • Background in Information Technology, Information Security, Governance, Risk & Compliance (GRC), Internal Audit, Compliance, or Quality Management.

Responsabilidades

  • Lead and continuously improve the organization's GRC practices, ensuring governance, risk, and compliance across technology systems.

Conhecimentos

Advanced Portuguese
Advanced English
GRC expertise
Communication

Ferramentas

Vanta
Drata

Descrição da oferta de emprego

GRC at TRACTIAN

The Engineering team at Tractian is at the forefront of developing cutting-edge infrastructure, technologies, and products to harness the power of IoT data. Our team of talented Engineers collaborates to build robust systems, innovative solutions, and scalable platforms that drive Tractian's success. We are instrumental in shaping the company's decision‑making process, optimizing operational efficiency, and delivering exceptional experiences to our consumers.

What You'll Do

As a GRC Analyst, you will be responsible for developing and implementing robust governance, risk management, and compliance (GRC) practices within our technology-driven organization. You will play a key role in establishing frameworks and processes that ensure the security, integrity, and regulatory compliance of our technology systems. You will collaborate with cross‑functional teams to assess risks, implement controls, and drive continuous improvement of our GRC program.

Key Responsibilities
  • Lead and continuously improve the organization's operational resilience, business continuity, and risk management activities – including identifying, assessing, documenting, monitoring, and reviewing operational, technology, cybersecurity risks.
  • Perform Business Impact Analysis (BIA), define recovery objectives (RTO/RPO), develop disruption scenarios, and establish contingency, recovery, and business continuity strategies for critical business services.
  • Develop, implement, maintain, and continuously improve the organization's Business Continuity (BCM), Disaster Recovery (DR), and Incident Response (IR) activities, including policies, standards, procedures, recovery plans, and playbooks, aligned with corporate objectives, regulatory requirements, and industry best practices.
  • Plan, facilitate, execute, and document tabletop exercises, recovery tests, backup and recovery validation, failover exercises, and other resilience testing activities, ensuring lessons learned and corrective actions are tracked.
  • Maintain the enterprise risk register, controls, mitigation plans, and audit evidence within the organization's GRC/compliance platform, partnering with control owners to drive remediation activities through completion.
  • Collaborate with Engineering, Development, Infrastructure, Security, and business stakeholders to design, implement, and continuously improve risk, resilience, recovery, and incident management processes.
  • Support and continuously improve compliance with ISO 27001, ISO 27002, ISO 22301, and ISO 22313 through assessments, internal controls, audits, and remediation activities.
  • Support customer security and compliance due diligence activities, including responding to security questionnaires (e.g., SIG, CAIQ, RFPs) in collaboration with the GRC team and subject matter experts.
  • Provide guidance to business and technology teams on governance, risk, operational resilience, and compliance matters.
  • Partner closely with Engineering, Infrastructure, Product, Security, and business teams to integrate governance, risk, and compliance practices into business and technology initiatives.
  • Collaborate with cross-functional teams on a variety of Security GRC initiatives, contributing to governance, risk, compliance, and assurance programs in support of shared organizational goals.
Requirements
  • Background in Information Technology, Information Security, Governance, Risk & Compliance (GRC), Internal Audit, Compliance, or Quality Management.
  • Experience implementing and operating Business Continuity Management (BCM) and Disaster Recovery (DR) programs based on ISO 22301 and ISO 22313.
  • Experience conducting Business Impact Analysis (BIA), defining RTO/RPO, recovery strategies, contingency planning, and business disruption scenarios.
  • Experience planning and facilitating tabletop exercises and technical recovery tests for Business Continuity, Disaster Recovery, and Incident Response.
  • Experience developing and maintaining policies, standards, procedures, and playbooks related to Business Continuity, Disaster Recovery, and Incident Response.
  • Experience with ISO 27001 / ISO 27002 compliance.
  • Knowledge of data protection best practices and compliance requirements under the LGPD and GDPR.
  • Hands‑on experience implementing controls and managing remediation plans.
  • Knowledge of risk management frameworks (e.g., ISO 27005, NIST).
  • Experience collaborating with Engineering and Development teams on resilience and compliance initiatives.
  • Advanced Portuguese proficiency.
  • Advanced English proficiency.
Nice to Have
  • Experience with compliance automation and GRC platforms (e.g., Vanta, Drata, etc.).
  • Experience with Business Continuity Management (BCM) tools.
  • Experience working with multiple security frameworks and regulatory environments.
  • Experience using task and project management platforms (e.g., Jira, Linear, Monday, etc.) to manage remediation plans and compliance initiatives.
  • Market-recognized security certifications.
  • Experience leveraging automation and Artificial Intelligence (AI) to improve GRC processes, evidence collection, reporting, and compliance operations.
Soft Skills
  • Ability to collaborate effectively across technical and business teams.
  • Excellent communication skills.
  • Proactive, analytical, and solution-oriented.
  • Highly organized, with strong attention to documentation and audit evidence.
  • Team-oriented mindset (one person’s problem is everyone’s problem).
  • Comfortable working in dynamic environments and navigating ambiguity.
  • Ability to independently drive assigned initiatives and deliver high-quality results.
  • Continuous improvement mindset focused on strengthening organizational resilience.
Compensation & Benefits
  • Competitive salary and stock options
  • 30 days of paid annual leave
  • Education and courses stipend
  • Earn a trip anywhere in the world every 4 years
  • R$1.035/month for meals allowance
  • Health plan with national coverage and without coparticipation
  • Dental Insurance: we help you with dental treatment for a better quality of life.
  • Wellhub and Sports Incentive: R$300/mo extra if you practice activities
Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

Senior GRC Analyst (Business Resilience)
Senior GRC Analyst (Business Resilience)

Tractian Technologies Inc • São Paulo

Presencial
BRL 120 000 - 180 000
Competitive salary
Stock options
30 days paid annual leave
+1
Senior GRC Analyst (Security Assurance)
Senior GRC Analyst (Security Assurance)

TRACTIAN • São Paulo

Presencial
BRL 120 000 - 240 000
Stock options
30 days paid leave
Education stipend
+4
Senior GRC Analyst (Security Assurance)
Senior GRC Analyst (Security Assurance)

Tractian Technologies Inc • São Paulo

Presencial
BRL 130 000 - 190 000
Competitive salary
Stock options
29 days annual leave
Software Engineer - Data & Analytics
Software Engineer - Data & Analytics

Tractian Technologies Inc • São Paulo

Híbrido
BRL 156 000 - 257 000
30 days of paid annual leave
Education and courses stipend
Health plan with national coverage
+1
ANALISTA GRC
ANALISTA GRC

Grupo Ferroeste • Belo Horizonte

Presencial
BRL 78 000 - 123 000
Seguro de Vida
Plano de Saúde
Café da manhã
+9
Software Quality Assurance Engineer
Software Quality Assurance Engineer

Tractian • São Paulo

Presencial
BRL 120 000 - 180 000
Paid annual leave
Education stipend
Meal allowance
+2
Senior Backend Software Engineer
Senior Backend Software Engineer

TRACTIAN ?? • São Paulo

Presencial
BRL 180 000 - 280 000
Competitive salary and stock options
Fully funded English / Spanish courses
30 days of paid annual leave
+7
ANALISTA DE SEGURANÇA GRC PL (001852) Rio de Janeiro - RJ and Hybrid Full-time employee
ANALISTA DE SEGURANÇA GRC PL (001852) Rio de Janeiro - RJ and Hybrid Full-time employee

Stefanini • Rio de Janeiro

Presencial
BRL 120 000 - 180 000
Vale-refeição
Descontos em cursos
Academia Stefanini
+6
10233 - Specialist - Especialista de GRC - Híbrida
10233 - Specialist - Especialista de GRC - Híbrida

Provider IT • Rio de Janeiro

Híbrido
BRL 90 000 - 130 000
Ambiente inclusivo
Provider IT Academy
Programa de Mentoria
Growth Recruiter
Growth Recruiter

Tractian • São Paulo

Presencial
BRL 67 000 - 134 000
30 days paid leave
Education stipend
Global travel opportunity
+4