Senior GRC Analyst (Security Assurance)

TRACTIAN

São Paulo

Presencial

BRL 120 000 - 240 000

Tempo integral

14 dias+
Gerador de candidaturas

Não envies um currículo genérico — gera um currículo e uma carta de apresentação adaptados a esta função específica.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Stock options
30 days paid leave
Education stipend
Meal allowance
Health plan
Dental Insurance
Wellhub and Sports Incentive

Resumo da oferta

TRACTIAN seeks a GRC Analyst in Brazil to develop and implement governance, risk, and compliance practices for its technology-focused organization. You will work with cross-functional teams to assess risks, implement controls, and drive continuous improvement of the GRC program across ISMS, security policies, and third-party risk management.

You will support audits, evidence collection, and regulatory requirements such as LGPD, with a focus on data protection, privacy by design, and secure

Qualificações

  • Experience in ISMS and compliance with security standards (ISO 27001/27002, SOC 2, NIST).
  • Knowledge of LGPD and GDPR data protection requirements.
  • Experience conducting compliance assessments, audits, and remediation tracking.
  • Experience creating and maintaining security policies and governance docs.
  • Experience with Third-Party Risk Management and vendor security reviews.
  • Hands-on with security controls implementation and validation.
  • Collaborates with Engineering, IT, Security, Procurement, Legal and business teams.
  • Proficient in Portuguese and English.

Responsabilidades

  • Develop and implement robust GRC practices across the organization.
  • Maintain ISMS alignment with ISO 27001/27002, SOC 2, and NIST.
  • Lead compliance assessments, control reviews, and remediation tracking.
  • Support audits with evidence collection and audit readiness.
  • Promote Privacy by Design and Privacy by Default principles.
  • Manage Third-Party Risk Management activities and vendor assessments.
  • Keep GRC evidence and records up to date in the platform.
  • Collaborate with cross-functional teams to integrate GRC into initiatives.
  • Assist customer security due diligence and security questionnaires.

Conhecimentos

GRC
ISMS
ISO 27001
SOC 2
NIST
LGPD
GDPR
Audits
Cross-Functional
Portuguese
English

Formação académica

Information Technology degree

Ferramentas

Vanta
Drata
Jira

Descrição da oferta de emprego

GRC at TRACTIAN

The Engineering team at Tractian is at the forefront of developing cutting-edge infrastructure, technologies, and products to harness the power of IoT data. Our team of talented Engineers collaborates to build robust systems, innovative solutions, and scalable platforms that drive Tractian's success. We are instrumental in shaping the company's decision-making process, optimizing operational efficiency, and delivering exceptional experiences to our consumers.

GRC at TRACTIAN

The Engineering team at Tractian is at the forefront of developing cutting-edge infrastructure, technologies, and products to harness the power of IoT data. Our team of talented Engineers collaborates to build robust systems, innovative solutions, and scalable platforms that drive Tractian's success. We are instrumental in shaping the company's decision-making process, optimizing operational efficiency, and delivering exceptional experiences to our consumers.

What You’ll Do

As a GRC Analyst, you will be responsible for developing and implementing robust governance, risk management, and compliance (GRC) practices within our technology-driven organization. You will play a key role in establishing frameworks and processes that ensure the security, integrity, and regulatory compliance of our technology systems. You will collaborate with cross-functional teams to assess risks, implement controls, and drive continuous improvement of our GRC program.

Key Responsibilities
  • Support the continuous maintenance and improvement of the organization's Information Security Management System (ISMS), ensuring alignment with ISO 27001/27002, SOC 2, and applicable NIST frameworks.
  • Perform compliance assessments, control reviews, and gap analyses, driving remediation plans and tracking corrective actions through completion.
  • Develop, review, and maintain information security policies, standards, procedures, and governance documentation, while monitoring the effectiveness and adoption of security controls across the organization.
  • Support internal and external audits by coordinating evidence collection, maintaining audit documentation, responding to auditor requests, and ensuring continuous audit readiness.
  • Support the implementation and continuous improvement of secure development practices by reviewing processes, advising Engineering and Product teams, and promoting Privacy by Design and Privacy by Default principles.
  • Support Third-Party Risk Management (TPRM) activities, including vendor security assessments, risk reviews, remediation tracking, and continuous improvement of third-party governance processes, aligned with the organization's Risk Management Program.
  • Maintain controls, evidence, remediation plans, and compliance records within the organization's GRC platform, ensuring information remains accurate, current, and audit-ready.
  • Support customer security and compliance due diligence activities, including security questionnaires (SIG, CAIQ, RFPs, etc.), in collaboration with the GRC team and subject matter experts.
  • Partner closely with Engineering, Infrastructure, Product, Security, and business teams to integrate governance, risk, and compliance practices into business and technology initiatives.
  • Collaborate with cross-functional teams on a variety of Security GRC initiatives, contributing to governance, risk, compliance, and assurance programs in support of shared organizational goals.
Requirements
  • Background in Information Technology, Information Security, Governance, Risk & Compliance (GRC), Internal Audit, Compliance, or Quality Management.
  • Experience supporting Information Security Management Systems (ISMS) and assessing compliance with security frameworks and standards, including ISO/IEC 27001, ISO/IEC 27002, SOC 2, and NIST.
  • Knowledge of data protection best practices and compliance requirements under the LGPD and GDPR.
  • Experience performing compliance assessments, internal audits, control reviews, gap analyses, and remediation tracking.
  • Experience developing and maintaining information security policies, standards, procedures, and governance documentation.
  • Experience with Third-Party Risk Management (TPRM), including vendor security assessments and remediation follow-up.
  • Hands-on experience implementing, monitoring, and validating security and compliance controls.
  • Experience working cross-functionally with Engineering, IT, Security, Procurement, Legal, and business teams.
  • Advanced Portuguese proficiency.
  • Advanced English proficiency.
Nice to Have
  • Experience with compliance automation and GRC platforms (e.g., Vanta, Drata, etc.).
  • Experience working with multiple security frameworks and regulatory environments.
  • Experience using task and project management platforms (e.g., Jira, Linear, Monday, etc.) to manage remediation plans and compliance initiatives.
  • Market-recognized security certifications.
  • Experience leveraging automation and Artificial Intelligence (AI) to improve GRC processes, evidence collection, reporting, and compliance operations.
Soft Skills
  • Ability to collaborate effectively across technical and business teams.
  • Excellent communication skills.
  • Proactive, analytical, and solution-oriented.
  • Highly organized, with strong attention to documentation and audit evidence.
  • Team-oriented mindset (one person’s problem is everyone’s problem).
  • Comfortable working in dynamic environments and navigating ambiguity.
  • Ability to independently drive assigned initiatives and deliver high-quality results.
  • Continuous improvement mindset focused on strengthening organizational resilience.
Compensation & Benefits
  • Competitive salary and stock options
  • 30 days of paid annual leave
  • Education and courses stipend
  • Earn a trip anywhere in the world every 4 years
  • R$1.035/month for meals allowance
  • Health plan with national coverage and without coparticipation
  • Dental Insurance: we help you with dental treatment for a better quality of life.
  • Wellhub and Sports Incentive: R$300/mo extra if you practice activities
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Senior GRC Analyst (Security Assurance)
Senior GRC Analyst (Security Assurance)

Tractian Technologies Inc • São Paulo

Presencial
BRL 130 000 - 190 000
Competitive salary
Stock options
29 days annual leave
Senior GRC Analyst (Business Resilience)
Senior GRC Analyst (Business Resilience)

TRACTIAN • São Paulo

Presencial
BRL 120 000 - 190 000
Stock options
30 days paid annual leave
Education stipend
+4
Senior GRC Analyst (Business Resilience)
Senior GRC Analyst (Business Resilience)

Tractian Technologies Inc • São Paulo

Presencial
BRL 120 000 - 180 000
Competitive salary
Stock options
30 days paid annual leave
+1
Grupo QuintoAndar | Information Security Manager - GRC
Grupo QuintoAndar | Information Security Manager - GRC

QuintoAndar • São Paulo

Híbrido
BRL 350 000 - 750 000
Competitive salary
Profit sharing
Health insurance
+5
Software Engineer - Data & Analytics
Software Engineer - Data & Analytics

Tractian Technologies Inc • São Paulo

Híbrido
BRL 156 000 - 257 000
30 days of paid annual leave
Education and courses stipend
Health plan with national coverage
+1
Senior Backend Engineer
Senior Backend Engineer

Tractian • São Paulo

Presencial
BRL 180 000 - 300 000
30 days paid annual leave
Education stipend
Meals allowance (R$1,035/month)
+3
Software Engineer - Data & Analytics
Software Engineer - Data & Analytics

Tractian • São Paulo

Presencial
BRL 150 000 - 210 000
30 days annual leave
Education stipend
Meals allowance
+3
Software Quality Assurance Engineer
Software Quality Assurance Engineer

Tractian • São Paulo

Presencial
BRL 120 000 - 180 000
Paid annual leave
Education stipend
Meal allowance
+2
IT Infrastructure Senior Analyst (Network & Security)
IT Infrastructure Senior Analyst (Network & Security)

Tractian Technologies Inc • São Paulo

Presencial
30 days paid annual leave
Education stipend
R$1.035/month for meals
+3
Senior Backend Software Engineer
Senior Backend Software Engineer

TRACTIAN ?? • São Paulo

Presencial
BRL 180 000 - 280 000
Competitive salary and stock options
Fully funded English / Spanish courses
30 days of paid annual leave
+7