Senior GRC Analyst (Security Assurance)

Tractian Technologies Inc

São Paulo

Presencial

BRL 130 000 - 190 000

Tempo integral

14 dias+
Gerador de candidaturas

Transforma esta função numa entrevista — um currículo e uma carta de apresentação criados à volta do que este empregador procura.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Competitive salary
Stock options
29 days annual leave

Resumo da oferta

TRACTIAN is seeking a GRC Analyst to help develop and implement governance, risk, and compliance across its technology platforms in São Paulo. You will work with cross-functional teams to assess risks, implement controls, and drive continuous improvement of the GRC program.

The role involves supporting ISMS maintenance, conducting control reviews, and coordinating audit readiness while promoting Privacy by Design principles and third-party risk management.

Qualificações

  • Advanced Portuguese and English proficiency.
  • Experience with information security governance and compliance.

Responsabilidades

  • Support ISMS maintenance aligned with ISO 27001/27002, SOC 2, and NIST.
  • Conduct compliance assessments and gap analyses with remediation tracking.
  • Maintain security policies and governance artifacts across the organization.
  • Coordinate evidence collection for internal and external audits.
  • Support Third-Party Risk Management and vendor assessments.

Conhecimentos

Portuguese
English
GRC
ISMS

Ferramentas

Vanta
Drata

Descrição da oferta de emprego

GRC at TRACTIAN

The Engineering team at Tractian is at the forefront of developing cutting-edge infrastructure, technologies, and products to harness the power of IoT data. Our team of talented Engineers collaborates to build robust systems, innovative solutions, and scalable platforms that drive Tractian's success. We are instrumental in shaping the company's decision-making process, optimizing operational efficiency, and delivering exceptional experiences to our consumers.


What you'll do

As a GRC Analyst, you will be responsible for developing and implementing robust governance, risk management, and compliance (GRC) practices within our technology-driven organization. You will play a key role in establishing frameworks and processes that ensure the security, integrity, and regulatory compliance of our technology systems. You will collaborate with cross-functional teams to assess risks, implement controls, and drive continuous improvement of our GRC program.


Key Responsibilities


  • Support the continuous maintenance and improvement of the organization's Information Security Management System (ISMS), ensuring alignment with ISO 27001/27002, SOC 2, and applicable NIST frameworks.

  • Perform compliance assessments, control reviews, and gap analyses, driving remediation plans and tracking corrective actions through completion.

  • Develop, review, and maintain information security policies, standards, procedures, and governance documentation, while monitoring the effectiveness and adoption of security controls across the organization.

  • Support internal and external audits by coordinating evidence collection, maintaining audit documentation, responding to auditor requests, and ensuring continuous audit readiness.

  • Support the implementation and continuous improvement of secure development practices by reviewing processes, advising Engineering and Product teams, and promoting Privacy by Design and Privacy by Default principles.

  • Support Third-Party Risk Management (TPRM) activities, including vendor security assessments, risk reviews, remediation tracking, and continuous improvement of third-party governance processes, aligned with the organization's Risk Management Program.

  • Maintain controls, evidence, remediation plans, and compliance records within the organization's GRC platform, ensuring information remains accurate, current, and audit-ready.

  • Support customer security and compliance due diligence activities, including security questionnaires (SIG, CAIQ, RFPs, etc.), in collaboration with the GRC team and subject matter experts.

  • Partner closely with Engineering, Infrastructure, Product, Security, and business teams to integrate governance, risk, and compliance practices into business and technology initiatives.

  • Collaborate with cross-functional teams on a variety of Security GRC initiatives, contributing to governance, risk, compliance, and assurance programs in support of shared organizational goals.


Requirements


  • Background in Information Technology, Information Security, Governance, Risk & Compliance (GRC), Internal Audit, Compliance, or Quality Management.

  • Experience supporting Information Security Management Systems (ISMS) and assessing compliance with security frameworks and standards, including ISO/IEC 27001, ISO/IEC 27002, SOC 2, and NIST.

  • Knowledge of data protection best practices and compliance requirements under the LGPD and GDPR.

  • Experience performing compliance assessments, internal audits, control reviews, gap analyses, and remediation tracking.

  • Experience developing and maintaining information security policies, standards, procedures, and governance documentation.

  • Experience with Third-Party Risk Management (TPRM), including vendor security assessments and remediation follow-up.

  • Hands-on experience implementing, monitoring, and validating security and compliance controls.

  • Experience working cross-functionally with Engineering, IT, Security, Procurement, Legal, and business teams.

  • Advanced Portuguese proficiency.

  • Advanced English proficiency.


Nice to Have


  • Experience with compliance automation and GRC platforms (e.g., Vanta, Drata, etc.).

  • Experience working with multiple security frameworks and regulatory environments.

  • Experience using task and project management platforms (e.g., Jira, Linear, Monday, etc.) to manage remediation plans and compliance initiatives.

  • Market-recognized security certifications.

  • Experience leveraging automation and Artificial Intelligence (AI) to improve GRC processes, evidence collection, reporting, and compliance operations.


Soft Skills


  • Ability to collaborate effectively across technical and business teams.

  • Excellent communication skills.

  • Proactive, analytical, and solution-oriented.

  • Highly organized, with strong attention to documentation and audit evidence.

  • Team-oriented mindset (one person’s problem is everyone’s problem).

  • Comfortable working in dynamic environments and navigating ambiguity.

  • Ability to independently drive assigned initiatives and deliver high-quality results.

  • Continuous improvement mindset focused on strengthening organizational resilience.


Compensation & Benefits


  • Competitive salary and stock options

  • 30 days of paid annual leave

  • Education and courses stipend

  • Earn a trip anywhere in the world every 4 years

  • R$1.035/month for meals allowance

  • Health plan with national coverage and without coparticipation

  • Dental Insurance: we help you with dental treatment for a better quality of life.

  • Wellhub and Sports Incentive: R$300/mo extra if you practice activities

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Senior GRC Analyst (Security Assurance)
Senior GRC Analyst (Security Assurance)

TRACTIAN • São Paulo

Presencial
BRL 120 000 - 240 000
Stock options
30 days paid leave
Education stipend
+4
Senior GRC Analyst (Business Resilience)
Senior GRC Analyst (Business Resilience)

Tractian Technologies Inc • São Paulo

Presencial
BRL 120 000 - 180 000
Competitive salary
Stock options
30 days paid annual leave
+1
Senior GRC Analyst (Business Resilience)
Senior GRC Analyst (Business Resilience)

TRACTIAN • São Paulo

Presencial
BRL 120 000 - 190 000
Stock options
30 days paid annual leave
Education stipend
+4
Grupo QuintoAndar | Information Security Manager - GRC
Grupo QuintoAndar | Information Security Manager - GRC

QuintoAndar • São Paulo

Híbrido
BRL 350 000 - 750 000
Competitive salary
Profit sharing
Health insurance
+5
Software Engineer - Data & Analytics
Software Engineer - Data & Analytics

Tractian Technologies Inc • São Paulo

Híbrido
BRL 156 000 - 257 000
30 days of paid annual leave
Education and courses stipend
Health plan with national coverage
+1
Senior Backend Engineer
Senior Backend Engineer

Tractian • São Paulo

Presencial
BRL 180 000 - 300 000
30 days paid annual leave
Education stipend
Meals allowance (R$1,035/month)
+3
Software Quality Assurance Engineer
Software Quality Assurance Engineer

Tractian • São Paulo

Presencial
BRL 120 000 - 180 000
Paid annual leave
Education stipend
Meal allowance
+2
Analista de Segurança Pleno
Analista de Segurança Pleno

Jobgether • Brasil

Híbrido
BRL 90 000 - 150 000
Flexible hybrid or remote options
Health insurance for employees and dep
Dental insurance for employees and dep
+9
Software Engineer - Data & Analytics
Software Engineer - Data & Analytics

Tractian • São Paulo

Presencial
BRL 150 000 - 210 000
30 days annual leave
Education stipend
Meals allowance
+3
IT Infrastructure Senior Analyst (Network & Security)
IT Infrastructure Senior Analyst (Network & Security)

Tractian Technologies Inc • São Paulo

Presencial
30 days paid annual leave
Education stipend
R$1.035/month for meals
+3