Third Party Risk Management Expert

DiDi Global

São Paulo

Hybride

BRL 180 000 - 360 000

Plein temps

Il y a 3 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Obtenez une réponse de cet employeur — un CV et une lettre de motivation adaptés exactement à ce qu’il recherche.

Passez les filtres ATS

Résumé du poste

DiDi Global is seeking an Information Security Expert to join the Fintech Information Risk & Security Tech team in Brazil. You will implement security governance for BPO operations, manage access controls, and oversee vendor risk assessments and incident response.

You will assess overseas partners’ security architectures, manage vulnerability remediation, and support regulatory audits while translating HQ standards for local teams.

Qualifications

  • Bachelor’s degree or higher in Computer Science, Information Security, or related field.
  • Experience in information security, security operations, or security architecture.
  • Knowledge of overseas data privacy regulations (GDPR/CCPA) and PCI-DSS/ISO27001.

Responsabilités

  • Onboard overseas ecosystem partners with security assessments and drive remediation.
  • Manage vulnerability and risk operations for overseas business.
  • Coordinate regulatory reviews and audit responses with authorities and auditors.
  • Localize HQ security standards for overseas lines and translate PCI-DSS requirements into actionable baselines.

Connaissances

Security architecture
Web/API security
Encryption concepts
Cloud platforms (AWS/GCP/Azure)
Regulatory compliance (GDPR/CCPA)
PCI-DSS/ISO27001 knowledge
English proficiency
Cross-cultural communication
Regulatory inquiries handling
Auditing experience

Formation

Bachelor’s degree in CS/InfoSec

Outils

AWS
GCP
Azure

Description du poste

Company Overview

If you see technology as a way to smooth your path in life, our team does too: Your Path, Our Journey.

We believe in technology that connects talented people who embrace diversity to create and share paths we don't even know about (yet!). We work to generate value not only for our users but, above all, for the communities we serve and for society as a whole, making every day better for everyone with mobility and delivery services (99) or digital payments (99Pay).

To make life easier for millions of people every day, since 2018, we have been part of DiDi DiDi Global Inc., the world’s leading mobility technology platform. We are pioneers in creating innovative solutions that start in Brazil and scale up to make a positive impact in more than 12 countries where DiDi operates. This innovation encompasses sustainability, safety, artificial intelligence, financial markets, and much more.

Whether building projects from scratch or improving our solutions, we enjoy challenges that give us butterflies, which is why we work at a fast pace with respect, collaboration, and good humor. Along this journey, we also draw strength from diverse experiences and opinions to grow together, fail quickly, learn, and adjust the course to create solutions that deliver even better results.

#LI-Hybrid

Team Overview

We are seeking a detail-oriented and motivated Information Security Expert to join our Fintech Information Risk & Security Tech team in Brazil. This role focuses on ensuring data security compliance and risk remedation within our BPO (Business Process Outsourcing) operations management. You will be responsible for implementing BPO security governance, workplace(site) security check, personnel access control and indentity management and ensuring that our BPO partners adhere to our security standards. And Vendor risk assessement, Vulnerability management, Regulatory analysis and audit response.

Role Responsibilities
  • Ecosystem Onboarding Technical Assessment: Conduct security assessments for overseas ecosystem partners (merchants, channels, service providers, etc.) during the onboarding process. Deeply evaluate their enterprise security architecture, API interface security, data encryption schemes, and compliance qualifications. Output technical assessment conclusions and drive the closure of remediation actions.
  • Vulnerability Management & Risk Operations: Implement and execute the domestic HQ's security operations SOPs. Analyze security risks in overseas business based on vulnerability scans, penetration testing, or daily monitoring results. Guide and drive partners to complete vulnerability remediation and verification to ensure timely risk mitigation.
  • Regulatory Review & Audit Response: Act as the overseas security liaison to cooperate with local regulatory authorities (e.g., central banks, data protection bureaus) and external auditors during inspections and inquiries. Prepare technical evidence regarding system architecture and security policies, and draft compliance reports.
  • Security Standard Localization & Enablement: Assist the Team Lead in promoting and adapting HQ's security control standards and AI-driven automated assessment strategies for overseas business lines. Translate complex compliance requirements (e.g., PCI-DSS) into actionable technical baselines, collect frontline feedback from overseas teams, and contribute to the continuous improvement of security capabilities.
Role Qualifications
  • Education & Experience: Bachelor’s degree or above in Computer Science, Information Security, or related fields.
  • Experience in information security, security architecture, or security operations. Prior experience in overseas finance, cross-border payments, or global internet companies is highly preferred.
  • Technical & Architecture Capabilities: Solid technical foundation in security, with a strong understanding of enterprise security architecture design, common Web/API vulnerability principles, and remediation strategies. Familiarity with data lifecycle encryption and security baseline configurations for mainstream cloud platforms (AWS/GCP/Azure).
  • Compliance & InfoSec Knowledge: Familiarity with major overseas data privacy regulations (e.g., GDPR, CCPA) and financial security standards (e.g., PCI-DSS, ISO27001). Ability to translate compliance requirements into actionable technical metrics.
  • English Proficiency: Fluent in English as a working language. Excellent cross-cultural communication skills, with the ability to independently draft technical compliance reports in English, respond to regulatory inquiries, and handle email communications.[
  • Operations & Resilience: Strong execution and closed-loop thinking skills. Ability to independently drive cross-functional collaboration with limited resources, and handle unexpected security incidents or regulatory inquiries calmly.
  • Bonus Points: Certifications such as CISSP, CCSP, CISP-PTE, or CISA are highly preferred. Prior experience in Information Security/Compliance Auditing (technical focus) at Big 4 firms or renowned consulting companies is a plus.
EEO Statement
  • We create customer value – We strive to always create valuable experiences for our users in everything we do. Our focus is to always innovate new experiences that are safe, pleasant, and efficient.
  • We are data-driven – We are strong believers in making informed decisions, that’s why we are data-driven. We can better navigate the business landscape strategically by analyzing valuable metrics.
  • We believe in Win-win Collaboration – Success is a team sport. When we work to help our partners and colleagues win, we win, too. While keeping everyone's best interest at heart, we communicate with candor and execute with excellence in all we do.
  • We believe in integrity – Integrity is at the very core of our business. We are people who always want to do the right thing. Our intentions are sincere, we speak our minds and listen to each other.
  • We always strive to do better. That means venturing beyond our comfort zones, learning from our mistakes, and helping each other grow.
  • We believe in Diversity and Inclusion – Diversity is one of our biggest strengths. Our differences are what makes us distinct. We respect each other and believe in equal opportunities for all.
Diversity & Inclusion

Diversity is not a future vision or a wish for something we want someday; it is a non‑negotiable value of who we are today.

We embrace inclusion, plurality, and respect, and to achieve this, we rely on the governance of the Diversity Committee, which works alongside HR, our leadership, and identity groups—99Adapta, 99Afro, 99Colors, 99Womem, and 99Familys.

This is our ongoing journey, with much more still to come.

We reinforce that this position is open to everyone, including pregnant people and people with disabilities (PwD).

I acknowledge that prior to submitting this application, I have read and accepted the Privacy Notice for Candidates which is available on https://careers.didiglobal.com/terms

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Vendor Risk Manager
Vendor Risk Manager

Didi • São Paulo

Sur place
BRL 180 000 - 320 000
Vendor Risk Manager
Vendor Risk Manager

DiDi Chuxing • São Paulo

Hybride
BRL 180 000 - 260 000
Vendor Risk Manager
Vendor Risk Manager

99 • São Paulo

Sur place
BRL 120 000 - 160 000
Safety Onboarding Operation Manager
Safety Onboarding Operation Manager

99 • São Paulo

Sur place
BRL 180 000 - 240 000
Service Governance Sr. Analyst - Vaga afirmativa para diversidade de gênero e racial
Service Governance Sr. Analyst - Vaga afirmativa para diversidade de gênero e racial

Didi • São Paulo

Sur place
BRL 120 000 - 180 000
Payment Vendor Relastionship Manager
Payment Vendor Relastionship Manager

DiDi Global • São Paulo

Hybride
BRL 180 000 - 240 000
Payment Vendor Relastionship Manager
Payment Vendor Relastionship Manager

Didi • São Paulo

Sur place
BRL 180 000 - 240 000
Sales Ops Analyst
Sales Ops Analyst

Didi • São Paulo

Hybride
BRL 120 000 - 180 000
Business Solution Analyst Sr.
Business Solution Analyst Sr.

Didi-Global- • São Paulo

Sur place
BRL 201 000 - 268 000
Sales Ops Analyst
Sales Ops Analyst

DiDi Global • São Paulo

Sur place
BRL 90 000 - 130 000