Vendor Risk Manager

DiDi Chuxing

São Paulo

Híbrido

BRL 180 000 - 260 000

Tempo integral

Há 2 dias
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Transforma esta função numa entrevista — um currículo e uma carta de apresentação criados à volta do que este empregador procura.

Ultrapassa os filtros ATS

Resumo da oferta

DiDi Chuxing in Brazil seeks a detail-oriented Information Security Expert to join our Fintech Information Risk & Security Tech team. You will implement BPO security governance, workplace security checks, and identity management for overseas operations.

You will assess ecosystem partners, handle regulatory inquiries, and translate PCI-DSS requirements into technical baselines, contributing to ongoing security capability improvements.

Qualificações

  • Bachelor's degree or higher in Computer Science, Information Security, or related field.
  • Experience in information security, security architecture, or security operations.
  • Knowledge of data lifecycle encryption and cloud platform baseline configurations (AWS/GCP/Azure).
  • Familiarity with GDPR/CCPA and PCI-DSS/ISO27001 compliance.

Responsabilidades

  • Conduct security assessments for overseas ecosystem partners during onboarding, evaluating architecture, API security, and data encryption.
  • Manage vulnerability and risk operations, analyze security risks, and drive remediation with partners.
  • Serve as overseas security liaison with regulators and auditors, preparing technical evidence and compliance reports.
  • Assist in localizing HQ security controls to overseas business lines and translate PCI-DSS requirements into actionable baselines.

Conhecimentos

Security architecture
Security operations
Web/API security
English proficiency

Formação académica

Bachelor's degree in Computer Science or related

Ferramentas

AWS
GCP
Azure

Descrição da oferta de emprego

If you see technology as a way to smooth your path in life, our team does too: Your Path, Our Journey.

We believe in technology that connects talented people who embrace diversity to create and share paths we don't even know about (yet!). We work to generate value not only for our users but, above all, for the communities we serve and for society as a whole, making every day better for everyone with mobility and delivery services (99) or digital payments (99Pay).

To make life easier for millions of people every day, since 2018, we have been part of DiDi DiDi Global Inc., the world’s leading mobility technology platform. We are pioneers in creating innovative solutions that start in Brazil and scale up to make a positive impact in more than 12 countries where DiDi operates. This innovation encompasses sustainability, safety, artificial intelligence, financial markets, and much more.

Whether building projects from scratch or improving our solutions, we enjoy challenges that give us butterflies, which is why we work at a fast pace with respect, collaboration, and good humor. Along this journey, we also draw strength from diverse experiences and opinions to grow together, fail quickly, learn, and adjust the course to create solutions that deliver even better results.

If you see technology as a way to smooth your path in life, our team does too: Your Path, Our Journey.

We believe in technology that connects talented people who embrace diversity to create and share paths we don't even know about (yet!). We work to generate value not only for our users but, above all, for the communities we serve and for society as a whole, making every day better for everyone with mobility and delivery services (99) or digital payments (99Pay).

To make life easier for millions of people every day, since 2018, we have been part of DiDi DiDi Global Inc., the world’s leading mobility technology platform. We are pioneers in creating innovative solutions that start in Brazil and scale up to make a positive impact in more than 12 countries where DiDi operates. This innovation encompasses sustainability, safety, artificial intelligence, financial markets, and much more.

Whether building projects from scratch or improving our solutions, we enjoy challenges that give us butterflies, which is why we work at a fast pace with respect, collaboration, and good humor. Along this journey, we also draw strength from diverse experiences and opinions to grow together, fail quickly, learn, and adjust the course to create solutions that deliver even better results.

Hybrid

About the team/role

We are seeking a detail-oriented and motivated Information Security Expert to join our Fintech Information Risk & Security Tech team in Brazil. This role focuses on ensuring data security compliance and risk remedation within our BPO (Business Process Outsourcing) operations management. You will be responsible for implementing BPO security governance, workplace(site) security check, personnel access control and indentity management and ensuring that our BPO partners adhere to our security standards. And Vendor risk assessement, Vulnerability management, Regulatory analysis and audit response.

In this role, you'll be...
  • Ecosystem Onboarding Technical Assessment: Conduct security assessments for overseas ecosystem partners (merchants, channels, service providers, etc.) during the onboarding process. Deeply evaluate their enterprise security architecture, API interface security, data encryption schemes, and compliance qualifications. Output technical assessment conclusions and drive the closure of remediation actions.
  • Vulnerability Management & Risk Operations: Implement and execute the domestic HQ's security operations SOPs. Analyze security risks in overseas business based on vulnerability scans, penetration testing, or daily monitoring results. Guide and drive partners to complete vulnerability remediation and verification to ensure timely risk mitigation.
  • Regulatory Review & Audit Response: Act as the overseas security liaison to cooperate with local regulatory authorities (e.g., central banks, data protection bureaus) and external auditors during inspections and inquiries. Prepare technical evidence regarding system architecture and security policies, and draft compliance reports.
  • Security Standard Localization & Enablement: Assist the Team Lead in promoting and adapting HQ's security control standards and AI-driven automated assessment strategies for overseas business lines. Translate complex compliance requirements (e.g., PCI-DSS) into actionable technical baselines, collect frontline feedback from overseas teams, and contribute to the continuous improvement of security capabilities.
We're eager to be in touch because you have...
  • Education & Experience: Bachelor’s degree or above in Computer Science, Information Security, or related fields.
  • Experience in information security, security architecture, or security operations. Prior experience in overseas finance, cross-border payments, or global internet companies is highly preferred.
  • Technical & Architecture Capabilities: Solid technical foundation in security, with a strong understanding of enterprise security architecture design, common Web/API vulnerability principles, and remediation strategies. Familiarity with data lifecycle encryption and security baseline configurations for mainstream cloud platforms (AWS/GCP/Azure).
  • Compliance & InfoSec Knowledge: Familiarity with major overseas data privacy regulations (e.g., GDPR, CCPA) and financial security standards (e.g., PCI-DSS, ISO27001). Ability to translate compliance requirements into actionable technical metrics.
  • English Proficiency: Fluent in English as a working language. Excellent cross-cultural communication skills, with the ability to independently draft technical compliance reports in English, respond to regulatory inquiries, and handle email communications.[
  • Operations & Resilience: Strong execution and closed-loop thinking skills. Ability to independently drive cross-functional collaboration with limited resources, and handle unexpected security incidents or regulatory inquiries calmly.
  • Bonus Points: Certifications such as CISSP, CCSP, CISP-PTE, or CISA are highly preferred. Prior experience in Information Security/Compliance Auditing (technical focus) at Big 4 firms or renowned consulting companies is a plus.
You’ll love working at DiDi because...
  • We create user value
  • We strive to always create valuable experiences for our users in everything we do. Our focus is to always innovate new experiences that are safe, pleasant and efficient.
  • We are data-driven. We are strong believers in making informed decisions, that’s why we are data-driven. We can better navigate the business landscape strategically by analyzing valuable metrics.
  • Win-win Collaboration. Success is a team sport. When we work to help our partners and colleagues win, we win, too. While keeping everyone's best interest at heart, we communicate with candor and execute with excellence in all we do.
  • We believe in integrity. Integrity is at the very core of our business. We are people who always want to do the right thing. Our intentions are sincere, we speak our minds and listen to each other.
  • Growth. We always strive to do better. That means venturing beyond our comfort zones, learning from our mistakes, and helping each other grow.
  • Diversity and Inclusion. Diversity is one of our biggest strengths. Our differences are what make us distinct. We respect each other and believe in equal opportunities for all.
Diversity & Inclusion
  • Diversity is not a vision of the future or something we wish to have one day, it is a non-negotiable value of who we are.
  • We practice inclusion, plurality, and respect. And we count on the governance of the Diversity Committee, which works together with HR, leadership and identity groups - 99Adapta, 99Afro, 99Cores, 99Mulheres, and 99Mamães. This part of our journey has been written, there remains a long road before us.
  • We reinforce that this position is open to everyone, including pregnant people and people with disabilities (PwD).
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Vendor Risk Manager
Vendor Risk Manager

DiDi Global • São Paulo

Presencial
BRL 180 000 - 260 000
Safety Onboarding Operation Manager
Safety Onboarding Operation Manager

99 • São Paulo

Presencial
BRL 180 000 - 240 000
User Operations Intern
User Operations Intern

DiDi Chuxing • São Paulo

Híbrido
BRL 17 000 - 23 000
Strategy & Planning Senior Analyst
Strategy & Planning Senior Analyst

DiDi Chuxing • São Paulo

Híbrido
BRL 180 000 - 280 000
User Operations Intern
User Operations Intern

99 • São Paulo

Presencial
BRL 120 000 - 170 000
Service Governance Sr. Analyst - Vaga afirmativa para diversidade de gênero e racial
Service Governance Sr. Analyst - Vaga afirmativa para diversidade de gênero e racial

99 • São Paulo

Híbrido
BRL 120 000 - 180 000
Hybrid working model
Safety Onboarding Operation Manager
Safety Onboarding Operation Manager

Didi • São Paulo

Híbrido
BRL 180 000 - 240 000
User Operations Intern
User Operations Intern

Didi-Global- • São Paulo

Presencial
BRL 100 000 - 201 000
Safety Business Intelligence SR Analyst
Safety Business Intelligence SR Analyst

DiDi Chuxing • São Paulo

Híbrido
BRL 120 000 - 180 000
Hybrid work model
Safety Onboarding Operation Manager
Safety Onboarding Operation Manager

Didi-Global- • São Paulo

Presencial
BRL 180 000 - 280 000