Governance, Risk & Compliance Specialist

Bizagi Group

Bogotá ciudad

Presencial

COP 120.000.000 - 180.000.000

Jornada completa

Hace 9 días
Generador de candidaturas

Una candidatura completa en un minuto: currículum y carta de presentación adaptados, listos para enviar.

Supera los filtros ATS

Descripción de la vacante

Bizagi seeks a Governance, Risk & Compliance Specialist to strengthen security and privacy across LATAM. The role emphasizes data protection, regulatory alignment, and collaboration with Legal, IT, and Cloud teams to safeguard customer and internal environments.

Ideal candidates have 4+ years in GRC for global cloud/AI contexts, ISO 27001/SOC 2 exposure, and strong English communication. Bogotá-based with a focus on data protection and privacy governance.

Formación

  • Bachelor’s degree in information technology, computer science, MIS, or related field.
  • Postgraduate degree or certifications in information security/risk management.
  • Industry certifications such as CISM, CRISC, ISO 27001:2022 auditor.

Responsabilidades

  • Define and update data lifecycle policies with Security & Compliance, Legal, IT, and Cloud teams.
  • Ensure adherence to GDPR, HIPAA, and other regulatory frameworks, including regulatory responses.
  • Monitor privacy and security across customer environments and internal operations.
  • Develop understanding of Azure-based architecture to identify data flows and controls.
  • Support DPIAs for systems/processes with Legal and owners to mitigate privacy risks.
  • Conduct third-party/vendor risk assessments and support security/privacy by design reviews.
  • Act as a point of contact for privacy and security questions and guidance to teams.
  • Develop and deliver compliance and privacy awareness materials and training.
  • Support audits (ISO 27001, SOC 2) and maintain risk dashboards with mitigations.

Conocimientos

AI Fluency
Analytical thinking
Attention to detail
Problem-solving
Stakeholder management
Communication

Educación

Bachelor’s degree in information technology
Postgraduate degree in information security
Security certifications (CISM, CRISC)

Herramientas

Azure Cloud
ISO 27001 compliance
NIST framework

Descripción del empleo

Bizagi is at the forefront of the rapidly growing enterprise automation and AI market. We’re hunting for top talent across regions to find innovative people that are eager to make an impact. Our name stands for Business Agility, and we help organizations adapt to a fast-changing world by embedding AI into operations through business orchestration. AI is everywhere, but without a solid foundation, it can’t deliver ROI. Bizagi bridges that gap—connecting AI to end-to-end processes and measurable outcomes to ensure real results. Companies use Bizagi to automate processes, build low-code apps, and integrate systems. Now, they’re adding our AI Agents, Workers, and Assistant in just weeks. Trusted by leaders like DHL, Unilever, and Old Mutual, Bizagi powers daily operations and transforms how business gets done.

What is it like to work at Bizagi? Founded in LATAM, we’re a global company with strong presence in EMEA and growing in NAM. We’re proud of our diverse culture, world‑class leadership, and incredible team. At Bizagi, you’ll make a real impact, grow professionally, and enjoy the journey. We value innovation, collaboration, and accountability—and we support flexibility and work‑life balance. Diversity, inclusion, and mutual respect are part of who we are. Join us and discover the best work of your career at Bizagi.

What We Are Seeking

We are looking for the best talent in the industry to support Bizagi’s rapid growth across Latam as a Governance Risk Compliance Specialist. The role is responsible for implementing corporate security and compliance initiatives while participating in administrating security solutions/tools in support of business objectives.

Key Tasks & Accountabilities
  • Define and update data lifecycle policies (acquisition, storage, use, retention, deletion) together with Security & Compliance, Legal, IT, and the Cloud Team, ensuring they are correctly applied across customer and internal environments.
  • Ensure adherence to applicable regulatory frameworks — GDPR, CCPA, Ley 1581, HIPAA, EU AI Act (Bizagi's role as Deployer), SARO, and Circulares de ciberseguridad SFC — supporting timely responses to data subject and regulatory requests.
  • Monitor privacy and security compliance across customer‑facing environments and internal operations, identifying and tracking gaps.
  • Build and apply a solid working understanding of a Cloud Azure‑based architecture to identify where sensitive data resides, how it flows, and where privacy and security controls apply — advisory, not hands‑on implementation.
  • Support Data Protection Impact Assessments (DPIAs) for new and existing systems/processes, working with Legal and system/process owners to identify and mitigate privacy risks.
  • Conduct third‑party/vendor risk assessments and support security/privacy by design reviews on new architecture and AI‑powered agent capabilities, in coordination with the Cloud and Product/Engineering teams.
  • Act as a point of contact for privacy and security questions, translating regulatory obligations into practical guidance for technical and business teams.
  • Develop and deliver compliance and privacy awareness materials and training across the organization.
  • Conduct risk assessments (ISO 31000, scenario/root cause analysis) and support internal and external audits (ISO 27001, SOC 2), maintaining risk dashboards and escalating emerging risks with proposed mitigations.
Academic & professional Qualifications
  • Bachelor’s degree in information technology, computer science, management information systems, or a related field.
  • Information Security or Risk management Postgraduate degree and/or information security industry certifications: Cloud certifications such as AZ‑900, SC‑900, AWS practitioner is a plus.
  • Industry certifications as CISM, CRISC, ISO 27001:2022 auditor, and specific security tools certification.
Experience
  • At least 4 years of GRC specific experience working for global cloud and/or AI companies.
  • At least 4 years of experience with security and compliance monitoring frameworks and incident response processes.
  • Exposure to regulatory frameworks (SARO, GDPR, Circulares de SFC, HIPAA, Fedramp).
Technical Skills
  • Information Security and Compliance: ISO 27001 & GDPR.
  • Information Security Frameworks: NIST, FedRAMP, HIPAA. (desirable – nice to have)
  • Azure Cloud security and privacy controls
  • Risk Management ISO 31000, SARO, NIST risk management framework
  • Incident and data breach Response: Handling security events, regulators reporting, and remediation planning.
  • Project Management: Implementing security initiatives and compliance projects.
Skills
  • AI Fluency
  • Analytical thinking
  • attention to detail
  • problem‑solving
  • stakeholder management
  • communication and presentation skills
Language

English level: Advanced English level (At least B2)

Location

Bogota (ideally)

Leader in Intelligent Process Automation

We empower people to drive digital transformation, helping organizations across industries work more efficiently to the benefit of their employees and customers. As a global employer, Bizagi believes our success depends on diversity, inclusion and mutual respect among our team members. We are committed to making all employment decisions based upon business need, individual merit, capability and equality of opportunity. All qualified applicants will receive consideration for employment without regard to age, disability, sex, gender identity, sexual orientation, pregnancy and maternity, race, religion or belief and marriage and civil partnerships. We will ensure that any individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process and to perform essential job functions. Please contact HR@bizagi.com to inform us of any accommodations you may require.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Governance, Risk & Compliance Specialist
Governance, Risk & Compliance Specialist

bizagi • Bogotá ciudad

Presencial
COP 120.000.000 - 180.000.000
Intern / Sena
Intern / Sena

Bizagi Group • Bogotá ciudad

Presencial
COP 8.928.000 - 12.276.000
Digital Transformation engineer - Automatizador Bizagi
Digital Transformation engineer - Automatizador Bizagi

Bizagi Group • Bogotá

A distancia
COP 60.000.000 - 120.000.000
Digital Transformation engineer - Automatizador Bizagi
Digital Transformation engineer - Automatizador Bizagi

Bizagi • Bogotá

Presencial
COP 78.120.000 - 122.760.000
Account Executive - Medellín, Colombia
Account Executive - Medellín, Colombia

Bizagi • Medellín

Presencial
COP 156.121.000 - 234.183.000
GRC Specialist: Privacy, Security & Compliance
GRC Specialist: Privacy, Security & Compliance

bizagi • Bogotá ciudad

Presencial
COP 120.000.000 - 180.000.000
Cloud Administrator
Cloud Administrator

Bizagi • Bogotá

Presencial
COP 78.120.000 - 122.760.000
GRC & Privacy Specialist — Cloud & AI Compliance
GRC & Privacy Specialist — Cloud & AI Compliance

Bizagi Group • Bogotá ciudad

Presencial
COP 120.000.000 - 180.000.000
Senior Data Engineer
Senior Data Engineer

Blend • Bogotá

Presencial
COP 111.600.000 - 189.720.000
AWS Certifications
Udemy access
English lessons
+2
Ingeniero/a de senior de GRC
Ingeniero/a de senior de GRC

GMV • Bogotá

Híbrido
Hybrid working model
8 weeks remote work per year
Flexible working hours
+3