Information Security & Compliance Manager
About the Role
The company is in search of a dedicated individual to join the Information Security and Compliance team, specializing in adhering to cybersecurity regulations in Brazil and across the Americas. The Information Security & Compliance Manager will serve as a project leader, offering expert guidance on cybersecurity integration and regulatory compliance. This role involves collaborating with key IT stakeholders, steering committees, project teams, technical leads, third-party vendors, and customers. Responsibilities include identifying compliance gaps, making recommendations, and supporting remediation efforts. The role also entails providing technical advice to ensure security compliance requirements are met across all business units.
Responsibilities
- Develop, document, and update controls to meet international standards and local regulations, including the Central Bank of Brazil requirements.
- Oversee daily security integration activities, ensuring effective communication with stakeholders and resolution of issues to minimize disruptions.
- Enhance existing security integration methods through input from the corporate security team to assess the target organization's security posture and identify risks.
- Participate in security and privacy assessments, monitor security controls' effectiveness, and evaluate systems to evaluate the organizational security posture.
- Conduct security compliance activities, risk assessments, third-party assessments, and manage remediation activities.
- Evaluate and ensure the effectiveness of technical and organizational controls compliant with regulations.
- Provide recommendations on necessary changes to improve information systems security, considering business needs.
Qualifications
- Knowledge of Resolução BCB 85/2021 and BCB 198 standards.
- Experience in BACEN audit preparation and examination.
- Proficient in English, with advanced reading and writing skills.
- Strong leadership abilities to collaborate with stakeholders effectively.
- Understanding of business impact of security tools and risk assessment.
- Motivated to work in a fast-paced environment.
- Technical expertise in IT processes like configuration management, networking, and database management.
- Previous experience in information security, IT audit, or IT risk management roles.
- Preference for experience with ISO27001, ISO27701 standards, and data protection regulations.
- Security-related certifications (CISSP, CRISC, CISM, CISA, etc.) preferred.
- Minimum 5 years of security technology experience, with 2 years in supporting BACEN regulated activities.
Preferred
- Team player with a positive attitude.
- Committed to personal development and learning.
- Detail-oriented with strong analytical skills.
- Effective communication of technical issues to non-technical users.
- Previous project management experience.
- Interest in Blockchain is beneficial.
- Proficiency in both spoken and written English.
