Descrição do trabalho
Main Job Responsibilities
Our ideal candidate will be responsible for identifying and assessing cybersecurity risks, ensuring compliance with relevant standards and regulations, and developing and maintaining governance, risk, and compliance policies. They will also collaborate with internal teams to implement security controls, conduct periodic assessments, and define key performance indicators.
- Workday:
- Identify, assess, and monitor cybersecurity and compliance risks;
- Ensure the implementation and compliance with applicable standards and regulations (e.G., GDPR, ISO 27001, NIST CSF, NIS2);
- Support internal and external audits, ensuring proper preparation and response to security findings;
- Develop and maintain GRC policies, standards, and frameworks aligned with market best practices;
- Collaborate with internal teams to ensure the effective implementation of security controls;
- Conduct periodic assessments and reviews for continuous improvement of security practices;
- Define and track KPIs and metrics related to risk and compliance;
- Prepare reportsfor management on security status and identified risks;
- Participate in the definition and execution of security incident response plans;
- Develop and promote security and compliance awareness programs for employees;
- Promote best practices and secure behaviors within the organization;
- Act as a strategic partner to IT, Legal, and Business teams in risk and compliance management;
- Provide supportin evaluating risks associated with suppliers and third parties.