Analista de Riscos e Controles de Segurança da Informação Sênior
Quick Summary
Proven professi
As a Senior Information Security Risk and Controls Analyst, you will play a key role in identifying, assessing, and treating information security risks across the organization. You will help strengthen security controls, evaluate their effectiveness, and drive remediation initiatives through to completion. The role also includes third-party risk management, security maturity assessments, and governance activities. You will work closely with Product, Engineering, Cloud, Compliance, and Legal teams to embed security and risk management into projects from the beginning. Your ability to investigate complex scenarios and translate technical risks into clear recommendations will support both operational and executive decision-making. This is a highly autonomous role in a collaborative, agile environment where technical expertise and attention to detail are valued.
- Lead the end-to-end information security risk management lifecycle, including risk identification, analysis, evaluation, and treatment in accordance with ISO/IEC 27005.
- Apply and continuously improve risk management methodologies, including qualitative probability-versus-impact matrices and, where appropriate, quantitative approaches such as FAIR.
- Define and monitor risk treatment plans covering mitigation, transfer, acceptance, or avoidance, ensuring appropriate follow-up through formal closure or acceptance.
- Maintain and test the information security controls framework, assessing control effectiveness, documenting exceptions, and monitoring corrective action plans.
- Conduct security control maturity assessments and gap analyses based on frameworks such as ISO/IEC 27001/27002, NIST CSF, and CIS Controls.
- Lead third-party and supplier risk assessments, including due diligence, criticality classification, and monitoring of contractual security requirements.
- Develop and maintain risk and control indicators, including KRIs and KPIs, and prepare technical and executive-level reports to support decision-making.
- Act as a technical advisor to Product, Engineering, Cloud, Compliance, and Legal teams, promoting security-by-design and risk mitigation throughout project development.
- Support formal risk acceptance and exception management processes through appropriate documentation, governance, and periodic reviews.
Requirements
~1 min read- Proven professional experience in information security risk management.
- Strong practical and in-depth knowledge of ISO/IEC 27005, including risk identification, analysis, evaluation, probability and impact criteria, and treatment planning.
- Solid understanding of ISO/IEC 27001/27002, NIST CSF, and CIS Controls and their relationship to information security risk management.
- Experience with third-party risk management (TPRM), including supplier due diligence, criticality assessments, and contractual security requirements.
- Demonstrated ability to design and perform control effectiveness testing, manage supporting evidence, and track remediation plans through completion.
- Strong technical writing and communication skills, with the ability to translate complex security risks into clear language for executive and business audiences.
- Strong organization, autonomy, analytical thinking, and senior-level judgment when handling complex assessments with limited supervision.
- Bachelor's degree or equivalent professional background in information security, technology, risk management, or a related field is desirable.
- Certifications such as ISO 27005 Risk Manager, CRISC, or ISO 27001 Lead Implementer/Auditor are desirable.
- Experience with quantitative risk modeling, such as FAIR or equivalent methodologies, is a plus.
- Experience in regulated environments, particularly financial or payment institutions subject to Central Bank of Brazil regulations, is a plus.
- Ability to translate regulatory requirements into practical security and risk management processes is desirable.
What We Offer
~2 min readLocation & Eligibility
Listing Details
- Posted
- September 29, 2026
- First seen
- September 29, 2026
- Last seen
- September 29, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 68%
- Scored at
- September 29, 2026
Signal breakdown
Similar Analista jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.