Director, Information Security Risk Management

3 semanas atrás


São Paulo, São Paulo, Brasil IQVIA Tempo inteiro
**Job Overview**
- Leading risk-related projects
- Maintaining ongoing testing and development of Information Security Risk Management framework, liaising with senior stakeholders and providing regular updates to stakeholders.
- Producing risk reports when required
- Working closely with other senior leaders within the team regarding training and guidance to support the business.
- Working with Business Units and stakeholders to ensure adequate, cost effective and timely protection/risk transfer for business activities.
- Creating a Supplier Risk Management Framework
**Key Responsibilities**:
- Own the development and integration of the Information Security Risk Management Framework, Risk Appetite Statements, and Risk Policies and Procedures across the organization.
- Work closely with business and senior management to identify and manage risks aligned with the organization's strategy and risk appetite.
- Provides strategic and tactical guidance to business decision-makers.
- Contribute to a strong governance structure and risk management across all business entities.
- Assess the impact of emerging risks and regulations, providing input and support for pragmatic solutions.
- Establish a comprehensive risk reporting system and process.
- Assist to remediate risks identified through established processes and procedures.
- Provides recommendations for remediation based on the reviews and risk assessments performed.
- Assist key business stakeholders in identifying and responding effectively to risk.
- Define key risk and performance indicators (KRIs/KPIs) for evaluating risk management performance.
- Integrate business continuity and crisis management into the organization's risk management strategies.
- Support the configuration of the TPRM & Risk Management solution for consistency with local processes.
- Assist in reviewing third parties, including due diligence reviews.
- Perform review of vendor engagements, understanding the functions of effective third-party risk.
**Qualifications**:
- Bachelor's Degree Computer Science, a related field, or equivalent experience required.
- 10 years of experience within the information security domain managing Risk frameworks.
- Deep understanding and demonstrated experience of end-to-end risk management lifecycle, including key components and their relationships with internal and external stakeholders.
- Experience in non-financial/operational risk - developing and implementing risk frameworks, policies, and procedures.
- Demonstrated experience leading risk management workshops, obtaining and synthesizing inputs from technical and non-technical stakeholders throughout the enterprise.
- Experience in conducting Third Party reviews is advantageous.
- Experience operating as a part of a GRC program in alignment with common information technology management frameworks such as NIST, ITIL, ISO 27001 etc.
- Security-related qualifications such as CISM or CISSP, CRISC are a plus.

  • São Paulo, São Paulo, Brasil Bitso Tempo inteiro

    As an Information Security Lead, you will be a key player in the planning, design, implementation, operation and maintenance of the organization's Information Security Risk Management program, guaranteeing that it complies with the legal and regulatory requirements, as well as implementing and promoting the adoption of security and risk standards such as...


  • São Paulo, São Paulo, Brasil Canonical Tempo inteiro

    Overview In security risk management we're looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we identify, track and reduce our security risk across everything we do. To...

  • Business Security Management

    3 semanas atrás


    São Paulo, São Paulo, Brasil Santander Tempo inteiro

    Business Security ManagementSAO PAULO, Brazil**WHAT YOU WILL BE DOING**Descrição do cargoThe Business Security Management function is implemented by a distributed team that collaborates closely with business lines to ensure security is appropriately considered as part of all business activities - internal and key suppliers. Business Security Managers embed...


  • São Paulo, São Paulo, Brasil Kroll Tempo inteiro

    In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate...


  • São Paulo, São Paulo, Brasil Bank of America Tempo inteiro

    **Responsibilities**:- Advise LOB management on risk issues related to information security and recommend actions in support of the bank's wider risk management and compliance programs.- Monitor information security trends internal and external to the bank and keep LOB leadership informed about information security-related topics.- Collaborate with risk...


  • São Paulo, São Paulo, Brasil Pfizer Tempo inteiro

    At Pfizer we are a patient centric company, guided by our four values: courage, joy, equity, and excellence. Our culture lends itself to our dedication to transforming millions of lives. Pfizer's Global Security team is responsible for identifying and mitigating risk to public health, patients, and core business functions to enable the delivery of...

  • Cyber Security Engineer

    2 semanas atrás


    São Paulo, São Paulo, Brasil ODATA - An Aligned Data Centers Company Tempo inteiro R$80.000 - R$120.000 por ano

    We are seeking a highly skilled Information & Cyber Security Engineer to join our team in São Paulo, Brazil, working closely with the Director, Information & Cyber Security. The ideal candidate will have extensive expertise in information security domains, with a strong emphasis on security operations, threat hunting, incident response, and vulnerability...


  • São Paulo, São Paulo, Brasil Mastercard Tempo inteiro

    **Our Purpose**- Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation,...


  • São Paulo, São Paulo, Brasil Johnson & Johnson Tempo inteiro

    Johnson & Johnson is currently recruiting a Security Director, Latin America Region (New Consumer Health Company). This position will be located in Sao Paulo, Brazil.Caring for the world, one person at a time has inspired and united the people of Johnson & Johnson for over 125 years. We embrace research and science - bringing innovative ideas, products, and...


  • São Paulo, São Paulo, Brasil Nubank Tempo inteiro

    About Nubank Nubank was founded in 2013 to free people from a bureaucratic, slow and inefficient financial system. Since then, through innovative technology and outstanding customer service, the company has been redefining people's relationships with money across Latin America. With operations in Brazil, Mexico, and Colombia, Nubank is today one of the...