Analyst, Information Security and Compliance

4 semanas atrás


São Paulo, São Paulo, Brasil Mastercard Tempo inteiro
Our Purpose
- Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build _a sustainable economy_ where everyone can prosper. We support a wide range of digital payments choices, making _transactions secure,_ simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential._
Title and Summary
Analyst, Information Security and Compliance
**Responsibilities**:
Internal Compliance
- Identifying control gaps and process improvement opportunities; evaluating compliance with
operational, legal, regulatory and IT policies and procedures
- Maintaining and managing the controls list
- Tracking and monitoring management action plans to ensure sustainable resolution of control gaps
- Providing risk and control advice and education for the benefit of the organization, being a "champion" and advocate for strong risk management and governance controls and partnering with
other control functions to strengthen our three lines of defense model
- Understanding and critically analyzing complex IT processes, identifying and assessing potential risks and determining whether those risks are appropriately mitigated (using various techniques
such as problem solving, root cause and data analysis)
Security Due Diligence Questionnaires
- Managing the security/due-diligence questionnaires lifecycle and ensuring compliant,
accurate and timely completion of all responses
- Responding to clients due-diligence questionnaires and audits
- Identifying the needs, requirements and risks associated with questionnaires received
- Maintaining a library of content to help ensure responses are up-to-date; contributing to
developing and improving the process and the existing knowledge-base to streamline the
responses
- Responsible for managing regular scheduled internal reviews of key control areas
- Excellent communication skills, both written and verbal; strong presentation
Skills required
Must have a positive attitude, an excellent critical thinking and problem-solving skills to supports the business working with cross-functional teams on projects and initiatives. Liaise with internal and external stakeholders on an ongoing basis during the audit, relative to plans, objectives, evidence collection and results documenting, presenting and tracking findings and remediation actions.
- Preferably 3 - 5 years' experience with/in:
IT security controls
IT Audit, and/or
Compliance management, and/or
Project management/ coordination (document collections, coordination, tracking, customer partnership), and/or
Information management
- Understanding of risk management and Information Security frameworks
- Certified Professional designation (CSA CCM, CISSP, CISA, CRISC) or willingness to work towards one or more of these certifications
- Experience with GDPR and/or PIPEDA and/or similar Data Privacy frameworks
- Experience with information management/ RFP platforms (e.g., Loopio, RFPIO, RFP360, etc.)
- Experience working with auditors and other stakeholders, managing audits, collecting evidence and tracking findings to a resolution
- Intellectually curious, self-motivated, passionate works well both independently and as part of a team
- Ability to influence change through effective communication and interpersonal skills
- Ability to work and partner with others in different levels of the organization
- Ability to multi-task, be organized and take initiative audit management.
- Managing the PCI, SOC-2 and other compliance programs end-to-end
- Evaluating internal stakeholders' response to audits and reporting to management on appropriateness
- Acting in a consultative capacity, providing advice and clarity to teams on compliance requirements and audits
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard's security policies and practices;- Ensure the confidentiality and integrity of the information being accessed;- Report any suspected information security violation or breach, and- Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.

  • São Paulo, São Paulo, Brasil WEX Inc. Tempo inteiro

    Senior Information Security GRC Analyst page is loadedSenior Information Security GRC Analyst Apply locations Brazil Sao Paulo - Remote Office Brazil Porto Alegre - Remote Office Brazil Salvador - Remote Office time type Full time posted on Posted 14 Days Ago job requisition id R18721About the Team/Role We are seeking a highly experienced and proactive...


  • São Paulo, São Paulo, Brasil WEX Inc. Tempo inteiro

    Senior Information Security GRC Analyst page is loadedSenior Information Security GRC AnalystApply locations Brazil Sao Paulo - Remote Office Brazil Porto Alegre - Remote Office Brazil Salvador - Remote Office time type Full time posted on Posted 14 Days Ago job requisition id R18721About the Team/RoleWe are seeking a highly experienced and proactive...


  • São Paulo, São Paulo, Brasil Tata Consultancy Services Tempo inteiro

    Get AI-powered advice on this job and more exclusive features.Direct message the job poster from Tata Consultancy ServicesGlobal Talent Acquisition Recruiter at Tata Consultancy Services (Latam Region)Come to one of the biggest IT Services companies in the world Here you can transform your careerWhy to join TCS? Here at TCS we believe that people make the...


  • São Paulo, São Paulo, Brasil DiDi Global Tempo inteiro

    Company Overview:If you see technology as there to smooth your path in life, our team does too: Your Path, Our Journey.We believe in people who transform their paths through technology. Technology that connects people who are good at what they do and which practices diversity to create and share those paths that we (as yet) do not even know about. Our...


  • São Paulo, São Paulo, Brasil DiDi Global Tempo inteiro

    Company Overview:If you see technology as there to smooth your path in life, our team does too: Your Path, Our Journey.We believe in people who transform their paths through technology. Technology that connects people who are good at what they do and which practices diversity to create and share those paths that we (as yet) do not even know about. Our...


  • São Paulo, São Paulo, Brasil Array Technologies Tempo inteiro

    4 days ago Be among the first 25 applicantsArray Technologies, Inc. is a global leader in solar energy solutions – and we have been for over 30 years Our dramatic growth is creating incredible opportunities on our dynamic, innovative andcreative team. Are you self-motivated, highly-skilled and possess previous Cyber Security / Information Security...


  • São Paulo, São Paulo, Brasil Array Technologies Tempo inteiro

    4 days ago Be among the first 25 applicants Array Technologies, Inc. is a global leader in solar energy solutions – and we have been for over 30 years Our dramatic growth is creating incredible opportunities on our dynamic, innovative and creative team. Are you self-motivated, highly-skilled and possess previous Cyber Security / Information Security...


  • São Paulo, São Paulo, Brasil Array Technologies Tempo inteiro

    4 days ago Be among the first 25 applicants Array Technologies, Inc. is a global leader in solar energy solutions – and we have been for over 30 years Our dramatic growth is creating incredible opportunities on our dynamic, innovative and creative team. Are you self-motivated, highly-skilled and possess previous Cyber Security / Information Security...


  • São Paulo, São Paulo, Brasil beBeeSecurity Tempo inteiro R$128.640 - R$161.680

    Job OverviewWe are a team of innovators who believe in harnessing technology to transform people's lives.Our mission is to make life easier for millions of people every day by leveraging cutting-edge solutions and collaboration.Monitor and manage vulnerabilities, ensuring compliance with relevant regulations on a daily basis.Develop and implement corrective...


  • São Paulo, São Paulo, Brasil Pay Retailers Tempo inteiro

    At PayRetailers, we are committed to providing cutting-edge solutions that empower businesses to succeed in Latin America. Our collaborative and inclusive work environment encourages creativity and growth, where every employee's contribution is valued. Get ready to embark on an exciting journey with us, as we strive to make a meaningful impact on the world...