Analyst, Information Security and Compliance
Há 3 dias
Our Purpose- Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build _a sustainable economy_ where everyone can prosper. We support a wide range of digital payments choices, making _transactions secure,_ simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential._Title and SummaryAnalyst, Information Security and Compliance**Responsibilities**:Internal Compliance- Identifying control gaps and process improvement opportunities; evaluating compliance withoperational, legal, regulatory and IT policies and procedures- Maintaining and managing the controls list- Tracking and monitoring management action plans to ensure sustainable resolution of control gaps- Providing risk and control advice and education for the benefit of the organization, being a "champion” and advocate for strong risk management and governance controls and partnering withother control functions to strengthen our three lines of defense model- Understanding and critically analyzing complex IT processes, identifying and assessing potential risks and determining whether those risks are appropriately mitigated (using various techniquessuch as problem solving, root cause and data analysis)Security Due Diligence Questionnaires- Managing the security/due-diligence questionnaires lifecycle and ensuring compliant,accurate and timely completion of all responses- Responding to clients due-diligence questionnaires and audits- Identifying the needs, requirements and risks associated with questionnaires received- Maintaining a library of content to help ensure responses are up-to-date; contributing todeveloping and improving the process and the existing knowledge-base to streamline theresponses- Responsible for managing regular scheduled internal reviews of key control areas- Excellent communication skills, both written and verbal; strong presentationSkills requiredMust have a positive attitude, an excellent critical thinking and problem-solving skills to supports the business working with cross-functional teams on projects and initiatives. Liaise with internal and external stakeholders on an ongoing basis during the audit, relative to plans, objectives, evidence collection and results documenting, presenting and tracking findings and remediation actions.- Preferably 3 - 5 years' experience with/in:IT security controlsIT Audit, and/orCompliance management, and/orProject management/ coordination (document collections, coordination, tracking, customer partnership), and/orInformation management- Understanding of risk management and Information Security frameworks- Certified Professional designation (CSA CCM, CISSP, CISA, CRISC) or willingness to work towards one or more of these certifications- Experience with GDPR and/or PIPEDA and/or similar Data Privacy frameworks- Experience with information management/ RFP platforms (e.g., Loopio, RFPIO, RFP360, etc.)- Experience working with auditors and other stakeholders, managing audits, collecting evidence and tracking findings to a resolution- Intellectually curious, self-motivated, passionate works well both independently and as part of a team- Ability to influence change through effective communication and interpersonal skills- Ability to work and partner with others in different levels of the organization- Ability to multi-task, be organized and take initiative audit management.- Managing the PCI, SOC-2 and other compliance programs end-to-end- Evaluating internal stakeholders' response to audits and reporting to management on appropriateness- Acting in a consultative capacity, providing advice and clarity to teams on compliance requirements and auditsCorporate Security ResponsibilityAll activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:- Abide by Mastercard’s security policies and practices;- Ensure the confidentiality and integrity of the information being accessed;- Report any suspected information security violation or breach, and- Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.
-
Information Security Compliance Analyst
Há 6 dias
São Paulo, Brasil Access | Gestão De Informação Tempo inteiroAbout Access Corp Access Corp is a leading provider of secure information management solutions, helping organizations manage, protect, and unlock the value of their data.We are committed to innovation, integrity, and operational excellence.Position SummaryAccess Corp is seeking a detail-oriented and proactive Information Security Compliance Analyst to...
-
Information Security Compliance Analyst
1 semana atrás
São Paulo, Brasil Access | Gestão de Informação Tempo inteiroAbout Access CorpAccess Corp is a leading provider of secure information management solutions, helping organizations manage, protect, and unlock the value of their data. We are committed to innovation, integrity, and operational excellence.Position SummaryAccess Corp is seeking a detail-oriented and proactive Information Security Compliance Analyst to...
-
Information Security Compliance Analyst
1 dia atrás
São Paulo, Brasil Access Brasil Tempo inteiroAccess Corp is a leading provider of secure information management solutions, helping organizations manage, protect, and unlock the value of their data. We are committed to innovation, integrity, and operational excellence. Position Summary Access Corp is seeking a detail-oriented and proactive Information Security Compliance Analyst to support our growing...
-
Information Security Compliance Analyst
1 semana atrás
são paulo, Brasil Access | Gestão de Informação Tempo inteiroAbout Access Corp Access Corp is a leading provider of secure information management solutions, helping organizations manage, protect, and unlock the value of their data. We are committed to innovation, integrity, and operational excellence. Position Summary Access Corp is seeking a detail-oriented and proactive Information Security Compliance Analyst to...
-
Information security compliance analyst
Há 7 dias
São Paulo, Brasil Access | Gestão De Informação Tempo inteiroAbout Access Corp Access Corp is a leading provider of secure information management solutions, helping organizations manage, protect, and unlock the value of their data. We are committed to innovation, integrity, and operational excellence. Position Summary Access Corp is seeking a detail-oriented and proactive Information Security Compliance Analyst to...
-
Information Security Compliance Analyst
1 semana atrás
São Paulo, São Paulo, Brasil Access Brasil Tempo inteiroAbout Access CorpAccess Corp is a leading provider of secure information management solutions, helping organizations manage, protect, and unlock the value of their data. We are committed to innovation, integrity, and operational excellence.Position SummaryAccess Corp is seeking a detail-oriented and proactiveInformation SecurityCompliance Analystto support...
-
Compliance Lead, Information Security
1 dia atrás
São Paulo, Brasil CAI Software, LLC Tempo inteiroAbout the RoleWe are seeking an experienced and detail-oriented Compliance Lead to join our Information Security team. This role is responsible for leading, maintaining, and continuously improving the organization’s compliance initiatives across key information security frameworks, including ISO 27001, SOC 2 Type II, PCI DSS, and GDPR. The ideal candidate...
-
Compliance Lead, Information Security
Há 5 dias
São Paulo, Brasil CAI Software, LLC Tempo inteiroAbout the Role We are seeking an experienced and detail-oriented Compliance Lead to join our Information Security team. This role is responsible for leading, maintaining, and continuously improving the organization’s compliance initiatives across key information security frameworks, including ISO 27001, SOC 2 Type II, PCI DSS, and GDPR. The ideal candidate...
-
Information Security Compliance Manager
2 semanas atrás
São Paulo, Brasil IQVIA Tempo inteiroRole:As an **Information Security Compliance Mgr**., you will play a crucial role in ensuring the security and compliance of our organization. You’ll be responsible for providing assurance to our external parties on the security posture of IQVIA. This role plays a significant part in our Global Information Security team and will provide an excellent...
-
Information Security Analyst
3 semanas atrás
Sao Paulo, Brasil Eurofins Brazil Tempo inteiroCompany DescriptionEurofins Scientific is an international life sciences company which provides a unique range of analytical testing services to clients across multiple industries. The Group believes it is the world leader in food, environment and pharmaceutical products testing and in agroscience CRO services. It is also one of the global independent market...