Information Security Senior Analyst

Há 2 dias


Sao Paulo, Brasil DiDi Global Tempo inteiro

Company Overview:
If you see technology as there to smooth your path in life, our team does too: Your Path, Our Journey.

We believe in people who transform their paths through technology. Technology that connects people who are good at what they do and which practices diversity to create and share those paths that we (as yet) do not even know about. Our journey is in the smile of every talented person who brings revolution to the world from Brazil - whether with in-app transportation (99) or digital payments (99Pay).

To make life easier for millions of people every day, we are in the driving seat as part of DiDi Chuxing, the world's largest transport, and convenient platform. And so, we can say, with great pride, that we are pioneers in creating solutions, starting in Brazil, that grow in scale and have positive impacts in a range of other countries.

Whether creating projects from scratch or continually improving our solutions, we like challenges that give us butterflies, and that's why we work with intensity, at a fast pace, with respect, collaboration, and partnership. On this journey, we also create learning and strengthen ourselves in diversity as a fundamental aspect that makes us stand out for our growth day after day.

Team Overview:
The Information Security Senior Analyst will be responsible for monitoring activities related to vulnerability management and ensuring compliance with privacy regulations on a daily basis.

Role Responsibilities:

- Monitor activities for vulnerability management and ensure compliance with relevant privacy regulations.
- Monitor audits, create and monitor corrective action plans to address compliance and privacy gaps.
- Follow security incidents until closure, adhering to the incident management process.
- Advise and report on industry best practices for compliance and privacy.
- Stay up-to-date on security trends, especially those related to compliance and privacy, and report as necessary.
- Lead investigations into cyber security breaches and intrusions with a focus on compliance and privacy.
- Provide a coordinated response to complex cyber attacks, ensuring compliance with privacy regulations.
- Create reports, procedures, and playbooks for incident response activities with a strong emphasis on compliance and privacy.

Role Qualifications:

- Demonstrated experience in cloud security and Security Operations (SecOps) with a focus on compliance and privacy.
- Solid understanding of security concepts, particularly in relation to compliance and privacy requirements.
- 3+ years of combined experience in related information security fields, with specific experience in critical analysis to identify and address information security issues with compliance and privacy considerations.
- Advanced proficiency in spoken and written English, as all reports must be written in this language.
- Experience in CSIRT/DIRT practices (Computer Security Incident Response Team/ Digital Incident Response Team).
- Certifications: Security+ or/and any additional certifications related to compliance and privacy would be beneficial.
- Previous experience working in a Security Operations Center (SOC),
- Managed Security Services (MSS), or incident handling role.
- Broad knowledge of security practices and standards prevalent in the industry, with a strong emphasis on compliance and privacy.
- Ability to plan, organize, and meet deadlines while considering compliance and privacy requirements.

EEO Statement:
**You'll love working at DiDi because**
- We create customer value - We strive to always create valuable experiences for our users in everything we do. Our focus is to always innovate new experiences that are safe, pleasant, and efficient.
- We are data-driven - We are strong believers in making informed decisions, that’s why we are data-driven. We can better navigate the business landscape strategically by analyzing valuable metrics.
- We believe in Win-win Collaboration - Success is a team sport. When we work to help our partners and colleagues win, we win, too. While keeping everyone's best interest at heart, we communicate with candor and execute with excellence in all we do.
- We believe in integrity - Integrity is at the very core of our business. We are people who always want to do the right thing. Our intentions are sincere, we speak our minds and listen to each other.
- We always strive to do better. That means venturing beyond our comfort zones, learning from our mistakes, and helping each other grow.
- We believe in Diversity and Inclusion - Diversity is one of our biggest strengths. Our differences are what makes us distinct. We respect each other and believe in equal opportunities for all.

**Diversity & Inclusion**

Diversity is not a vision of the future or something we wish to have one day, it is a non-negotiable value of who we are.

We practice inclusion, plurality, and respect. And we count on the governance of the Diversity Committee, which works together with HR, lea



  • Sao Paulo, Brasil IQVIA Tempo inteiro

    **Role**: As a** Senior Information Security Metrics Analyst, **you will play a crucial role in ensuring the security and compliance of our organization. You’ll be responsible for analyzing, measuring, and reporting on various security metrics to enhance our overall security posture. Your expertise will guide decision-making and risk management...

  • Information Security Analyst

    2 semanas atrás


    São Paulo, São Paulo, Brasil Botcity Tempo inteiro

    Company OverviewBotCity is building the future of automation with the Governance Platform for Python automations and AI Agents. We empower enterprises to innovate at scale, bringing governance, control, and observability to every automation project. Our philosophy is simple: automation is software, and software deserves the same high-code standards that...


  • Sao Paulo, Brasil Bank of America Tempo inteiro

    **Responsibilities**: - Advise LOB management on risk issues related to information security and recommend actions in support of the bank's wider risk management and compliance programs. - Monitor information security trends internal and external to the bank and keep LOB leadership informed about information security-related topics. - Collaborate with risk...


  • São Paulo, Brasil Mastercard Tempo inteiro

    Our Purpose - Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build _a sustainable economy_ where everyone can prosper. We support a wide range of digital payments choices, making _transactions secure,_ simple, smart and accessible. Our technology and innovation,...


  • Sao Paulo, Brasil Topaz Tempo inteiro

    **Jr Information Security Analyst** Ser Topaz significa assumir o compromisso de contribuir dia a dia em cocriar soluções capazes de fazer da indústria financeira um lugar mais seguro, dinâmico e acessível para todos, em todas as partes. Nosso amplo ecossistema de soluções tecnológicas nos posiciona como a plataforma financeira mais completa do...


  • São Paulo, Brasil IQVIA Tempo inteiro

    Role: As an **Information Security Compliance Mgr**., you will play a crucial role in ensuring the security and compliance of our organization. You’ll be responsible for providing assurance to our external parties on the security posture of IQVIA. This role plays a significant part in our Global Information Security team and will provide an excellent...

  • Security Analyst

    Há 6 dias


    São Paulo, Brasil Bunge Tempo inteiro

    Location :BAL - SEDE City :Sao Paulo State :São Paulo (BR-SP) Country :Brazil (BR) Requisition Number :40380 At Bunge, people don’t just come here to work, they come here to grow – solving challenges that directly impact the world with a diverse and talented team working to make us the most innovative and dynamic company in our industry. Bunge offers a...

  • Cyber Security Analyst

    Há 11 horas


    Sao Paulo, Brasil Santander Tempo inteiro

    Cyber Security Analyst SAO PAULO, Brazil **WHAT YOU WILL BE DOING** **Quais serão seus desafios e responsabilidades?**: - Execução das rotinas de acompanhamento a operação do Security Operation Center; - Apoio no desenvolvimento dos controles (procedimentos como Playbooks e Runbooks); - Atuar na equipe de CSIRTs (Computer Security Incident Response...


  • São Paulo, Brasil CAI Software, LLC Tempo inteiro

    About the Role We are seeking an experienced and detail-oriented Compliance Lead to join our Information Security team. This role is responsible for leading, maintaining, and continuously improving the organization’s compliance initiatives across key information security frameworks, including ISO 27001, SOC 2 Type II, PCI DSS, and GDPR. The ideal candidate...


  • São Paulo, Brasil CAI Software, LLC Tempo inteiro

    About the RoleWe are seeking an experienced and detail-oriented Compliance Lead to join our Information Security team. This role is responsible for leading, maintaining, and continuously improving the organization’s compliance initiatives across key information security frameworks, including ISO 27001, SOC 2 Type II, PCI DSS, and GDPR. The ideal candidate...