Information Security Specialist

Há 5 horas


Sao Paulo, Brasil SumUp Tempo inteiro

At SumUp our vision is to be a global leader in the FinTech industry and build a world where small businesses can be successful doing what they love. To get there, we are putting together a team that is passionate about what they do, committed to one another and to our merchants.

The Information Security Team is a key component in SumUp's Governance, Risk and Compliance (GRC) team. Our SumUp office in Brazil is hiring for an Information Security Specialist.

As a key member of the SumUp global information security team, you will contribute to the achievement of SumUp security objectives which are to.protect confidentiality, integrity and availability of SumUp information and client information assets. You will strengthen the Security Assurance section dedicated to information security governance and risk management. You can be sure of having agile working in a motivated, dynamic and international security team.

**Responsibilities - What you will do**:

- Contribute to the ongoing design, implementation, improvement and maintenance of the SumUp Information Security Management Program.
- Improve and maintain information security risk management systems
- Review information security controls, audit recommendations and risk mitigation plans and collaborate with other teams to implement the necessary actions.
- Participate in third-party risk management by conducting third party due diligence, supplier reviews and contract review.
- Collaborate with other stakeholders to promote information security best practices, provide expert advice and help to integrate security principles into their processes.
- Support the preparation of external audits or due diligences and respond to auditors, clients and partner requests.
- Monitor the existing laws, regulations and security standards to ensure adequacy with the security controls and processes in place.

**Experience required - You'll be great for this position if**:

- You have a Bachelor or Master Degree in information security or technical area or similar qualification
- You have 4+ years of professional experience in a similar position and have acquired knowledge in information security governance, information security risk management and data protection
- You have knowledge and experience of common information security standards (e.g, ISO 2700X, NIST), payment standard (e.g. PCI-DSS) and data privacy regulation (e.g. GDPR).
- Ideally you will have experience with third-party risk management and audit procedures as well.
- You hold professional certifications such as CISSP, CISM, ISO 27001 or similar.
- You enjoy working independently as much as working in a team and demonstrate good team spirit & cooperation skills.
- You have strong organizational and analytical skills.
- You have strong communication skills and are comfortable working with stakeholders across all levels.
- You work in an ethical manner and have a high sense of integrity and confidentiality.
- You speak and write fluent English.

**Why SumUp?**.
- Be a part of a truly global team: SumUppers come from over 50 different countries around the world (The GRC Team has nearly 80 members over 3 continents).
- You'll work in an amazing agile team environment that values passion and purpose to achieve incredible results.
- You'll have access to rewarding compensation and benefits.
- You'll have the freedom to drive your career, own projects, and make an impact across the company.
- You'll enjoy flexible hours - we don't micromanage. You have freedom to align with your team if you want to work remotely or take a few days off.
- SumUp is an Equal Employment Opportunity employer that proudly pursues and hires a diverse workforce. SumUp does not make hiring or employment decisions on the basis of race, colour, religion or religious belief, ethnic or national origin, nationality, sex, gender, gender identity, sexual orientation, disability, age or any other basis protected by applicable laws or prohibited by Company policy. SumUp also strives for a healthy and safe workplace and strictly prohibits harassment of any kind._

**Job Application Tip



  • São Paulo, São Paulo, Brasil WestSac Petcare Research Institute Tempo inteiro R$40.000 - R$60.000 por ano

    Role DescriptionThis is a full-time on-site role for an Information Technology Specialist located in São Paulo, SP. The IT Specialist will be responsible for daily management of network operations, network security, troubleshooting technical issues, and providing customer service. The specialist will work to ensure the institution's IT infrastructure is...


  • Sao Paulo, Brasil Mondelēz International Tempo inteiro

    **Job Description**: **Are You Ready to Make It Happen at Mondelēz International?** **Join our Mission to Lead the Future of Snacking. Make It Uniquely Yours.** You work with the information security team as a competent and experienced information security and compliance leader. **How you will contribute** You will assess information security risks in...


  • Sao Paulo, Brasil DLL Tempo inteiro

    **Information Security Officer** Do you believe businesses should have a bigger ambition than short term profit? If you do, join DLL’s mission to ‘See what counts’. You’ll be part of a team that gets the right tools into the right hands. A team that understands the heart and soul of our partners’ business. A team that provides original financial...


  • Sao Paulo, Brasil DLL Group Tempo inteiro

    Do you believe businesses should have a bigger ambition than short term profit? If you do, join DLL’s mission to ‘See what counts’. You’ll be part of a team that gets the right tools into the right hands. A team that understands the heart and soul of our partners’ business. A team that provides original financial solutions to sustain success for...

  • Information Security Analyst

    2 semanas atrás


    São Paulo, São Paulo, Brasil Botcity Tempo inteiro

    Company OverviewBotCity is building the future of automation with the Governance Platform for Python automations and AI Agents. We empower enterprises to innovate at scale, bringing governance, control, and observability to every automation project. Our philosophy is simple: automation is software, and software deserves the same high-code standards that...


  • Sao Paulo, Brasil Informaker Tempo inteiro

    "Consultor Information Security - Conhecimentos: em frameworks de SI (ISO, NIST, CIS...) - Capacidade de realizar assessment de governança voltado a SI, com algum backgroud técnico - Capacidade de realizar análises de risco e maturidade de Segurança da Informação, baseando-se nos frameworks, com objetivo de construir de um Roadmap de adequações -...

  • Security Specialist

    Há 6 dias


    Sao Paulo, Brasil Western Union Tempo inteiro

    Are you a data expert with a focus on enhancing security? Would you like to have exposure to a wide range of internal stakeholders? Join Western Union as a Security Specialist. **Motivated by our values: purpose-driven, globally minded, and trustworthy & respectful** We’re a FinTech that’s using insight from customers and colleagues worldwide to...


  • São Paulo, Brasil Array Technologies Tempo inteiro

    4 days ago Be among the first 25 applicants Array Technologies, Inc. is a global leader in solar energy solutions – and we have been for over 30 years! Our dramatic growth is creating incredible opportunities on our dynamic, innovative and creative team. Are you self-motivated, highly-skilled and possess previous Cyber Security / Information Security...


  • São Paulo, Brasil Array Technologies Tempo inteiro

    4 days ago Be among the first 25 applicants Array Technologies, Inc. is a global leader in solar energy solutions – and we have been for over 30 years! Our dramatic growth is creating incredible opportunities on our dynamic, innovative and creative team. Are you self-motivated, highly-skilled and possess previous Cyber Security / Information Security...

  • Information Security Manager

    2 semanas atrás


    São Paulo, Brasil Iris Software Tempo inteiro

    Overview Information Security Manager We are one of the largest technology-driven Audit, Consulting, Tax, Strategy, and Transaction services in the world. With a presence in over 150 countries, here you will have the opportunity to experience exceptional experiences that only EY can offer, with global reach, an inclusive culture, and technology to become...