
Information Security Specialist
2 semanas atrás
**Information Security Specialist (GRC)**
At SumUp our vision is to be a global leader in the FinTech industry and build a world where small businesses can be successful doing what they love. To get there, we are putting together a team that is passionate about what they do, committed to one another and to our merchants.
The Information Security Team is a key component in SumUp's Governance, Risk and Compliance (GRC) team. Our SumUp office in Brazil is hiring for an Information Security Specialist.
As an Information Security Specialist, you'll help us ensure that we're taking all the required steps to build a secure product set and protect our production environments from ever-evolving cyber threats. You'll play a key role in our product engineering ecosystem and partner with engineers from various tribes and squads to oversee the security of our products and features. You'll be influencing implementation of cutting-edge measures to minimise exposures and vulnerabilities while actively training and educating the engineers on security best practices and latest developments. We will look toward your unique skills to approach and solve problems in your own way while ensuring alignment with our global strategic directions. Whether engineering a system to address a technical security hurdle, protecting the customers' data, or consulting on a wide range of security topics, you are fully empowered to autonomously drive the engagement and promote security best practices cross-functionally.
**Responsibilities - What you will do**:
- Contribute to the ongoing design, implementation, improvement and maintenance of the SumUp Information Security Management Program.
- Improve and maintain information security risk management systems
- Review information security controls, audit recommendations and risk mitigation plans and collaborate with other teams to implement the necessary actions.
- Participate in third-party risk management by conducting third party due diligence, supplier reviews and contract review.
- Collaborate with other stakeholders to promote information security best practices, provide expert advice and help to integrate security principles into their processes.
- Support the preparation of external audits or due diligences and respond to auditors, clients and partner requests.
- Monitor the existing laws, regulations and security standards to ensure adequacy with the security controls and processes in place.
- Willing to travel as required.
**Experience required - You'll be great for this position if**:
- You have a Bachelor or Master Degree in information security or technical area or similar qualification
- You have 4+ years of professional experience in a similar position and have acquired knowledge in information security and governance, information security risk management and data protection within the financial industry..
- You have knowledge and experience of common information security standards (e.g, ISO 2700X, NIST), payment standard (e.g. PCI-DSS) and data privacy regulation (e.g. GDPR).
- Ideally you will have experience with third-party risk management and audit procedures as well.
- You hold professional certifications such as CISSP, CISM, ISO 27001 or similar.
- You enjoy working independently as much as working in a team and demonstrate good team spirit & cooperation skills.
- You have strong organizational and analytical skills.
- You have strong communication skills and are comfortable working with stakeholders across all levels.
- You work in an ethical manner and have a high sense of integrity and confidentiality.
- You speak and write fluent English.
**Why SumUp?**.
- Be a part of a truly global team: SumUppers come from over 50 different countries around the world (The GRC Team has nearly 80 members over 3 continents).
- You'll work in an amazing agile team environment that values passion and purpose to achieve incredible results.
- You'll have access to rewarding compensation and benefits.
- You'll have the freedom to drive your career, own projects, and make an impact across the company.
- You'll enjoy flexible hours - we don't micromanage. You have freedom to align with your team if you want to work remotely or take a few days off.
- SumUp is an Equal Employment Opportunity employer that proudly pursues and hires a diverse workforce. SumUp does not make hiring or employment decisions on the basis of race, colour, religion or religious belief, ethnic or national origin, nationality, sex, gender, gender identity, sexual orientation, disability, age or any other basis protected by applicable laws or prohibited by Company policy. SumUp also strives for a healthy and safe workplace and strictly prohibits harassment of any kind._
LI-PD1
**Job Application Tip
-
Information Security Specialist
2 semanas atrás
Sao Paulo, Brasil SumUp Tempo inteiro**Information Security Specialist (GRC)**At SumUp our vision is to be a global leader in the FinTech industry and build a world where small businesses can be successful doing what they love. To get there, we are putting together a team that is passionate about what they do, committed to one another and to our merchants.The Information Security Team is a key...
-
Information Security Specialist
1 semana atrás
Sao Paulo, Brasil Nubank Tempo inteiro**About Nubank** Nubank was founded in 2013 to free people from a bureaucratic, slow and inefficient financial system. Since then, through innovative technology and outstanding customer service, the company has been redefining people's relationships with money across Latin America. With operations in Brazil, Mexico, and Colombia, Nubank is today one of the...
-
Information Security Specialist
Há 6 dias
Sao Paulo, Brasil Nubank Tempo inteiro**About Nubank**Nubank was founded in 2013 to free people from a bureaucratic, slow and inefficient financial system. Since then, through innovative technology and outstanding customer service, the company has been redefining people's relationships with money across Latin America. With operations in Brazil, Mexico, and Colombia, Nubank is today one of the...
-
Security Specialist
Há 3 dias
Sao Paulo, Brasil Microsoft Tempo inteiroMicrosoft continues to invest significantly per year in cyber security and research, to provide its customers with the solutions to confidently move to the cloud and modernize their platforms by delivering the security and compliance solutions, expertise and services needed to keep their data safe. In the Security Solutions Area we are passionate about this...
-
Technical Specialist- Cyber Security
2 semanas atrás
Sao Paulo, Brasil Microsoft Tempo inteiroMicrosoft is on a mission to empower every person and every organization on the planet to achieve more. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. You can...
-
Technical Specialist- Cyber Security
1 semana atrás
Sao Paulo, Brasil Microsoft Tempo inteiroMicrosoft is on a mission to empower every person and every organization on the planet to achieve more. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. You can...
-
Regional Information Security Officer
1 semana atrás
São Paulo, Brasil IQVIA Tempo inteiroAs the Regional Information Security Officer, you will help to elevate our Cybersecurity Program by unifying Global Cyber Security Practices across IQVIA Business Units.You will provide oversight and coordination of delivery of global Cyber security portfolio risk mitigation projects and programs within the US & Canada region.Reporting directly the Global...
-
Information Security Engineer
2 semanas atrás
São Paulo, Brasil Array Technologies Tempo inteiro4 days ago Be among the first 25 applicants Array Technologies, Inc. is a global leader in solar energy solutions – and we have been for over 30 years! Our dramatic growth is creating incredible opportunities on our dynamic, innovative and creative team. Are you self-motivated, highly-skilled and possess previous Cyber Security / Information Security...
-
Information Security Engineer
2 semanas atrás
São Paulo, Brasil Array Technologies Tempo inteiro4 days ago Be among the first 25 applicants Array Technologies, Inc. is a global leader in solar energy solutions – and we have been for over 30 years! Our dramatic growth is creating incredible opportunities on our dynamic, innovative and creative team. Are you self-motivated, highly-skilled and possess previous Cyber Security / Information Security...
-
Regional Information Security Officer
1 semana atrás
São Paulo, SP, Brasil IQVIA Tempo inteiroAs the Regional Information Security Officer, you will help to elevate our Cybersecurity Program by unifying Global Cyber Security Practices across IQVIA Business Units. You will provide oversight and coordination of delivery of global Cyber security portfolio risk mitigation projects and programs within the US & Canada region. Reporting directly the...