Mid-Level Governance, Risk, and Compliance (GRC) Analyst
About the company
ORAEX Cloud Consulting is a consultancy specialized in the modernization and optimization of IT processes, infrastructure, and governance.
We act in the implementation and management of technologies that support critical corporate environments, focusing on innovation, performance, and operational efficiency.
Responsibilities and Duties:
Perform governance of internal and external audits, including ISO27001, PCI-DSS, BACEN, ITGC/SOX.
Manage and monitor action plans for the correction of non-conformities and identified gaps.
Support regulatory and normative compliance processes, ensuring adherence to applicable internal and external requirements.
Develop, review, and maintain information security policies, standards, and procedures.
Work together with various areas, including technical and business teams, to ensure the compliance of internal controls and security governance.
Interact with other entities of the Group to align local and global initiatives related to security control compliance.
Requirements:
Knowledge of security standards and frameworks, such as PCI-DSS, ISO 27001, and BACEN regulatory requirements.
Experience in conducting audits and managing information security controls.
Experience in the development, review, and implementation of security policies and standards.
Intermediate English and Spanish levels, for participation in meetings and reading/writing of documents.
Differentials:
Certifications such as ISO 27001 Lead Implementer/Lead Auditor, CISA, CISM, CRISC, or PCI ISA.
Knowledge in Cloud Security (preferably Azure).
Experience with the implementation of cybersecurity best practices and regulatory compliance.