IT Compliance & Controls Analyst

Jobgether· Brussels (Firmensitz, recherchiert)· lever· pubblicata il 30/07/2026
Indispensabile:AISecurityRemote

Accountabilities: As an IT Compliance & Controls Analyst, you will support the organization’s technology compliance framework by evaluating controls, assisting audit activities, and helping teams maintain strong governance practices. You will collaborate with technical and business stakeholders to identify risks, improve processes, and ensure ongoing compliance with industry standards.

Perform testing and validation of IT General Controls (ITGC), information security controls, and Quality Management System (QMS) controls.

Evaluate control design and operational effectiveness, identify gaps, and support remediation initiatives.

Assist with internal and external audit activities, including evidence collection, validation, coordination, and follow-up.

Partner with Engineering, Security, Product, Risk, and Quality teams to strengthen governance, risk, and compliance processes.

Monitor compliance metrics, service-level agreements, risks, corrective actions, and key control indicators.

Maintain accurate audit documentation and ensure processes remain audit-ready.

Develop dashboards, reports, and compliance metrics to provide visibility into control performance.

Support continuous improvement initiatives related to security governance, risk management, and operational resilience.

Requirements:

We are looking for a detail-oriented professional with experience in IT compliance, controls, audits, and security governance. The ideal candidate has strong analytical abilities, understands technology risk frameworks, and can effectively collaborate with multiple stakeholders.

2–4 years of experience in IT Compliance, IT Audit, IT General Controls (ITGC), Risk Management, Information Security Governance, Internal Controls, or Quality Management Systems (QMS).

Hands-on experience with ITGC and security controls, including access management, identity management, SDLC controls, change management, cybersecurity controls, and information security policies.

Experience supporting compliance initiatives involving SOC 2, ISO 27001, internal audits, evidence collection, audit coordination, and remediation tracking.

Knowledge of operational resilience practices, including business continuity, disaster recovery, vulnerability management, patch management, encryption, firewall controls, and logging and monitoring.

Familiarity with GRC platforms, evidence management tools, dashboards, and compliance reporting solutions.

Strong analytical, documentation, problem-solving, and stakeholder communication skills.

Proficiency with Microsoft Office tools and the ability to create clear reports and compliance documentation.

Ability to work collaboratively across technical and business teams in a fast-paced environment.

Benefits:

Fully remote work opportunity from anywhere in Brazil.

Opportunity to work with global teams on technology, security, and compliance initiatives.

Exposure to modern governance, risk, and compliance practices.

Collaborative environment with cross-functional teams across engineering, security, and product.

Professional growth opportunities within a global technology organization.

Experience supporting recognized security and compliance frameworks.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether? 

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1