Analista de Programa de Compliance PL
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Analista de Programa de Compliance PL based in Brazil.
This role focuses on ensuring technology processes, controls, and operational practices remain aligned with compliance, security, and quality standards.
The professional will collaborate with IT product teams, risk management areas, auditors, and internal stakeholders to support audit readiness and continuous improvement.
You will contribute to identifying risks, validating controls, reviewing evidence, and strengthening governance frameworks.
The position requires a balance of analytical skills, technical knowledge, and attention to regulatory requirements.
You will work in a structured environment where your expertise helps maintain reliable, secure, and compliant technology operations.
This is an opportunity to support critical compliance initiatives while developing expertise across IT governance, risk, and auditing practices.
Accountabilities:
The professional will support compliance programs by evaluating technology controls, assisting audit processes, and ensuring teams follow established governance and security practices. The role involves analyzing risks, validating evidence, and partnering with different teams to improve compliance maturity.
- Collaborate with IT product teams, security areas, risk management teams, and auditors to maintain compliance readiness.
- Support internal and external audit activities, from preparation and evidence collection to remediation tracking.
- Perform IT General Controls (ITGC) testing, including access management, change management, operations, SDLC, and resilience controls.
- Execute and support Quality Management System (QMS) control testing through walkthroughs, sampling, re-performance, and inspection activities.
- Review security policies, control frameworks, and governance requirements to ensure alignment with compliance standards.
- Identify, document, and escalate compliance and operational risks across technology environments.
- Validate evidence related to security controls, vulnerability assessments, penetration testing activities, and monitoring processes.
- Support continuous improvement initiatives related to compliance processes, reporting, and control effectiveness.
- Bachelor’s degree in Administration, Information Technology, Information Security, Risk Management, or related fields.
- 2 to 4 years of experience in compliance, IT auditing, ITGC testing, QMS testing, or risk management, preferably in regulated technology environments.
- Strong knowledge of compliance frameworks such as SOC 2, ISO 27001, and related control standards.
- Experience conducting audits, validating evidence, and supporting remediation activities.
- Practical experience with ITGC methodologies, including walkthroughs, sample-based testing, re-performance, and inspection.
- Knowledge of information security policies, governance frameworks, and control structures.
- Familiarity with access control systems, identity management, encryption standards, and change management workflows.
- Experience using Microsoft Office, GRC platforms, evidence management tools, reporting tools, and compliance dashboards.
- Ability to analyze risks, communicate findings clearly, and collaborate with multidisciplinary teams.
- CISA (Certified Information Systems Auditor).
- CRISC (Certified in Risk and Information Systems Control).
- ISO 27001 Lead Auditor certification.
- ISO 42001 or related Quality Management System certifications.
- Training or certifications focused on IT General Controls.
- Remote work model.
- Opportunity to work on compliance, risk, and technology governance initiatives.
- Exposure to international security and audit frameworks.
- Professional development in IT compliance, risk management, and information security.
- Collaboration with multidisciplinary teams in a structured technology environment.
Requirements:
The ideal candidate has experience in compliance, IT auditing, risk management, or technology governance, with strong knowledge of security frameworks and control validation methodologies. The professional should be analytical, organized, and comfortable working with multiple stakeholders.
Preferred certifications and qualifications:
Benefits:
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1