Analista de Segurança da Informação
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Analista de Segurança da Informação based in Brazil.
This is a strategic opportunity for an Information Security professional to play a central role in the implementation and ongoing management of an Information Security Management System (ISMS/SGSI). You will act as a key internal point of contact throughout the ISO/IEC 27001 certification journey. The role connects Information Security, Technology, Legal, Compliance, HR, leadership, and external consulting partners. You will translate regulatory and security requirements into practical controls, processes, documentation, and evidence. The position offers broad exposure to governance, risk, compliance, audits, and security frameworks. It is particularly suited to a senior professional who is organized, analytical, collaborative, and comfortable coordinating multiple stakeholders and deadlines.
Accountabilities:
- Act as the primary internal point of contact with the external consulting partner supporting the ISO/IEC 27001 certification project.
- Support the implementation, evolution, maintenance, and continuous improvement of the Information Security Management System (SGSI).
- Interpret ISO/IEC 27001 requirements and translate them into actionable security processes, controls, policies, and procedures.
- Lead and monitor gap analyses, risk assessments, remediation plans, controls, and certification-related action plans.
- Support the creation, review, and continuous improvement of Information Security policies, standards, procedures, and related documentation.
- Coordinate the preparation, organization, and maintenance of documentation and evidence required for internal and external audits.
- Support internal and external audits, including the management of findings, non-conformities, corrective actions, and remediation activities.
- Promote effective collaboration between Information Security, IT, Legal, Compliance, HR, leadership, and other business functions.
- Monitor security and certification indicators, deadlines, risks, action plans, and overall progress toward ISO/IEC 27001 readiness and certification.
- Ensure appropriate tracking and visibility of security governance activities and provide clear updates to relevant stakeholders.
- Contribute to the continuous strengthening of security governance, risk management, compliance, and information protection practices.
- Bachelor’s degree in Technology, Information Security, Information Systems, Computer Science, Engineering, Business Administration, or a related field.
- Proven professional experience in Information Security, Governance, Risk & Compliance (GRC), and/or Security Compliance.
- Strong hands-on experience with ISO/IEC 27001, particularly implementation, compliance, certification, maintenance, or recertification initiatives.
- Solid understanding of Information Security Management Systems (SGSI/ISMS) and Information Security controls.
- Practical experience conducting gap assessments, managing information security risks, and developing and tracking remediation plans.
- Experience preparing audit evidence and supporting internal and external security or compliance audits.
- Strong organizational and project coordination skills, with the ability to manage multiple activities, stakeholders, risks, and deadlines simultaneously.
- Analytical and problem-solving mindset, with strong attention to detail and the ability to translate requirements into practical actions.
- Excellent communication and stakeholder management skills, particularly when working across technical and non-technical teams.
- Ability to work independently, take ownership, and operate effectively in a multidisciplinary environment.
- ISO/IEC 27001 Lead Implementer, Lead Auditor, or Internal Auditor certification is a strong advantage.
- Knowledge of ISO/IEC 27005, NIST, CIS Controls, and/or COBIT is desirable.
- Familiarity with LGPD and data privacy principles is a plus.
- Experience using GRC platforms or tools is advantageous.
- Experience working in organizations that have undergone ISO/IEC 27001 certification processes is highly valued.
- CLT employment contract.
- 100% remote work model within Brazil.
- Flexible working hours focused on deliverables and outcomes.
- Meal and food allowances through VA and VR.
- Health insurance.
- Digital healthcare/hospital services.
- Dental plan.
- Wellhub membership.
- Sesc partnership.
- Life insurance.
- Funeral assistance.
- Opportunity to play a key role in an ISO/IEC 27001 certification and Information Security governance journey.
- Exposure to multidisciplinary stakeholders and strategic GRC initiatives.
- Professional development opportunities in Information Security, compliance, risk management, and security frameworks.
Requirements:
Benefits:
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1