Grupo QuintoAndar | Information Security Manager - GRC
QuintoAndarJob Description
📋 Description Lead the Information Security GRC function within a Cybersecurity context. Define the GRC vision, structure practices, and drive end-to-end strategic initiatives. Collaborate with CISO and leadership to enable critical projects securely. Translate cyber risks into financial and operational impact using frameworks like FAIR. Oversee governance, risk management, and compliance across LGPD, SOX, GDPR. 🎯 Requirements 10+ years in Information Security GRC with 5+ years in leadership. Proven experience reporting to executives and influencing stakeholders. Expertise in NIST CSF 2.0, ISO 27001/27002, CIS Controls, ISO 31000; ITSM a plus. Ability to quantify cyber risk and its business impact; KPI/KRI framework experience. Experience with TPRM, incident response governance, and SOX ITGC. Fluency in Portuguese and advanced English; strong vendor/regulator engagement. 🎁 Benefits Competitive salary Profit sharing Health, dental, life insurance Home office allowance and wellbeing programs Parental leave and childcare subsidies Employee assistance and diversity inclusion initiatives