Jobgether logo

Senior Information Security Risk and Controls Analyst

Jobgether

Brazil
Full-time
Senior
Salary not listedPosted 4d ago

Real job — pulled straight from Jobgether’s careers page · Verified October 4, 2026 · No reposts.

Job description

Jobgether is hiring a Senior Information Security Risk and Controls Analyst — a full-time, based in Brazil role. Apply directly on Jobgether's careers page below.

Analista de Riscos e Controles de Segurança da Informação Sênior

Team: IT

Location: Brazil

Commitment: Full-time

Workplace Type: remote

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Analista de Riscos e Controles de Segurança da Informação Sênior based in Brazil.

As a Senior Information Security Risk and Controls Analyst, you will play a key role in identifying, assessing, and treating information security risks across the organization. You will help strengthen security controls, evaluate their effectiveness, and drive remediation initiatives through to completion. The role also includes third-party risk management, security maturity assessments, and governance activities. You will work closely with Product, Engineering, Cloud, Compliance, and Legal teams to embed security and risk management into projects from the beginning. Your ability to investigate complex scenarios and translate technical risks into clear recommendations will support both operational and executive decision-making. This is a highly autonomous role in a collaborative, agile environment where technical expertise and attention to detail are valued.

Accountabilities:

    • Lead the end-to-end information security risk management lifecycle, including risk identification, analysis, evaluation, and treatment in accordance with ISO/IEC 27005.
    • Apply and continuously improve risk management methodologies, including qualitative probability-versus-impact matrices and, where appropriate, quantitative approaches such as FAIR.
    • Define and monitor risk treatment plans covering mitigation, transfer, acceptance, or avoidance, ensuring appropriate follow-up through formal closure or acceptance.
    • Maintain and test the information security controls framework, assessing control effectiveness, documenting exceptions, and monitoring corrective action plans.
    • Conduct security control maturity assessments and gap analyses based on frameworks such as ISO/IEC 27001/27002, NIST CSF, and CIS Controls.
    • Lead third-party and supplier risk assessments, including due diligence, criticality classification, and monitoring of contractual security requirements.
    • Develop and maintain risk and control indicators, including KRIs and KPIs, and prepare technical and executive-level reports to support decision-making.
    • Act as a technical advisor to Product, Engineering, Cloud, Compliance, and Legal teams, promoting security-by-design and risk mitigation throughout project development.
    • Support formal risk acceptance and exception management processes through appropriate documentation, governance, and periodic reviews.
    • Requirements:

      • Proven professional experience in information security risk management.
      • Strong practical and in-depth knowledge of ISO/IEC 27005, including risk identification, analysis, evaluation, probability and impact criteria, and treatment planning.
      • Solid understanding of ISO/IEC 27001/27002, NIST CSF, and CIS Controls and their relationship to information security risk management.
      • Experience with third-party risk management (TPRM), including supplier due diligence, criticality assessments, and contractual security requirements.
      • Demonstrated ability to design and perform control effectiveness testing, manage supporting evidence, and track remediation plans through completion.
      • Strong technical writing and communication skills, with the ability to translate complex security risks into clear language for executive and business audiences.
      • Strong organization, autonomy, analytical thinking, and senior-level judgment when handling complex assessments with limited supervision.
      • Bachelor's degree or equivalent professional background in information security, technology, risk management, or a related field is desirable.
      • Certifications such as ISO 27005 Risk Manager, CRISC, or ISO 27001 Lead Implementer/Auditor are desirable.
      • Experience with quantitative risk modeling, such as FAIR or equivalent methodologies, is a plus.
      • Experience in regulated environments, particularly financial or payment institutions subject to Central Bank of Brazil regulations, is a plus.
      • Ability to translate regulatory requirements into practical security and risk management processes is desirable.
      • Benefits:

        • Full-time CLT employment.
        • Monday to Friday schedule, 8 hours per day.
        • Fully remote/home-office work within Brazil.
        • Medical and dental insurance with no copay.
        • Life insurance.
        • Medication assistance.
        • Physical activity and wellness assistance.
        • Financial wellness support.
        • Four free monthly sessions with therapy or nutrition professionals.
        • Flexible food allowance through a Visa card.
        • Childcare assistance.
        • Parental support program.
        • Extended maternity and paternity leave.
        • Education assistance covering 70% of eligible undergraduate, language, course, and book expenses.
        • Access to professional training and development programs.
        • Home-office allowance and work equipment.
        • Furniture allowance for remote work.
        • Access to coworking spaces across Brazil.
        • Birthday Day Off.
        • Happy Hour allowance.
        • Employee referral bonuses.
        • Annual goal-based bonus opportunities.
        • Stock option plan.
        • Flexible, collaborative work environment with no formal dress code.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
 Why Apply Through Jobgether? 
 
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
 
 
#LI-CL1

Get Senior Information Security Risk and Controls Analyst jobs like this→

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
ELCA logo

ELCA

New

Cyber Security Manager

Saint-Pierre, Mauritius
✓ From careers page· 10h ago
Elevance Health logo

Cybersecurity Application Senior Advisor

Atlanta, GA
✓ From careers page· 11h ago
Vix Technology logo

Cyber Security Analyst

Manchester, England
✓ From careers page· 12h ago
Ecobank logo

Group Officer Cyber Security

Togo
✓ From careers page· 12h ago

Frequently asked questions

What skills are required for Senior Information Security Risk and Controls Analyst at Jobgether?

The required skills for Senior Information Security Risk and Controls Analyst at Jobgether include: ISO 27001.

What is the seniority level for Senior Information Security Risk and Controls Analyst at Jobgether?

Senior Information Security Risk and Controls Analyst at Jobgether is a Senior level position.

How do I apply for Senior Information Security Risk and Controls Analyst at Jobgether?

You can view the full description and apply for Senior Information Security Risk and Controls Analyst at Jobgether on EchoJobs: https://echojobs.io/job/jobgether-analista-de-riscos-e-controles-de-seguran-a-da-informa-o-s-nior-5yaax.