Compliance Program Analyst (Mid-level)
Posted 1ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Analista de Compliance avaliando controles ITGC, SGQ e auditorias para empresa de tecnologia em São Paulo. Apoiando conformidade, validação de evidências e prontidão para auditorias.
Responsibilities:
- Partner with IT product teams, security and risk management areas, QMS owners, and internal and external auditors
- Assist teams in maintaining compliance and audit readiness
- Conduct audits and validate evidence from preparation through remediation
- Validate ITGC controls, including access controls, change management, operations, SDLC, and resilience
- Assess whether controls are designed and operating effectively
- Support or perform QMS control testing across global and territory-specific frameworks
- Interpret standards, assist teams in applying information security policies, and validate compliance
- Identify and escalate compliance and operational risks in the context of a portfolio
Requirements:
- Bachelor’s degree in Business Administration, Information Technology, Information Security, Risk Management, or a related field
- 2–4 years of experience in compliance, IT audit, ITGC testing, QMS testing, or risk management
- Solid knowledge of SOC 2, ISO 27001, and 7216
- Experience conducting audits and validating evidence from preparation through remediation
- Proven experience validating ITGC controls: access, change management, operations, SDLC, and resilience
- Experience supporting or executing QMS control testing
- Practical knowledge of information security policies and control frameworks, preferably PwC ISP
- Ability to identify and escalate compliance and operational risks
- Proficiency with control frameworks: SOC 2, ISO 27001, 7216, and ISP
- Experience with ITGC and QMS testing methodologies: walkthroughs, sampling, re-performance, and inspection
- Familiarity with vulnerability scanning tools, pentest evidence review, and security monitoring
- Proficiency in Microsoft Office, evidence-management platforms, GRC tools, and compliance reporting/dashboard tools
- Understanding of access control systems, identity management, encryption standards, and change management workflows
- Familiarity with global and territory-specific regulatory and quality management requirements
- Preferred certifications: CISA, CRISC, ISO 27001 Lead Auditor, ISO 42001 or other QMS-related certifications, and training or certifications specific to ITGC



















