Compliance Program Analyst (Mid-level)

Posted 1ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Analista de Compliance avaliando controles ITGC, SGQ e auditorias para empresa de tecnologia em São Paulo. Apoiando conformidade, validação de evidências e prontidão para auditorias.

Responsibilities:

  • Partner with IT product teams, security and risk management areas, QMS owners, and internal and external auditors
  • Assist teams in maintaining compliance and audit readiness
  • Conduct audits and validate evidence from preparation through remediation
  • Validate ITGC controls, including access controls, change management, operations, SDLC, and resilience
  • Assess whether controls are designed and operating effectively
  • Support or perform QMS control testing across global and territory-specific frameworks
  • Interpret standards, assist teams in applying information security policies, and validate compliance
  • Identify and escalate compliance and operational risks in the context of a portfolio

Requirements:

  • Bachelor’s degree in Business Administration, Information Technology, Information Security, Risk Management, or a related field
  • 2–4 years of experience in compliance, IT audit, ITGC testing, QMS testing, or risk management
  • Solid knowledge of SOC 2, ISO 27001, and 7216
  • Experience conducting audits and validating evidence from preparation through remediation
  • Proven experience validating ITGC controls: access, change management, operations, SDLC, and resilience
  • Experience supporting or executing QMS control testing
  • Practical knowledge of information security policies and control frameworks, preferably PwC ISP
  • Ability to identify and escalate compliance and operational risks
  • Proficiency with control frameworks: SOC 2, ISO 27001, 7216, and ISP
  • Experience with ITGC and QMS testing methodologies: walkthroughs, sampling, re-performance, and inspection
  • Familiarity with vulnerability scanning tools, pentest evidence review, and security monitoring
  • Proficiency in Microsoft Office, evidence-management platforms, GRC tools, and compliance reporting/dashboard tools
  • Understanding of access control systems, identity management, encryption standards, and change management workflows
  • Familiarity with global and territory-specific regulatory and quality management requirements
  • Preferred certifications: CISA, CRISC, ISO 27001 Lead Auditor, ISO 42001 or other QMS-related certifications, and training or certifications specific to ITGC