Cybersecurity Analyst
Posted 1hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Analista de Cibersegurança responsável por avaliações de risco e gestão de segurança da informação em modelo remoto. Atuação em governança, risco e compliance com equipes internas e externas.
Responsibilities:
- Conduct risk assessments of vendors and third-party partners.
- Evaluate security controls implemented by third parties and identify potential vulnerabilities.
- Ensure adherence to corporate information security and risk management policies.
- Identify, document and track mitigation plans for identified risks.
- Collaborate with the GRC team in managing information security risks.
- Review evidence, certifications and compliance attestations from vendors.
- Assess alignment with industry frameworks and best practices, including NIST.
- Support the implementation and monitoring of security controls.
- Participate in contract reviews between the company and vendors, ensuring information security requirements are included and followed.
- Work closely with Legal and Procurement teams to mitigate contractual risks related to security.
- Prepare executive reports and technical opinions on identified risks.
- Present assessment results to business areas, managers and stakeholders.
- Support risk-based decision making by providing mitigation recommendations.
- Assist with concurrent investigations of security incidents.
- Contribute to threat and vulnerability monitoring activities.
- Produce incident reports and support senior teams in the analysis and remediation of occurrences.
Requirements:
- Experience in Information Security, Governance, Risk or Compliance.
- Knowledge of Third-Party Risk Management (TPRM).
- Experience conducting risk assessments and analyzing security controls.
- Knowledge of security frameworks, especially: NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001 (desired).
- Knowledge of Governance, Risk and Compliance (GRC) processes.
- Experience preparing risk reports and documentation.
- Ability to communicate with both technical and non-technical stakeholders.
- Knowledge of vulnerability management and security incident concepts.
Benefits:
- Remote work


















