Cybersecurity Analyst

Posted 1hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Analista de Cibersegurança responsável por avaliações de risco e gestão de segurança da informação em modelo remoto. Atuação em governança, risco e compliance com equipes internas e externas.

Responsibilities:

  • Conduct risk assessments of vendors and third-party partners.
  • Evaluate security controls implemented by third parties and identify potential vulnerabilities.
  • Ensure adherence to corporate information security and risk management policies.
  • Identify, document and track mitigation plans for identified risks.
  • Collaborate with the GRC team in managing information security risks.
  • Review evidence, certifications and compliance attestations from vendors.
  • Assess alignment with industry frameworks and best practices, including NIST.
  • Support the implementation and monitoring of security controls.
  • Participate in contract reviews between the company and vendors, ensuring information security requirements are included and followed.
  • Work closely with Legal and Procurement teams to mitigate contractual risks related to security.
  • Prepare executive reports and technical opinions on identified risks.
  • Present assessment results to business areas, managers and stakeholders.
  • Support risk-based decision making by providing mitigation recommendations.
  • Assist with concurrent investigations of security incidents.
  • Contribute to threat and vulnerability monitoring activities.
  • Produce incident reports and support senior teams in the analysis and remediation of occurrences.

Requirements:

  • Experience in Information Security, Governance, Risk or Compliance.
  • Knowledge of Third-Party Risk Management (TPRM).
  • Experience conducting risk assessments and analyzing security controls.
  • Knowledge of security frameworks, especially: NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001 (desired).
  • Knowledge of Governance, Risk and Compliance (GRC) processes.
  • Experience preparing risk reports and documentation.
  • Ability to communicate with both technical and non-technical stakeholders.
  • Knowledge of vulnerability management and security incident concepts.

Benefits:

  • Remote work