IT Compliance Analyst

Posted 18hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Analista de Compliance de TI focado em validação de controles e aplicação de padrões de compliance da PwC. Atuando em projetos em mais de 21 países com responsabilidades em auditorias e gestão de riscos.

Responsibilities:

  • You will be a key member of the ATE Compliance Program, reporting directly to the Compliance Program Lead.
  • Your primary focus will be to develop a deep understanding of PwC's compliance standards and support teams in their correct application.
  • This role is centered on control validation, ensuring controls are well designed and operating effectively across ITGC, ISP and QMS domains.
  • You will be responsible for testing controls, reviewing evidence, facilitating audits, responding to requests, supporting escalations, and contributing to the evolution of controls.
  • Testing and validation of ITGC controls (primary focus).
  • Test and validate that ITGC controls are appropriately designed and operating as expected in the following areas: Access Controls, System Development and Change Management, Cybersecurity and Data Protection, and Service Management.
  • Validate controls related to: Identity and Access Management, Change Management, Cybersecurity Operations, and Database and Network Controls.
  • Facilitate audits and manage compliance evidence.
  • Support the handling of inquiries and escalations related to controls.
  • Contribute to discussions on control design and improvement.
  • Support remediation processes and continuous monitoring.
  • Interact with stakeholders and areas involved in the program.
  • Support communication of compliance and risk topics.
  • Prepare reports, metrics and data-driven analyses.
  • Support reviews of policies, procedures and access.

Requirements:

  • Knowledge of control frameworks such as SOC 2, ISO 27001, 7216 and ISP.
  • Experience with ITGC and QMS control testing methodologies (walkthroughs, sampling, re-performance, inspection).
  • Practical knowledge of information security policies (ISP) and control frameworks.
  • Proficiency in Microsoft Office, evidence management platforms, GRC tools and compliance dashboards.
  • Knowledge of: Access control systems, Identity management, Encryption standards, Change management processes, Familiarity with global and local regulatory requirements and quality management systems.
  • Risk-oriented mindset, with the ability to identify and escalate operational and compliance risks.
  • Familiarity with vulnerability scanning tools, penetration testing (pentest) and security monitoring.
  • Preferred: CISA (Certified Information Systems Auditor), CRISC (Certified in Risk and Information Systems Control), ISO 27001 Lead Auditor, ISO 42001 or QMS-related certifications, and certifications or trainings specific to ITGC.

Benefits:

  • Health insurance;
  • Dental insurance;
  • Meal allowance;
  • Food allowance;
  • Mobility allowance;
  • Cultural allowance;
  • Wellness allowance;
  • Education allowance;
  • Life insurance;
  • Childcare assistance;
  • Discounts with partner companies.