Senior GRC Analyst, IT Controls
Posted 16ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Analyst at Arco Educação focusing on GRC and risk management in cybersecurity. Leading audits, governance, and improving data security processes in a dynamic education technology environment.
Responsibilities:
- Continuous Information Security audit (Design and Operating Effectiveness testing): perform periodic technical tests to validate that designed security controls are operating as intended;
- Data Governance and Technical Autonomy: contribute to the company's data governance;
- Maturity and Gap Management (CIS/NIST): lead maturity assessments, identify gaps, define remediation priorities, and act as escalation point for high‑risk blockers with technical teams;
- Vulnerability Management: manage cyber risk based on CSPM events and vulnerability scanners;
- Audit Support: act as the technical focal point for external and internal audits, organizing evidence and translating audit requirements for technical teams;
- Data Protection (DLP/Classification): audit and enforce the correct implementation of DLP controls and adherence to the data classification policy across complex Data Lake and multi‑database environments;
- Process Improvement;
- Tracking and monitoring action plans.
Requirements:
- Strong GRC and Risk knowledge: familiarity with risk analysis methodologies (ISO 31000, ISO 27005, quantitative and qualitative approaches);
- Hands‑on experience in database security, Data Lakes, and cloud security architecture (AWS/GCP);
- Framework expertise: solid practical knowledge of CIS Controls (v8) and NIST CSF;
- Understanding of ISO 27001/27002;
- Technical and audit background (Tests of Design and Tests of Effectiveness — ToD/ToE);
- Productivity tools: advanced Excel/Google Sheets and familiarity with Jira.
Benefits:
- Meal and/or food allowance
- Health and dental insurance
- Transportation allowance
- Extended maternity and paternity leave
- Childcare assistance
- Employee well‑being: partnerships with Wellhub and Zenklub
- Education support/incentives
- Discounts on airline tickets
- Partnership for pet health insurance
- Access to Arco educational materials for employees' children
- Partnerships for MBA and postgraduate programs


















