20h ago
Information Security Engineer - GRC
Brazil
โจ $140k-$180k / yearest.
full-timesenior Remote
๐ Tech Stack
๐ผ About This Role
You'll own and mature the trust foundation by operationalizing security controls and driving evidence collection and continuous monitoring. You'll partner with product, engineering, and business teams to reduce risk while enabling speed in a rapidly scaling fintech SaaS platform. You'll also lead SOC 2 Type II audit cycles and develop AI/ML risk assessment frameworks.
๐ฏ What You'll Do
- Baseline control library mapped to SOC 2, PCI DSS, and fintech obligations.
- Implement lightweight evidence collection pipelines for key controls.
- Lead SOC 2 Type II audit cycle end-to-end.
- Develop AI/ML risk assessment framework covering model governance.
๐ Requirements
- 5+ years in GRC, security engineering, or risk management within SaaS or fintech.
- Proven experience running SOC 2 Type II and working toward ISO 27001.
- Strong understanding of cloud security controls across AWS and containerized workloads.
- Ability to translate requirements into actionable, ticketed work with clear owners and due dates.
โจ Nice to Have
- Experience with privacy programs, PCI readiness, or financial services regulations.
- Relevant certifications (e.g., CISA, CISSP, ISO 27001 LI/LA, ISO 42001).
- Familiarity with AI/ML risk frameworks (e.g., NIST AI RMF, ISO 42001).
๐ Benefits & Perks
- ๐๏ธ Remote Flexibility
- ๐ข Home Office Setup budget
- ๐ฐ Stock Options
- โ๏ธ Work Trip Budget
- ๐๏ธ 20 PTO days plus national holidays
๐จ Hiring Process
Estimated timeline: 2-4 weeks ยท AI estimate
- 1Recruiter Screenยท 30 min
- 2Hiring Manager Interviewยท 60 min
- 3Technical Interviewยท 60 min
๐ฉ Heads Up
- Role may evolve as business needs change (scope creep potential).
- Contractor basis with no sponsorship.
0 0 0