Swap
Swap
201 – 500 Darbinieki
B2BBanku darbībaFintech
Swap ir Brazīlijas finanšu tehnoloģiju uzņēmums, kas koncentrējas uz Banking-as-a-Service risinājumiem un maksājumu infrastruktūru uzņēmumiem. Tā platforma palīdz uzņēmumiem ieviest un pārvaldīt finanšu produktus ar savu zīmolu, nodrošinot karšu izsniegšanu un apstrādi, uzņēmumu un privātpersonu digitālos kontus, Pix, Boleto un TED maksājumu kanālus, API un bezkoda white-label portālus. Swap nodrošina arī KYC, krāpšanas novēršanas un normatīvo prasību ievērošanas iespējas, kā arī konkrētiem lietošanas scenārijiem pielāgotas integrācijas, piemēram, autoparku un degvielas kartēm, lauksaimniecības nozarei, algas avansiem, uzņēmumu kartēm, ERP banku pakalpojumiem un ceļošanai. Uzņēmums galvenokārt darbojas B2B partnerību veidā, apvienojot operatīvos rīkus un finanšu infrastruktūru, kas uzņēmumiem nepieciešama produktu izveidei ar savu zīmolu.

Senior Privacy and Data Protection Analyst

Senior privacy and data protection role at Swap, a Brazilian B2B Banking as a Service provider. Focus on LGPD, GRC, audits, and regulatory compliance.

Apraksts

  • Build and continuously improve Swap’s privacy and personal data protection program.
  • Ensure compliance with Brazil’s LGPD and other applicable legal, regulatory, and contractual requirements.
  • Maintain personal data inventories and processing records, covering purposes, legal bases, sharing, retention, and disposal.
  • Assess privacy risks and prepare or coordinate Data Protection Impact Assessments (DPIAs).
  • Help handle data subject rights requests and other privacy matters.
  • Review new products, projects, processes, integrations, and vendors, embedding privacy requirements from the outset.
  • Help manage personal data incidents, including impact assessments, documentation, and applicable communications and notifications.
  • Promote privacy awareness and data protection training.
  • Help develop the GRC program by connecting regulatory requirements, enterprise risks, and Information Security controls.
  • Identify, assess, document, and monitor risks, control gaps, action plans, and supporting evidence.
  • Maintain risk and control matrices, tracking owners, deadlines, metrics, and corrective actions.
  • Help maintain and improve the Information Security Management System (ISMS) in line with ISO 27001.
  • Track regulatory requirements, including those of the Central Bank of Brazil, alongside customer, partner, and contractual obligations.
  • Support third-party risk management (TPRM).
  • Plan, coordinate, and track internal and external audits, independent assessments, and certification processes.
  • Organize and maintain evidence for Central Bank of Brazil, PCI DSS, ISO 27001, and other applicable compliance audits.
  • Coordinate evidence gathering and control questions among internal teams, auditors, consultants, and other stakeholders.
  • Track audit findings, nonconformities, recommendations, and remediation plans through resolution.
  • Evaluate control effectiveness and identify improvement opportunities and remaining risks.
  • Help respond to security questionnaires, customer assessments, and requests for compliance evidence.
  • Manage corporate policies, standards, procedures, and guidelines from drafting through approval, publication, review, and communication.
  • Keep documentation aligned with regulatory requirements, internal policies, and Information Security practices.
  • Maintain document governance, including version history, ownership, review schedules, and approvals.
  • Help teams define corporate procedures and controls.
  • Monitor policy adherence and help manage deviations and exceptions.

Prasības

  • Bachelor’s degree in Information Security, Law, Business Administration, Information Systems, Risk Management, or a related discipline.
  • Substantial privacy and data protection experience, including hands-on implementation and maintenance of LGPD compliance programs.
  • Applied knowledge of personal data mapping, legal bases, processing records, and privacy risk assessments.
  • Experience preparing DPIAs and assessing risks tied to personal data processing.
  • Experience with GRC, risk management, internal controls, action plans, and process governance.
  • Experience preparing for and supporting internal and external audits, including gathering and validating evidence.
  • Knowledge of standards and frameworks such as ISO 27001, ISO 27701, and PCI DSS, plus financial-sector regulations.
  • Experience drafting corporate policies, standards, and procedures and managing their lifecycle.
  • Ability to work across Technical, Legal, Compliance, Product, Operations, Engineering, and vendor teams.
  • Strong written and spoken communication, organization, independence, and ability to manage several initiatives at once.
  • Experience in fintech, payment institutions, Banking as a Service (BaaS), or regulated financial services is an advantage.
  • Experience with Central Bank of Brazil audits and requirements, including Pix, cybersecurity, and outsourcing of relevant services, is an advantage.
  • Experience implementing or maintaining an ISMS and preparing for ISO 27001 certification is an advantage.
  • Knowledge of SOC 2, ISO 27701, and risk management frameworks is an advantage.
  • Experience with TPRM, vendor assessments, and reviewing security and privacy contract terms is an advantage.
  • Familiarity with GRC and document management tools, process automation, and evidence tracking is an advantage.
  • Experience defining risk, compliance, and privacy metrics and executive reports is an advantage.

Priekšrocības

  • SulAmérica health coverage for employees and dependents, with no monthly premium or copayment.
  • SulAmérica dental coverage with no monthly premium or copayment.
  • Flexible meal and food allowance card.
  • Childcare support for parents of children up to 5 years and 11 months old.
  • Financial support for parents of children with disabilities.
  • Prudential group life insurance.
  • Wellhub partnership.
  • Onhappy leisure travel partnership.
  • Variable compensation program, depending on department and role.

Saistītās vakances

Terumo Medical Corporation

Region Manager, Terumo Interventional Systems Sales

Terumo Medical Corporation

Lead medical device sales across a North Central New Jersey region, managing field teams and hospital relationships. Drive regional revenue, sales performance, and compliant promotion of Terumo Interventional Systems products.

Atvērt