RecargaPay
RecargaPay
RecargaPay este o companie braziliană de plăți și finanțe digitale, care oferă o platformă unică pentru tranzacții cotidiene și servicii financiare. Clienții pot plăti facturi, pot reîncărca telefoane mobile și carduri de transport, pot cumpăra carduri cadou și pot efectua plăți Pix cu un card de credit. Platforma include și un portofel digital, cashback și împrumuturi mici. Pentru companii, RecargaPay oferă conturi de afaceri, procesarea plăților și servicii de marketing. Fondată în 2010, compania activează în domeniul finanțelor pentru consumatori și al plăților pentru companii.

Senior Security Governance Analyst — Brazil (Remote)

Lead security governance for RecargaPay’s digital payments and credit business, maintaining ISO 27001, ISO 22301, and PCI DSS certifications. Manage GRC, regulatory compliance, audits, third-party risk, and business continuity.

Descriere

  • Maintain ISO 27001, ISO 22301, and PCI DSS certifications by managing annual scope, controls, evidence, certification audits, and nonconformities.
  • Map requirements from CMN Resolution 4,893 and BCB Resolution 85 to controls, track regulatory changes, and report gaps and action plans to leadership.
  • Manage the Information Security Management System, including risk, metrics, management reviews, internal audits, and continual improvement.
  • Develop and maintain security policies, standards, and procedures, with defined review cycles and effective adoption across teams.
  • Assess suppliers, partners, and acquisitions through security due diligence, criticality ratings, questionnaire and evidence reviews, and ongoing third-party risk monitoring.
  • Manage business continuity, including business impact analyses, continuity and recovery plans, and regular tests and exercises with responsible teams.
  • Plan and deliver security awareness and engagement programs, including training, campaigns, and effectiveness metrics.
  • Support internal and external audits by coordinating requests, evidence, and responses, and tracking findings through closure.

Cerințe

  • Senior-level experience in information security Governance, Risk, and Compliance (GRC), preferably in fintech, payments, or another regulated financial sector.
  • Hands-on experience maintaining an ISO 27001-aligned Information Security Management System and supporting certification, including certification audit cycles.
  • Strong knowledge of PCI DSS requirements and experience preparing evidence and supporting assessments.
  • Knowledge of Brazilian financial-sector cybersecurity and continuity regulations, including CMN Resolution 4,893 and BCB Resolution 85.
  • Experience managing third-party risk, including assessing suppliers and partners according to their criticality.
  • Experience supporting internal and external audits and working directly with auditors and regulators.
  • Preferred: experience with ISO 22301 and business continuity management, including business impact analyses, plans, and testing.
  • Preferred: knowledge of SOX and IT general controls (ITGC).
  • Preferred: certifications such as ISO 27001 Lead Implementer or Auditor, ISO 22301 Lead Implementer or Auditor, CISA, CISM, CRISC, or PCI ISA.
  • Preferred: experience with GRC tools and security awareness programs.
  • Fluent Portuguese and technical English for reading and writing documentation.

Beneficii

  • Competitive, market-aligned salary.
  • Remote work from anywhere.
  • Monthly home office allowance deposited in the RecargaPay app.
  • Health and dental plans with no co-pay.
  • Life insurance.
  • Flexible meal allowance through Flash.
  • TotalPass membership.
  • Competitive, market-aligned salary.
  • Remote work from anywhere.
  • Monthly home office allowance deposited in the RecargaPay app.
  • Health and dental plans with no co-pay.
  • Life insurance.
  • Flexible meal allowance through Flash.
  • TotalPass membership.

Locuri de muncă similare