Swap
Swap
201 – 500 Zaposleni
B2BBančništvoFintech
Swap je brazilsko fintech podjetje, osredotočeno na Banking-as-a-Service in plačilno infrastrukturo za podjetja. Njegova platforma podjetjem pomaga zagnati in upravljati finančne produkte z lastno blagovno znamko z izdajanjem in obdelavo kartic, digitalnimi računi PJ in PF, plačilnimi sistemi Pix, Boleto in TED, API-ji ter white-label portali brez programiranja. Swap zagotavlja tudi zmogljivosti za KYC, preprečevanje goljufij in skladnost z regulativnimi zahtevami ter integracije, prilagojene primerom uporabe, kot so kartice za vozne parke in gorivo, agroposlovanje, predplačila plač, poslovne kartice, bančništvo v sistemih ERP in potovanja. Podjetje deluje predvsem prek partnerstev B2B ter združuje operativna orodja in finančno infrastrukturo, ki jo podjetja potrebujejo za razvoj produktov pod lastnimi blagovnimi znamkami.

Senior Privacy and Data Protection Analyst

Senior privacy and data protection role at Swap, a Brazilian B2B Banking as a Service provider. Focus on LGPD, GRC, audits, and regulatory compliance.

Opis

  • Build and continuously improve Swap’s privacy and personal data protection program.
  • Ensure compliance with Brazil’s LGPD and other applicable legal, regulatory, and contractual requirements.
  • Maintain personal data inventories and processing records, covering purposes, legal bases, sharing, retention, and disposal.
  • Assess privacy risks and prepare or coordinate Data Protection Impact Assessments (DPIAs).
  • Help handle data subject rights requests and other privacy matters.
  • Review new products, projects, processes, integrations, and vendors, embedding privacy requirements from the outset.
  • Help manage personal data incidents, including impact assessments, documentation, and applicable communications and notifications.
  • Promote privacy awareness and data protection training.
  • Help develop the GRC program by connecting regulatory requirements, enterprise risks, and Information Security controls.
  • Identify, assess, document, and monitor risks, control gaps, action plans, and supporting evidence.
  • Maintain risk and control matrices, tracking owners, deadlines, metrics, and corrective actions.
  • Help maintain and improve the Information Security Management System (ISMS) in line with ISO 27001.
  • Track regulatory requirements, including those of the Central Bank of Brazil, alongside customer, partner, and contractual obligations.
  • Support third-party risk management (TPRM).
  • Plan, coordinate, and track internal and external audits, independent assessments, and certification processes.
  • Organize and maintain evidence for Central Bank of Brazil, PCI DSS, ISO 27001, and other applicable compliance audits.
  • Coordinate evidence gathering and control questions among internal teams, auditors, consultants, and other stakeholders.
  • Track audit findings, nonconformities, recommendations, and remediation plans through resolution.
  • Evaluate control effectiveness and identify improvement opportunities and remaining risks.
  • Help respond to security questionnaires, customer assessments, and requests for compliance evidence.
  • Manage corporate policies, standards, procedures, and guidelines from drafting through approval, publication, review, and communication.
  • Keep documentation aligned with regulatory requirements, internal policies, and Information Security practices.
  • Maintain document governance, including version history, ownership, review schedules, and approvals.
  • Help teams define corporate procedures and controls.
  • Monitor policy adherence and help manage deviations and exceptions.

Zahteve

  • Bachelor’s degree in Information Security, Law, Business Administration, Information Systems, Risk Management, or a related discipline.
  • Substantial privacy and data protection experience, including hands-on implementation and maintenance of LGPD compliance programs.
  • Applied knowledge of personal data mapping, legal bases, processing records, and privacy risk assessments.
  • Experience preparing DPIAs and assessing risks tied to personal data processing.
  • Experience with GRC, risk management, internal controls, action plans, and process governance.
  • Experience preparing for and supporting internal and external audits, including gathering and validating evidence.
  • Knowledge of standards and frameworks such as ISO 27001, ISO 27701, and PCI DSS, plus financial-sector regulations.
  • Experience drafting corporate policies, standards, and procedures and managing their lifecycle.
  • Ability to work across Technical, Legal, Compliance, Product, Operations, Engineering, and vendor teams.
  • Strong written and spoken communication, organization, independence, and ability to manage several initiatives at once.
  • Experience in fintech, payment institutions, Banking as a Service (BaaS), or regulated financial services is an advantage.
  • Experience with Central Bank of Brazil audits and requirements, including Pix, cybersecurity, and outsourcing of relevant services, is an advantage.
  • Experience implementing or maintaining an ISMS and preparing for ISO 27001 certification is an advantage.
  • Knowledge of SOC 2, ISO 27701, and risk management frameworks is an advantage.
  • Experience with TPRM, vendor assessments, and reviewing security and privacy contract terms is an advantage.
  • Familiarity with GRC and document management tools, process automation, and evidence tracking is an advantage.
  • Experience defining risk, compliance, and privacy metrics and executive reports is an advantage.

Ugodnosti

  • SulAmérica health coverage for employees and dependents, with no monthly premium or copayment.
  • SulAmérica dental coverage with no monthly premium or copayment.
  • Flexible meal and food allowance card.
  • Childcare support for parents of children up to 5 years and 11 months old.
  • Financial support for parents of children with disabilities.
  • Prudential group life insurance.
  • Wellhub partnership.
  • Onhappy leisure travel partnership.
  • Variable compensation program, depending on department and role.

Sorodna delovna mesta

Ambush

Senior Machine Learning and AI Engineer

Ambush

Build production-grade generative AI and agent workflows for Ambush’s financial services clients. Develop Python and FastAPI services, SQL data workflows, retrieval-augmented generation, and cloud-based AI systems.

Odpri
GFN

Senior Software Engineer, Machine Learning

GFN
201 – 500 Zaposleni
E-trgovinaFintechSaaS

Build backend infrastructure and AI-enabled learning products for GFN, a German education provider. Develop scalable educational platforms with a focus on robust software architecture and practical machine learning.

Odpri
OPENLANE

Senior iOS Engineer, AI-First

OPENLANE
1001 – 5000 Zaposleni
Avtomobilska industrijaB2BTržnica

Build AI-assisted iOS apps for buyers and sellers in OPENLANE’s digital vehicle marketplace. Guide SwiftUI and UIKit architecture, testing, releases, and collaboration with Android and other teams.

Odpri