Swap
Swap
201 – 500 Xodimlar
B2BBank ishiFintex
Swap bizneslar uchun Banking-as-a-Service va to‘lov infratuzilmasiga ixtisoslashgan Braziliya fintech kompaniyasidir. Uning platformasi kompaniyalarga karta chiqarish va qayta ishlash, PJ va PF raqamli hisoblari, Pix, Boleto va TED to‘lov kanallari, API’lar hamda kOD talab qilmaydigan white-label portallar orqali o‘z brendi ostidagi moliyaviy mahsulotlarni ishga tushirish va boshqarish imkonini beradi. Swap, shuningdek, avtopark va yoqilg‘i kartalari, agrobiznes, ish haqi avanslari, korporativ kartalar, ERP bankingi va sayohat kabi foydalanish holatlariga moslashtirilgan integratsiyalar bilan birga KYC, firibgarlikning oldini olish va me’yoriy talablarga muvofiqlik imkoniyatlarini taqdim etadi. Kompaniya asosan B2B hamkorliklari orqali ishlaydi va kompaniyalarga o‘z brendlari ostida mahsulotlar yaratish uchun zarur bo‘lgan operatsion vositalar bilan moliyaviy infratuzilmani birlashtiradi.

Senior Privacy and Data Protection Analyst

Senior privacy and data protection role at Swap, a Brazilian B2B Banking as a Service provider. Focus on LGPD, GRC, audits, and regulatory compliance.

Tavsif

  • Build and continuously improve Swap’s privacy and personal data protection program.
  • Ensure compliance with Brazil’s LGPD and other applicable legal, regulatory, and contractual requirements.
  • Maintain personal data inventories and processing records, covering purposes, legal bases, sharing, retention, and disposal.
  • Assess privacy risks and prepare or coordinate Data Protection Impact Assessments (DPIAs).
  • Help handle data subject rights requests and other privacy matters.
  • Review new products, projects, processes, integrations, and vendors, embedding privacy requirements from the outset.
  • Help manage personal data incidents, including impact assessments, documentation, and applicable communications and notifications.
  • Promote privacy awareness and data protection training.
  • Help develop the GRC program by connecting regulatory requirements, enterprise risks, and Information Security controls.
  • Identify, assess, document, and monitor risks, control gaps, action plans, and supporting evidence.
  • Maintain risk and control matrices, tracking owners, deadlines, metrics, and corrective actions.
  • Help maintain and improve the Information Security Management System (ISMS) in line with ISO 27001.
  • Track regulatory requirements, including those of the Central Bank of Brazil, alongside customer, partner, and contractual obligations.
  • Support third-party risk management (TPRM).
  • Plan, coordinate, and track internal and external audits, independent assessments, and certification processes.
  • Organize and maintain evidence for Central Bank of Brazil, PCI DSS, ISO 27001, and other applicable compliance audits.
  • Coordinate evidence gathering and control questions among internal teams, auditors, consultants, and other stakeholders.
  • Track audit findings, nonconformities, recommendations, and remediation plans through resolution.
  • Evaluate control effectiveness and identify improvement opportunities and remaining risks.
  • Help respond to security questionnaires, customer assessments, and requests for compliance evidence.
  • Manage corporate policies, standards, procedures, and guidelines from drafting through approval, publication, review, and communication.
  • Keep documentation aligned with regulatory requirements, internal policies, and Information Security practices.
  • Maintain document governance, including version history, ownership, review schedules, and approvals.
  • Help teams define corporate procedures and controls.
  • Monitor policy adherence and help manage deviations and exceptions.

Talablar

  • Bachelor’s degree in Information Security, Law, Business Administration, Information Systems, Risk Management, or a related discipline.
  • Substantial privacy and data protection experience, including hands-on implementation and maintenance of LGPD compliance programs.
  • Applied knowledge of personal data mapping, legal bases, processing records, and privacy risk assessments.
  • Experience preparing DPIAs and assessing risks tied to personal data processing.
  • Experience with GRC, risk management, internal controls, action plans, and process governance.
  • Experience preparing for and supporting internal and external audits, including gathering and validating evidence.
  • Knowledge of standards and frameworks such as ISO 27001, ISO 27701, and PCI DSS, plus financial-sector regulations.
  • Experience drafting corporate policies, standards, and procedures and managing their lifecycle.
  • Ability to work across Technical, Legal, Compliance, Product, Operations, Engineering, and vendor teams.
  • Strong written and spoken communication, organization, independence, and ability to manage several initiatives at once.
  • Experience in fintech, payment institutions, Banking as a Service (BaaS), or regulated financial services is an advantage.
  • Experience with Central Bank of Brazil audits and requirements, including Pix, cybersecurity, and outsourcing of relevant services, is an advantage.
  • Experience implementing or maintaining an ISMS and preparing for ISO 27001 certification is an advantage.
  • Knowledge of SOC 2, ISO 27701, and risk management frameworks is an advantage.
  • Experience with TPRM, vendor assessments, and reviewing security and privacy contract terms is an advantage.
  • Familiarity with GRC and document management tools, process automation, and evidence tracking is an advantage.
  • Experience defining risk, compliance, and privacy metrics and executive reports is an advantage.

Imtiyozlar

  • SulAmérica health coverage for employees and dependents, with no monthly premium or copayment.
  • SulAmérica dental coverage with no monthly premium or copayment.
  • Flexible meal and food allowance card.
  • Childcare support for parents of children up to 5 years and 11 months old.
  • Financial support for parents of children with disabilities.
  • Prudential group life insurance.
  • Wellhub partnership.
  • Onhappy leisure travel partnership.
  • Variable compensation program, depending on department and role.

O‘xshash ish o‘rinlari

Kreato Global | BPO and Language Solutions

Remote English-Spanish OPI/VRI Interpreter

Kreato Global | BPO and Language Solutions

Interpret remotely between English- and Spanish-speaking people in medical, financial, social service, and customer care settings. Provide language support for Kreato Global across Latin America.

Ochish
RecruitGo

Remote Executive Assistant, Outreach and Marketing — Philippines

RecruitGo
51 – 200 Xodimlar
KonsaltingLogistikaMarketing

Handle administrative support, CRM, outreach, and marketing for RecruitGo, an Employer of Record serving global clients with talent from emerging markets. Support two UK-facing clients with day-to-day administration and creative campaigns.

Ochish