Description
Job Summary:
Ensure cloud compliance by guaranteeing that processes, technologies, and personnel meet security, privacy, and regulatory requirements.
Key Highlights:
1. Cloud risk and compliance management.
2. Conducting internal and external security and privacy audits.
3. Providing advisory support for projects with security and privacy impact.
Description: Ensure the maintenance and health of compliance in the Cloud domain, guaranteeing that processes, technologies, and personnel comply with all applicable security, privacy, legal, and regulatory requirements.
Responsibilities and Duties
* Manage risks related to the Management System (MS) using methodologies based on industry best practices;
* Execute control and monitoring of registered risk treatments, following internally defined methodologies aligned with industry standards;
* Prepare reports and presentations adhering to best practices, internal methodologies, and templates;
* Conduct and measure periodic Security and Privacy awareness activities in Cloud through trainings, informational materials, interactive sessions with employees, and/or other internally defined methods;
* Develop and maintain up-to-date compliance documentation (including MS maintenance), following market best practices, internal methodologies, and templates;
* Implement adherence to standards, laws, and regulations by performing periodic analyses and measurements based on industry best practices, including recording and monitoring findings and their resolutions;
* Conduct internal and external audits, coordinating and facilitating interviews between auditors and internal departments, and responding to queries regarding MS requirements;
* Support Cloud customer audits focused on information security and privacy, providing guidance and evidence per internal procedures;
* Address customer inquiries and questionnaires regarding Cloud security and privacy, handling requests and incidents via official support and communication channels;
* Execute compliance alignment activities for processes and environments (new or existing) by engaging, guiding, and directing Cloud teams;
* Provide advisory support for cross-departmental projects potentially impacting any security and/or privacy controls, based on industry best practices;
* Handle departmental requests using service and activity management tools;
* Review contracts and proposals, assessing the applicability of security and privacy clauses;
* Document how controls and requirements conform to applicable standards.
* Evaluate contractual clauses involving Cloud-related Security and Privacy topics, as well as draft terms and other necessary documentation.
Requirements and Qualifications
* Lei Geral de Proteção de Dados (LGPD);
* General Data Protection Regulation (GDPR) \- Familiarity;
* Cybersecurity;
* ISO 27001;
* ISO 27701;
* SOC 1;
* Information Security and/or Privacy Audits;
* CIS Controls;
* Cloud Security Alliance;
* Cloud Services;
* BACEN Regulation.
2512050202181904269