SlipstreamJobsFresh Startup & VC-Backed Jobs

[Tecnologia] Gerente de Segurança da Informação| GRC e IAM

Contabilizei - São Paulo, SP, Brazil - Hybrid

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Contabilizei, a Brazilian accounting technology company, seeks an Information Security Manager to lead their GRC (Governance, Risk, and Compliance) and IAM (Identity and Access Management) team. This is a hybrid role based in São Paulo. You will be responsible for disseminating security culture across the organization and driving the development of your team while ensuring alignment with business objectives. Your day-to-day responsibilities include: **Leadership & Strategy**: Lead the GRC and IAM team, fostering a continuous security culture aligned with company goals. **Governance & Policies**: Develop, maintain, and update information security policies, standards, and procedures covering security, privacy, and access governance. **Risk & Compliance Management**: Conduct security risk analyses, map operational vulnerabilities, and ensure compliance with regulations including LGPD, ISO/IEC 27001, SOC 2, and NIST frameworks. **IAM Architecture & Strategy**: Define and evolve the Identity and Access Management model (IAM/PAM/IGA), implementing Least Privilege and Zero Trust principles. **Identity Lifecycle Management**: Oversee Joiner, Mover & Leaver (JML) processes, periodic access reviews, and privileged account governance. **Audits & Reporting**: Coordinate internal and external security audits, create KPIs/KRIs, and present executive dashboards to leadership. **Incident & Third-Party Risk Management**: Support incident response for credential/access breaches and evaluate vendor security risks. **Required Qualifications**: Bachelor's degree in Computer Science, Computer Engineering, Information Systems, Information Security, or related technology field. Prior management or technical leadership experience in information security with direct GRC and IAM involvement. Strong knowledge of security frameworks (ISO/IEC 27001/27002, NIST CSF, CIS Controls, COBIT). Deep practical knowledge of LGPD and data protection frameworks. Familiarity with IAM/PAM concepts and architectures (SSO, MFA, SAML, OAuth, RBAC, ABAC). Ability to translate technical security risks into clear business language for executives. **Preferred Qualifications**: Industry certifications (CISM, CRISC, CISA, CISSP, CDPSE, CIPP/E, CIPM). Postgraduate degree or MBA in information security, risk management, IT governance, or strategic management. Experience with leading IAM/PAM platforms (Okta, Ping Identity, CyberArk, SailPoint, Microsoft Entra ID) and GRC tools (ServiceNow, RSA Archer, OneTrust). Advanced or fluent English for international communication. **Benefits**: Health and dental plans, online therapy, fitness benefits, life insurance, meal vouchers, discount partnerships, flexible dress code, and a strong culture of development with Y-shaped career paths, regular feedback cycles, and diversity & inclusion initiatives.

Similar roles