Responsible for working on IT consulting projects focused on Governance, Information Security and Privacy under the guidance and support of leadership, for internal and external clients, to provide appropriate solutions to business needs with quality, efficiency and compliance, ensuring the expected satisfaction and meeting planned timelines and costs. Activities include risk identification, strategy definition, solution implementation and opportunity mapping.
Participate in the development and delivery of consulting projects in Information Security and IT Governance within the defined scopes;
Support the structuring of methodological approaches and the organization of projects, ensuring alignment with deadlines, costs and quality expectations;
Identify, analyze and propose solutions to clients' problems and challenges related to Information Security;
Map, assess, design, optimize and implement improvements and adjustments to processes that integrate information security strategy and technologies;
Gather project requirements and prepare documents (policies, procedures, workflows and other project artifacts);
Conduct presentations and meetings with clients and internal teams, together with or under the supervision of more senior professionals in the area;
Opportunity to work on more than one project in parallel, maintaining delivery quality and stakeholder communication;
Support the team in detecting needs and proposing continuous improvement actions related to project scopes and, when applicable, reflecting these improvements in the area's processes;
Develop insights and opportunities for new consulting projects, contributing to the ongoing development of the practice;
Understand the area's processes, able to identify their repository and application, as well as corporate policies and guidelines, ensuring their use in professional activities.
Requirements
Experience in consulting, implementation, maintenance or operation of processes and projects related to Governance, Information Security and Privacy, balancing technical knowledge and analytical skills;
Experience in planning, structuring and implementing corrective measures for security and privacy controls, such as implementation/maintenance of certifications (ISO 27001, ISO 27701, ISO 22301...), assessment of security and privacy controls using industry frameworks, risk management and analysis, assessment and definition of information security management models, recommendations for processes, people and technologies, development of roadmaps focused on the evolution and compliance of information security, structuring data inventory processes, among others;
Knowledge of major industry frameworks and methodologies related to security and IT, such as ISO 27001, ISO 27701, ISO 22301, NIST, CIS, SIM3, ITIL, COBIT, among others;
Knowledge of other industry frameworks and methodologies, such as Project Management (PMBOK and agile methodologies) and Process Modeling (BPMN);
Familiarity with laws and regulations such as LGPD, GDPR and the Brazilian Marco Civil da Internet;
Ability to create managerial and executive presentations with strong command of Microsoft Office tools (PowerPoint, Excel, Word); knowledge of Power BI is considered a plus;
Technical certifications: ISO 27001, ISO 27701, ISO 22301, NIST, CIS, ITIL, COBIT, among others;
Desired knowledge of English (advanced reading, intermediate writing, intermediate speaking) and Spanish (intermediate reading, basic writing, basic speaking); more advanced levels are considered differentiators;
Desirable knowledge of market solutions and, as advantages, understanding of technological environments with knowledge of enterprise architectures and analytical skills to understand problems and applicable technologies, considering the impacts of technology and information security on the business.