Lead the development and maintenance of privacy policies, standards, and procedures with direct impact on related initiatives;
Collaborate with Legal & Compliance on LGPD-related matters;
Conduct vendor privacy assessments;
Support the process for responding to data subject requests;
Perform and support updates to Data Mapping and Data Inventory, Data Protection Impact Assessment (DPIA) reports, Legitimate Interest Assessments (LIA), maturity analyses, continuous improvement activities, and action plans;
Support the company's data governance initiatives by providing assessments and recommendations for preventive and corrective actions to ensure compliance with the LGPD.
Requirements
Bachelor's degree in Information Security, Computer Science, Computer Engineering, Law, or equivalent;
Experience developing and/or operating privacy and data protection programs;
Knowledge of major industry frameworks such as ISO20K, ISO27K, ISO29001, COBIT, ITIL, Agile methodologies, among others;
Knowledge of regulatory compliance legislation related to data protection and privacy (LGPD and GDPR);
Strong interpersonal skills and ability to work collaboratively in a team;
Ability to automate controls;
Availability to work in a hybrid model in São Paulo.
Differentials:
Specialization and/or postgraduate degree in Data Protection and Privacy and/or Information Security;
Experience in Technology Risk Management processes;