IT Compliance & Application Security Manager

Sylvamo
R$ 30.710 - R$ 38.886 a year
Região Metropolitana de Ribeirão Preto, São Paulo
Full time
há 2 dias
Pay Grade 17

Position Summary:
The IT Compliance & Application Security Manager is responsible for leading and coordinating IT compliance initiatives, with a strong focus on Sarbanes-Oxley (SOX) and cybersecurity requirements. This role ensures that IT controls are effectively designed, documented, and executed in alignment with regulatory standards and audit expectations.

This position plays a critical role in identifying risks, implementing cybersecurity best practices, and maintaining a robust control environment across both financial and non-financial systems.

Key Responsibilities:
Control Framework Ownership Develop and maintain application-specific control matrices (e.g., SoD, secure development, identity lifecycle, privileged access). Ensure alignment with frameworks such as COSO, COBIT, and NIST.
Policy Implementation & Oversight Translate enterprise security policies into actionable control requirements. Ensure consistent implementation across centralized (e.g., SAP GRC) and decentralized platforms.
Partner with internal software development teams to promote secure coding practices and integrate security checkpoints within CI/CD pipelines.
IAM & SoD Governance Develop governance over identity provisioning, role design, and segregation of duties enforcement. Coordinate exceptions and remediation plans in collaboration with IAM and audit teams.
Metrics & Reporting Define and report on KPIs/KRIs related to control effectiveness and risk posture. Deliver dashboards and reports to senior leadership and risk committees.
Cross-Functional Collaboration Partner with application owners, cybersecurity architects, GRC analysts, and vendors to ensure compliance coverage.
Policies, Procedures, and Documentation Develop and maintain IT compliance policies and procedures. Ensure documentation meets audit standards and reflects current operations.
Education, and training, develop and train application and system owners on their responsibilities and self-assessment for security controls.

Technical Skills & Competencies:
IT Controls & Frameworks Deep knowledge of ITGCs, application controls, and frameworks (COSO, COBIT, NIST). Experience in change management, access management, and system operations.
Audit Methodologies & Standards Familiarity with PCAOB, ISACA, and other audit standards. Experience working with internal/external auditors (Big Four experience is a plus).
Regulatory & Compliance Knowledge Strong understanding of SOX (especially Section 404), GDPR, HIPAA, PCI-DSS.
GRC Tools Proficiency in SAP GRC and other GRC platforms for control monitoring and reporting.
Cybersecurity Fundamentals Knowledge of ISO 27001, NIST CSF, incident response, and vulnerability management.
Data Analysis & Reporting Ability to analyze logs, metrics, and audit findings. Proficiency in Excel, Power BI, or similar tools for reporting.

Interpersonal Skills:
Collaboration & Teamwork: Effective cross-functional collaboration.
Communication: Clear articulation of technical concepts to non-technical stakeholders.
Leadership & Influence: Ability to drive compliance initiatives and gain organizational buy-in.
Adaptability: Flexibility in navigating regulatory and technological changes.
Strategic Thinking: Alignment of compliance efforts with business objectives.
Proactive Mindset: Anticipation of risks and continuous improvement.

Qualifications:
Core Competencies:
Apply
Other Job Recommendations:

IT Compliance & Application Security Manager

Sylvamo
Região Metropolitana de Ribeirão Preto, São Paulo
R$ 30.710 - R$ 38.886 a year
The IT Compliance & Application Security Manager is responsible for leading and coordinating IT compliance initiatives, with a...
há 2 dias

South America Regional Security Manager

General Motors
  • Develop excellent working relationships and strategic...
  • Communicate regularly with stakeholders and senior...
há 1 semana

Lead Security Engineer - AppSec

Nubank
São Paulo
  • Solid understanding of application security concepts and...
  • Hands-on experience with CI/CD pipelines and implementing...
há 1 semana

Senior Staff BCO - 1st Line Compliance Lead

Nubank
São Paulo
  • Reading regulations and understanding their implications for...
  • Help the 1LoD to co-create and finalize e2e action plans to...
há 1 semana

Director of Security

Jeeves
São Paulo
  • Security Program Management: Oversee the design,...
  • Security Operations & Incident Response: Oversee...
há 1 semana

Mid-Senior Information Security Intelligence Analyst (Hybrid work)

Eurofins
Região Metropolitana de Campinas, São Paulo
  • Proactively identify and track targeted intrusion cyber...
  • Conduct thorough analysis of threat data from various...
há 2 semanas

Security Cloud Consultant, Google Cloud Professional Services

Google
The Google Cloud Consulting Professional Services team guides customers through the moments that matter most in their cloud...
há 1 semana

Senior Manager Finance

C.H. Robinson
Região Metropolitana de São Paulo, São Paulo
R$ 25.558 - R$ 32.363 a year
  • Provide external reporting to authorities and encompasses...
  • Monitor cash flow and working capital to ensure adequate...
há 18 horas

Senior Security Engineer - Regulatory Requirements

Nubank
  • Analyze and interpret new IT and Security regulatory...
  • Stay up-to-date with regulatory changes and emerging trends,...
há 2 semanas

Account Manager - Microsoft Advertising

Aleph
São Paulo
  • Acquire a thorough understanding of key customer needs and...
  • Serve as the communication link between key customers and...
há 3 semanas