Senior GRC Analyst (Business Resilience)
Summary
Build and maintain Tractian’s governance, risk, and compliance program, integrating ISO 27001/22301 controls and resilience testing to protect IoT-driven operations.
- Lead and continuously improve the organization's operational resilience, business continuity, and risk management activities – including identifying, assessing, documenting, monitoring, and reviewing operational, technology, cybersecurity risks.
- Perform Business Impact Analysis (BIA), define recovery objectives (RTO/RPO), develop disruption scenarios, and establish contingency, recovery, and business continuity strategies for critical business services.
- Develop, implement, maintain, and continuously improve the organization's Business
- Continuity (BCM), Disaster Recovery (DR), and Incident Response (IR) activities, including policies, standards, procedures, recovery plans, and playbooks, aligned with corporate objectives, regulatory requirements, and industry best practices.
- Plan, facilitate, execute, and document tabletop exercises, recovery tests, backup and recovery validation, failover exercises, and other resilience testing activities, ensuring lessons learned and corrective actions are tracked.
- Maintain the enterprise risk register, controls, mitigation plans, and audit evidence within the organization's GRC/compliance platform, partnering with control owners to drive remediation activities through completion.
- Collaborate with Engineering, Development, Infrastructure, Security, and business stakeholders to design, implement, and continuously improve risk, resilience, recovery, and incident management processes.
- Support and continuously improve compliance with ISO 27001, ISO 27002, ISO 22301, and ISO 22313 through assessments, internal controls, audits, and remediation activities.
- Support customer security and compliance due diligence activities, including responding to security questionnaires (e.g., SIG, CAIQ, RFPs) in collaboration with the GRC team and subject matter experts.
- Provide guidance to business and technology teams on governance, risk, operational resilience, and compliance matters.
- Partner closely with Engineering, Infrastructure, Product, Security, and business teams to integrate governance, risk, and compliance practices into business and technology initiatives.
- Collaborate with cross-functional teams on a variety of Security GRC initiatives, contributing to governance, risk, compliance, and assurance programs in support of shared organizational goals.
- Background in Information Technology, Information Security, Governance, Risk & Compliance (GRC), Internal Audit, Compliance, or Quality Management.
- Experience implementing and operating Business Continuity Management (BCM) and
- Disaster Recovery (DR) programs based on ISO 22301 and ISO 22313.
- Experience conducting Business Impact Analysis (BIA), defining RTO/RPO, recovery strategies, contingency planning, and business disruption scenarios.
- Experience planning and facilitating tabletop exercises and technical recovery tests for Business Continuity, Disaster Recovery, and Incident Response.
- Experience developing and maintaining policies, standards, procedures, and playbooks related to Business Continuity, Disaster Recovery, and Incident Response.
- Experience with ISO 27001 / ISO 27002 compliance.
- Knowledge of data protection best practices and compliance requirements under the LGPD and GDPR.
- Hands-on experience implementing controls and managing remediation plans.
- Knowledge of risk management frameworks (e.g., ISO 27005, NIST).
- Experience collaborating with Engineering and Development teams on resilience and compliance initiatives.
- Advanced Portuguese proficiency.
- Advanced English proficiency.
- Experience with compliance automation and GRC platforms (e.g., Vanta, Drata, etc.).
- Experience with Business Continuity Management (BCM) tools.
- Experience working with multiple security frameworks and regulatory environments.
- Experience using task and project management platforms (e.g., Jira, Linear, Monday, etc.) to manage remediation plans and compliance initiatives.
- Market-recognized security certifications.
- Experience leveraging automation and Artificial Intelligence (AI) to improve GRC processes, evidence collection, reporting, and compliance operations.
- Ability to collaborate effectively across technical and business teams.
- Excellent communication skills.
- Proactive, analytical, and solution-oriented.
- Highly organized, with strong attention to documentation and audit evidence.
- Team-oriented mindset (one person’s problem is everyone’s problem).
- Comfortable working in dynamic environments and navigating ambiguity.
- Ability to independently drive assigned initiatives and deliver high-quality results.
- Continuous improvement mindset focused on strengthening organizational resilience.
Compensation & Benefits
- Competitive salary and stock options
- 30 days of paid annual leave
- Education and courses stipend
- Earn a trip anywhere in the world every 4 years
- R$1.035/month for meals allowance
- Health plan with national coverage and without coparticipation
- Dental Insurance: we help you with dental treatment for a better quality of life.
- Wellhub and Sports Incentive: R$300/mo extra if you practice activities