GRC at TRACTIAN The Engineering team at Tractian is at the forefront of developing cutting-edge infrastructure, technologies, and products to harness the power of IoT data. Our team of talented Engineers collaborates to build robust systems, innovative solutions, and scalable platforms that drive Tractian's success. We are instrumental in shaping the company's decision-making process, optimizing operational efficiency, and delivering exceptional experiences to our consumers. What you'll do As a GRC Analyst, you will be responsible for developing and implementing robust governance, risk management, and compliance (GRC) practices within our technology-driven organization. You will play a key role in establishing frameworks and processes that ensure the security, integrity, and regulatory compliance of our technology systems. You will collaborate with cross-functional teams to assess risks, implement controls, and drive continuous improvement of our GRC program. Key Responsibilities Support the continuous maintenance and improvement of the organization's Information Security Management System (ISMS), ensuring alignment with ISO 27001/27002, SOC 2, and applicable NIST frameworks. Perform compliance assessments, control reviews, and gap analyses, driving remediation plans and tracking corrective actions through completion. Develop, review, and maintain information security policies, standards, procedures, and governance documentation, while monitoring the effectiveness and adoption of security controls across the organization. Support internal and external audits by coordinating evidence collection, maintaining audit documentation, responding to auditor requests, and ensuring continuous audit readiness. Support the implementation and continuous improvement of secure development practices by reviewing processes, advising Engineering and Product teams, and promoting Privacy by Design and Privacy by Default principles. Support Third-Party Risk Management (TPRM) activities, including vendor security assessments, risk reviews, remediation tracking, and continuous improvement of third-party governance processes, aligned with the organization's Risk Management Program. Maintain controls, evidence, remediation plans, and compliance records within the organization's GRC platform, ensuring information remains accurate, current, and audit-ready. Support customer security and compliance due diligence activities, including security questionnaires (SIG, CAIQ, RFPs, etc.), in collaboration with the GRC team and subject matter experts. Partner closely with Engineering, Infrastructure, Product, Security, and business teams to integrate governance, risk, and compliance practices into business and technology initiatives. Collaborate with cross-functional teams on a variety of Security GRC initiatives, contributing to governance, risk, compliance, and assurance programs in support of shared organizational goals. Requirements Background in Information Technology, Information Security, Governance, Risk & Compliance (GRC), Internal Audit, Compliance, or Quality Management. Experience supporting Information Security Management Systems (ISMS) and assessing compliance with security frameworks and standards, including ISO/IEC 27001, ISO/IEC 27002, SOC 2, and NIST. Knowledge of data protection best practices and compliance requirements under the LGPD and GDPR. Experience performing compliance assessments, internal audits, control reviews, gap analyses, and remediation tracking. Experience developing and maintaining information security policies, standards, procedures, and governance documentation. Experience with Third-Party Risk Management (TPRM), including vendor security assessments and remediation follow-up. Hands-on experience implementing, monitoring, and validating security and compliance controls. Experience working cross-functionally with Engineering, IT, Security, Procurement, Legal, and business teams. Advanced English proficiency. Nice to Have Experience with compliance automation and GRC platforms (e.g., Vanta, Drata, etc.). Experience working with multiple security frameworks and regulatory environments. Experience using task and project management platforms (e.g., Jira, Linear, Monday, etc.) to manage remediation plans and compliance initiatives. Market-recognized security certifications. Experience leveraging automation and Artificial Intelligence (AI) to improve GRC processes, evidence collection, reporting, and compliance operations. Soft Skills Ability to collaborate effectively across technical and business teams. Excellent communication skills. Proactive, analytical, and solution-oriented. Highly organized, with strong attention to documentation and audit evidence. Team-oriented mindset (one person’s problem is everyone’s problem). Comfortable working in dynamic environments and navigating ambiguity. Ability to independently drive assigned initiatives and deliver high-quality results. Continuous improvement mindset focused on strengthening organizational resilience. Compensation & Benefits Competitive salary and stock options 30 days of paid annual leave Education and courses stipend Earn a trip anywhere in the world every 4 years R$1.035/month for meals allowance Health plan with national coverage and without coparticipation Dental Insurance: we help you with dental treatment for a better quality of life. Wellhub and Sports Incentive: R$300/mo extra if you practice activities
Senior GRC Analyst (Business Resilience)
Tractian Technologies Inc
Senior Backend Engineer (Remote) - UK
AlphaSights
Technical QA Associate
Ujv
Engenharia de Software Backend Sênior - Ruby on Rails | RD Station (Remoto)
RD Station
Engenharia de Software Frontend Pleno - React | RD Station (Remoto)
RD Station
Strategic Account Manager
Wesco