Job Description
Our client is a company dedicated to clinical research, which provides services to laboratories and top-level health organizations.\nTo work remotely and in a direct reporting relationship with the company, we are looking for a person who will lead the ISO 27001 Certification process, with solid knowledge in Information Security.\n\nThe position sought is: \nInformation Security Specialist / GRC Analyst (Governance, Risk & Compliance)\n\nThis will be the person reference in the organization for all aspects related to information security, risk management, regulatory compliance and audits of international clients.\n\nMain responsibilities\nLead the implementation, maintenance and improvement of the Information Security Management System (ISMS) based on ISO 27001.\nCoordinate the comprehensive ISO 27001 certification process.\nManage security risks and perform Gap Analysis, defining action plans and controls.\nAct as the main point of contact during audits of clients and external organizations.\nPrepare documentation, evidence and technical responses, mainly in English.\nEvaluate security aspects of suppliers and critical third parties.\nPromote good practices and security awareness actions within the organization.\nWork transversally with the different areas of the company.\nRole with a high level of autonomy and organizational impact.\n\nRequirements\nMinimum experience of 3 years in Information Security, GRC or Compliance.\nVerifiable participation in the implementation or maintenance of ISO 27001, having participated in at least one complete certification cycle.\nExperience responding to audits from clients or third parties.\nKnowledge of ISO 27001/27002, NIST CSF and risk management.\nFamiliarity with data privacy regulations (GDPR, LGPD or similar).\nGeneral understanding of Cloud environments and their security implications.\nAdvanced English, oral and written (exclusive).\n\nCertifications such as ISO 27001 Lead Implementer, Lead Auditor, CISM, CISSP or equivalent will be especially valued.\nExperience in clinical research companies, healthtech, biotech or highly regulated industries.\nKnowledge of HIPAA.\nManagement of GRC tools such as Vanta, Drata, Sprinto or similar.\n\nHiring conditions\n100% remote work, in a dependency relationship\nRole with a high level of autonomy and organizational impact.\nSalary to be agreed upon",