IT Risk & Compliance Officer (Cloud) - Fixed-Term Contract (3 months with Possibility of Extension)
Adaugat: Ieri
Stefanini EMEA
IT Risk & Compliance Officer (Cloud) - Fixed-Term Contract (3 months with Possibility of Extension)
Adaugat: Ieri
Stefanini EMEA
Acest anunt este cu aplicare externa. Cand dati click pe Aplicare Externa veti fi redirectionat pe un alt site pentru a aplica.
Job DescriptionStefanini Group is looking to welcome a highly skilled IT Risk & Compliance Officer for Cloud projects, a dedicated role supporting one of our valued clients.The IT Risk & Compliance Officer for Cloud is responsible for partnering with the platform and capability owners throughout the Central Tech business function to design and maintain IT security and compliance controls in line with our client's risk appetite and regulatory requirements and to maintain the quality of our client's processes.This role requires close collaboration with platform owners and development teams to build a strong high-level understanding of risk, while also being able to zoom in and out of the details to ensure a clear understanding of the solution design and to design effective controls.This role follows a hybrid working model with an onsite presence of 2 days/week.Job ResponsibilitiesProvide cybersecurity, IT risk, and regulatory compliance advice to platform owners, development teams, and business functions, in line with internal policies and standards such as NIST, SOX, PCI-DSS, and other relevant best practices, to support secure and compliant cloud adoption.Bridge the gap between technical and audit teams by working with platform and development teams to translate complex technology or application stacks into risk-based language for Internal and External Audits.Perform IT risk assessments for new platforms and significant platform changes, using the organization's risk and control framework, to identify key risks, assess control effectiveness, and recommend appropriate remediation actions.Advise stakeholders on the design of sustainable, proportionate, and scalable controls, including cloud control requirements for identity and access management, logging, encryption, network security, and configuration governance, to strengthen risk management and compliance.Develop and enhance cloud guardrails, standards, and control requirements, in line with internal governance and regulatory expectations, to support secure onboarding and consistent use of cloud services across platforms.Drive continuous improvement and harmonization of cloud controls across platforms, following internal control standards and compliance requirements, to simplify compliance and improve control consistency.Coordinate with Security, Risk and Controls, Internal Audit, External Audit, Business Continuity, IT Disaster Recovery, and Service Continuity teams, and support audit evidence requests as needed, to ensure effective risk oversight and timely audit support. Job Requirements:Education: Preferred: Bachelor's degree in computer science, Information Technology, Engineering, or a related field.Minimum education requirement: Bachelor's degree in any field Language proficiency:Excellent English communication skills, both verbal and written, for professional communication and documentation. Experience: Preferred: 5+ years of experience gained within IT risk, compliance, internal controls or audit within a highly regulated industry.Minimum: 3 years of experience gained within IT risk, compliance, internal controls or audit within a highly regulated industry. Technical skills:Strong expertise in business analysis, auditing, corporate governance, risk management or internal controls.Ability to assess risks, evaluate controls, and provide practical, proportionate recommendations to both technical and non-technical stakeholders.Basic technical understanding of internal control requirements and design and experience in applying them in various businesses.Ability to translate complex technology and application stacks into risk-based language for Internal and External Audits.Good technical expertise in Cloud Security and Compliance (AWS - strongly preferred, GCP, Azure, etc.) and DevOps domain.Knowledge of cloud risk and control domains, including identity and access management, logging and monitoring, encryption, network security, and configuration governance.Familiarity/experience working with a wide range of technologies (internally developed applications, Windows, Linux, Databases, Gitlab, etc.) from a risk and security perspective. Desired qualifications (Nice to have, but not mandatory):Cloud certifications are an advantage for this position. Relevant certifications include AWS certifications, ISC2 certifications such as CCSP, and the Certificate of Cloud Security Knowledge (CCSK) issued by CSA. Professional skills:Strong stakeholder management and communication skills, with the ability to collaborate effectively across technology, risk, audit, and business teams.Ability to build solid relationships with business partners to drive the adoption of the risk management culture.Ability to break down complex tasks into logical, manageable, and well-defined actions, ensuring effective execution and timely delivery.Ability to adapt quickly to change and demonstrate flexibility and agility in response to evolving business priorities, stakeholder expectations, and the client's regulatory or operating environment.Proven ability to work autonomously while remaining a collaborative and effective team player. This job description outlines the general nature and level of work performed by employees within this classification and is not intended to be a comprehensive inventory of all duties and responsibilities. Additionally, the responsibility to possess the necessary employment documents for this country rests with the candidate.Diversity & InclusionHere at the Stefanini Group, we value diversity and equity, regardless of race, sexual orientation, disability, age, ancestry, religion, gender, or nationality. We understand and encourage the importance of being yourself and invest our efforts in maintaining an environment where it is safe to express oneself!About UsGlobal Tech Consulting Company All in One.Stefanini is a Brazilian multinational company with 38 years of experience and presence in 41 countries. With more than 35,000 employees, we co-create solutions for a better future, driving digital transformation with a focus on real results.We operate in an integrated way through 7 specialized business units: Consulting (Technology and Business Agility), Analytics & AI, Banking & Payments, Cybersecurity, Manufacturing 4.0, and Digital Marketing. We are a group that breathes collaboration and offers a dynamic environment where you will learn by doing, grow alongside the team, and have space to contribute with ideas and projects. I-LI-HYBRID Show more Show less
Sfaturi de siguranta
- Nu trimiteti niciodata BANI in avans sau acte de identitate pentru aplicarea la un loc de munca. Nu trimiteti bani in avans pentru promisiuni de angajare sau alte oferte similare.
- Daca aveti impresia ca acest anunt nu este real, va rugam sa il raportati apasand butonul "Raporteaza Job"
This action will pause all job alerts. Are you sure?
Locuri de munca similare
Fii informat
Aboneaza-te la newsletter-ul nostru si primeste cele mai recente oferte de munca si informatii despre cariera direct in inbox-ul tau.
Securitatea datelor dumneavoastra este importanta pentru noi. Citeste Politica de confidentialitate.