远程工作雷达

GRC顾问

GRC Consultant

其他限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司Visa
薪资未公开
工作地点Brazil
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 Brazil 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

关于我们的公司
Visa 是支付技术领域的全球领导者,业务遍及 200 多个国家和地区,连接消费者、商户、金融机构和政府机构,致力于通过最佳的支付和收款方式,让世界各地的人们生活更美好。
在 Visa,你将有机会大规模地产生影响——解决有意义的挑战,提升技能,并看到你的贡献改变世界中人们的生活。
加入 Visa,做真正重要的工作——对你、对你的社区、对世界都有意义。进步始于你。
职位描述
职位概述

治理、风险与合规(GRC)顾问负责领导 Pismo 全球运营中的战略治理、合规、风险管理、审计和韧性计划。该职位与安全、工程、法律、隐私、产品、基础设施和业务团队合作,加强公司的安全和合规态势,同时支持客户、监管和 Visa 的要求。

成功候选人需在信息安全治理、监管合规、风险管理、审计准备、第三方风险管理、业务连续性和运营韧性方面具备专业知识。该职位需要强大的利益相关者管理能力,并能够向技术和高管受众展示复杂的风险和合规问题。

主要职责:
治理与合规:

  • 领导治理框架、政策、标准和流程的开发、维护和持续改进。
  • 支持符合行业标准和监管要求,包括 ISO 27001、SOC 1、SOC 2、PCI DSS、PCI PIN 安全、数据本地化要求以及其他适用的框架。
  • 进行合规性评估、差距分析和成熟度评审,识别控制增强和流程改进的机会。
  • 协调内部和外部审计,并支持发现的问题整改。

风险管理:

  • 主导企业、运营、技术和网络安全风险评估。
  • 维护风险登记册并支持风险处理、监控和报告活动。
  • 与利益相关者合作,实施有效的缓解策略并监控风险敞口。
  • 准备高管级风险报告和仪表板,以支持管理层决策。

客户与监管保障:

  • 支持安全审计
查看英文原文

About Us
Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid.
At Visa, you'll have the opportunity to create impact at scale — tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world.
Join Visa and do work that matters – to you, to your community, and to the world. Progress starts with you.
Job Description
Job Summary

The Governance, Risk & Compliance (GRC) Consultant is responsible for leading strategic governance, compliance, risk management, audit, and resilience initiatives across Pismo's global operations. This role partners with security, engineering, legal, privacy, product, infrastructure, and business teams to strengthen the company's security and compliance posture while supporting client, regulatory, and Visa requirements.

The successful candidate will provide subject matter expertise across information security governance, regulatory compliance, risk management, audit readiness, third-party risk management, business continuity, and operational resilience. The role requires strong stakeholder management skills and the ability to present complex risk and compliance matters to both technical and executive audiences.

Key Responsibilities:
Governance & Compliance:

  • Lead the development, maintenance, and continuous improvement of governance frameworks, policies, standards, and procedures.
  • Support compliance with industry standards and regulatory requirements, including ISO 27001, SOC 1, SOC 2, PCI DSS, PCI PIN Security, data localisation requirements, and other applicable frameworks.
  • Conduct compliance assessments, gap analyses, and maturity reviews, identifying opportunities for control enhancement and process improvement.
  • Coordinate internal and external audits and support remediation of identified findings.

Risk Management:

  • Facilitate enterprise, operational, technology, and cybersecurity risk assessments.
  • Maintain risk registers and support risk treatment, monitoring, and reporting activities.
  • Collaborate with stakeholders to implement effective mitigation strategies and monitor risk exposure.
  • Prepare executive-level risk reporting and dashboards to support leadership decision-making.

Client & Regulatory Assurance:

  • Support security due diligence activities, client assessments, and assurance requests from financial institutions, partners, regulators, and payment networks.
  • Coordinate responses to regulatory inquiries and examinations.
  • Engage directly with clients and external stakeholders to communicate Pismo's security, compliance, and resilience capabilities.
  • Prepare reports, executive summaries, and evidence packages for customer and regulatory reviews

Strategic Initiatives:

  • Drive continuous improvement initiatives through automation, AI-enabled processes, and operational efficiency programmes.
  • Support the implementation of new compliance and security initiatives resulting from regulatory or business changes.
  • Contribute to organisational security awareness and compliance maturity programmes.
  • Mentor junior GRC professionals and contribute to knowledge sharing across the organisation

This is a remote position. A remote position does not require job duties be performed within proximity of a Visa office location. Remote positions may be required to be present at a Visa office with scheduled notice.

Qualifications

Basic Qualifications:

  • 5 years relevant work experience with a Bachelor's degree or 2 years relevant work experience with an Advanced degree (e.g. Masters, MBA, JD, MD) or 0 years relevant work experience with a PhD; OR 8 years relevant work experience

Preferred Qualifications:

  • Bachelor's degree in Information Security, Cybersecurity, Risk Management, Information Technology, Law, Business Administration, or a related field.
  • Minimum 5 years of experience in Governance, Risk & Compliance, Information Security, Risk Management, Internal Audit, or related consulting roles.
  • Demonstrated experience supporting audits, regulatory reviews, or certification programmes.
  • Strong understanding of risk management methodologies and information security governance principles.
  • Experience interacting with senior stakeholders and executive leadership.
  • Strong analytical, communication, presentation, and report-writing skills.
  • Professional certifications such as:
  • CISSP
  • CISM
  • CISA
  • CRISC
  • ISO 27001 Lead Auditor or Lead Implementer
  • CGRC
  • Experience in banking, payments, fintech, or other highly regulated industries.
  • Familiarity with cloud-native environments and modern software development practices.
  • Knowledge of privacy and data protection regulations.

Visa is an EEO Employer
Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with EEOC guidelines and applicable local law.
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级工程经理,卡类

VisaBrazilFull Time今天
开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

高级网络安全工程师

VisaBrazilFull Time今天
开发工程职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

资深站点可靠性工程师

VisaBrazilFull Time今天
开发工程职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位