Job Overview
Job description
- Location:
- Brazil
- Work arrangement:
- On-site
Role Summary
Be responsible for the Data Security workstream in the Third-Party Risk Management (TPRM) process, working cross-functionally with the IT Risk team and continuously contributing to the improvement of security review gates, contractual security requirements and continuous monitoring of data exchange arrangements with third parties.
Promote security-by-design in engineering and data teams: incorporate data protection requirements into integration design standards, API governance frameworks and data residency controls.
Ensure data residency, encryption in transit and at rest, and access control models meet regulatory and contractual obligations in all production environments.
Support regulatory compliance programs (LGPD, GDPR, PCI-DSS) related to data protection, acting as the main Data Security point of contact for the Legal, Compliance and Audit teams.
AI Adoption and Measurable Results
Drive AI adoption across the Data Security function: Implement AI tools for detecting anomalous data patterns, automated data classification, adjusting DLP policies, and accelerating investigations — with measurable improvements in detection speed, false positive reduction, and analyst productivity.
Be responsible for the Data Security workstream for AI Security, working cross-functionally with the AI Security team to continuously improve governance and define data protection requirements for AI tools, including approved use cases, handling of sensitive data in prompts, access controls, monitoring and adoption standards.
Report AI-driven results to leadership: Quantify time saved, risks detected earlier, and improvements in classification accuracy attributable to AI tools.
Business Qualification and Executive Communication
Act as the main Data Security consultant for executive leadership: translate complex data-related risk scenarios into clear updates, contextualized by business impact, for the Corporate Security Manager, Senior Management and the board-level risk committee.
Build and present the executive Data Security dashboard: risk trends, policy violation rates, remediation SLAs, AI adoption metrics, and team capacity status.
Lead cross-functional Data Security initiatives: coordinate with Legal, Product, Engineering and IT to balance security requirements and business speed — finding the safe path that enables product delivery.
Manage Data Security exception requests: evaluate risk-based exceptions to security policies, present recommendations to the risk committee, and track the exception lifecycle.
Represent Data Security in incident response: lead the data-specific investigation front during high-impact incidents, coordinate with CSIRT, and communicate the impact of data-related risk to executives.
Strategic Program Management
Be responsible for the multi-year Data Security roadmap: translating the organizational security strategy into annual and quarterly goals, managing dependency tracking and reporting progress to the Corporate Security Manager.
Lead Sensitive Data Mapping initiatives: coordinate the discovery, classification and cross-functional cataloging of data in corporate and production environments.
Build and maintain Data Security metrics: risk exposure rates, policy violation trends, DLP alert closure rates, remediation SLAs, and team velocity.
Manage the Data Security budget: predict tool and headcount needs, prioritize investments and justify ROI to Finance and leadership.
Requirements
Ingredients We Look For
- Proven experience in people leadership: 3+ years managing and developing a team of security experts or analysts, with demonstrated success in talent retention, succession planning and performance management.
- Strong experience in data protection, DLP, ZTNA and information security governance — with a history of strategic responsibility for a Data Security domain.
- Solid understanding of Zero Trust architecture principles and their practical implementation: ZTNA, conditional access, device posture and identity-based segmentation.
- In-depth knowledge of enterprise SaaS security hardening: Google Workspace, Salesforce, Databricks, other platforms and emerging AI-based platforms.
- Role:
- Data Security Manager
- Job Type:
- Full Time