Back to Careers

Information Security Governance Analyst

Security · Brazil · On-site (negotiable)

Own security governance across the NeoData platform — policies, compliance (SOC 2, GDPR, LGPD) and access control.

About NeoSpace

NeoSpace is an innovative startup shaping the future of technology with cutting-edge artificial intelligence solutions. We develop specialized AI models to streamline processes and transform our clients' experience. Our goal is to simplify people's lives and boost business efficiency by creating smarter, more accessible products and services.

What we're looking for

We are looking for an Information Security Governance Analyst with solid experience in ISO/IEC 27001 and SOC 2, and a strong conceptual technical foundation, to work on the governance, assurance, and maturity of our Information Security program.

This role does not involve the technical implementation or maintenance of controls, but it does require enough technical knowledge to assess, challenge, and validate controls implemented by the technology and security teams, ensuring that the objectives of standards, frameworks, and corporate policies are effectively met.

In addition, this professional will play a key role in strengthening our Information Security culture through training, awareness initiatives, and corporate governance efforts.

Responsibilities

  • Support ISMS governance, ensuring adherence to ISO/IEC 27001.
  • Lead and maintain activities related to SOC 2 (Type I and Type II).
  • Perform gap analyses, risk assessments, and follow-up on action plans.
  • Maintain traceability between regulatory requirements, controls, risks, and evidence.
  • Support internal and external audits, acting as the governance focal point.
  • Periodically assess the effectiveness of controls from a compliance and assurance perspective.
  • Help define and evolve security metrics and indicators (KPIs and KRIs).
  • Assess the design and effectiveness of technical and administrative controls implemented by others (technology and security teams).
  • Conduct structured technical inquiries to ensure that controls: meet the objectives of the standards; are proportional to the risks; are backed by adequate evidence.
  • Validate controls related to: access management (IAM); logs and audit trails; vulnerability management; backup, continuity, and resilience; security in cloud environments; AI governance.
  • Act as a second line of defense, with independence and a critical eye.
  • Plan and run Information Security awareness programs.
  • Develop and maintain mandatory training and educational campaigns aligned with ISO 27001 and internal policies.
  • Help build a security-driven organizational culture, working closely with business and technology teams.
  • Create supporting materials, communications, and educational content on security best practices.
  • Track training adoption and effectiveness metrics.
  • Draft, review, and maintain Information Security policies, standards, and procedures.
  • Ensure alignment between corporate policies, regulatory requirements, and operational practices.
  • Support exception management and risk acceptance processes.
  • Contribute to the continuous improvement of the security governance framework.

Requirements

  • Proven experience with ISO/IEC 27001, including governance and audit support.
  • Solid experience with SOC 2, including: control assessment; critical review of evidence; interaction with external audits.
  • Technical knowledge of Information Security, sufficient to: assess architectures and processes; technically challenge the controls presented; validate adherence to the objectives of the standards.
  • Experience in GRC / governance / assurance activities.
  • Strong communication skills to work with both technical and non-technical teams.

Nice to have

  • Previous experience at startups or fast-growing companies.
  • Background in AI, technology, or digital product companies.
  • Intermediate/advanced English.
Apply

Information Security Governance Analyst