Grupo QuintoAndar | Information Security Manager
Job description
Manager of Information Security, GRC at Grupo QuintoAndar.
About the role
The role defines the GRC vision and leads strategic transformation of security governance. The manager drives cyber risk management and third-party resilience across a Latin American real estate ecosystem.
Security professionals protect systems, data, and users. They review code, run tests, monitor threats, and respond to incidents. The field spans application security, infrastructure security, and governance. Security work is careful, evidence based, and constantly evolving. Security teams work in a landscape of constant change, with new threats and new rules every year. Most companies invest heavily in training and tooling for their teams.
Key facts
What you'll do
Security service intake is owned to provide clear visibility and prioritization across the security portfolio. Cyber risk is tracked from identification to remediation, with financial quantification methods such as FAIR applied. Compliance with LGPD, SOX, and GDPR is maintained, representing the company in interactions with regulators and auditors. Information security policies, standards, procedures, and processes are structured, simplified, reviewed, and maintained.
Requirements
10+ years of experience in Information Security GRC, including at least 5 years in leadership and team management in complex, dynamic, multinational, or tech environments. Experience managing security demand intake and portfolio prioritization is required, ideally using ITSM practices. Deep mastery of frameworks and standards such as NIST CSF 2.0, ISO 27001/27002, CIS Controls, SOX, and ISO 31000 is necessary. The ability to translate technical cyber risks into financial and operational impacts using methodologies such as FAIR is essential. Experience designing and operating security KPI/KRI frameworks and maturity models for executive reporting is required. Experience designing vendor risk assessment methodologies and TPRM programs is required. Experience leading IAM Governance initiatives aligned with risk and compliance requirements is required. Experience supporting SOX compliance programs, including IT General Controls, is required. Experience designing and running security awareness and behavior change programs is required. A GRC Engineering mindset to use automation and AI for scalable problem-solving, reducing manual and bureaucratic work, is required. Fluency in Portuguese and advanced English is required.
Practical notes
Typical interview steps
Security interviews usually include a technical assessment, a threat modeling exercise, and behavioral rounds. Candidates may be asked to review a code sample for vulnerabilities or design a secure system. Practical knowledge and clear risk communication are the core skills. Interviewers often ask how you triage and communicate risk. Showing calm judgment under pressure matters as much as technical depth.
Good to know
The technology team follows a remote-first model within a diverse and inclusive workplace. The role uses frameworks such as NIST, ISO 27001, and FAIR to guide governance and risk management. AI governance and continuous compliance are central to modern security operations in this position. Security service intake, vendor risk, and cyber resilience form core end-to-end responsibilities.
Questions to ask
Useful questions for the interview: what a typical week looks like, how work is assigned, what tools the team uses, and how feedback works. Asking how the role has changed recently and what the team wishes it had known when joining is also reasonable. Questions about the manager's priorities are especially valued.
Career growth
Security careers grow from analyst or engineer to senior, staff, and leadership roles. Specializations include cloud security, application security, and security operations. Certifications help early; demonstrated impact matters later. Security careers reward specialization and a track record of finding and fixing real issues. Written communication of risk is a core skill at senior levels.