Hiring.Camp

Third Party Risk Management Expert

Didiglobal

·

Yesterday

Location
Sao Paulo, SP, BR
Workplace
Hybrid
Department
Engineering
Closing date
Today
Source
iCIMS

Description

Company Overview

If you see technology as a way to smooth your path in life, our team does too: Your Path, Our Journey.

 

We believe in technology that connects talented people who embrace diversity to create and share paths we don't even know about (yet!). We work to generate value not only for our users but, above all, for the communities we serve and for society as a whole, making every day better for everyone with mobility and delivery services (99) or digital payments (99Pay).

 

To make life easier for millions of people every day, since 2018, we have been part of DiDi DiDi Global Inc., the world’s leading mobility technology platform. We are pioneers in creating innovative solutions that start in Brazil and scale up to make a positive impact in more than 12 countries where DiDi operates. This innovation encompasses sustainability, safety, artificial intelligence, financial markets, and much more.

 

Whether building projects from scratch or improving our solutions, we enjoy challenges that give us butterflies, which is why we work at a fast pace with respect, collaboration, and good humor. Along this journey, we also draw strength from diverse experiences and opinions to grow together, fail quickly, learn, and adjust the course to create solutions that deliver even better results.

#LI-Hybrid

Team Overview

We are seeking a detail-oriented and motivated Information Security Expert to join our Fintech Information Risk & Security Tech team in Brazil. This role focuses on ensuring data security compliance and risk remedation within our BPO (Business Process Outsourcing) operations management. You will be responsible for implementing BPO security governance, workplace(site) security check, personnel access control and indentity management and ensuring that our BPO partners adhere to our security standards. And  Vendor risk assessement, Vulnerability management, Regulatory analysis and audit response. 

Role Responsibilities

  • Ecosystem Onboarding Technical Assessment: Conduct security assessments for overseas ecosystem partners (merchants, channels, service providers, etc.) during the onboarding process. Deeply evaluate their enterprise security architecture, API interface security, data encryption schemes, and compliance qualifications. Output technical assessment conclusions and drive the closure of remediation actions.
  • Vulnerability Management & Risk Operations: Implement and execute the domestic HQ's security operations SOPs. Analyze security risks in overseas business based on vulnerability scans, penetration testing, or daily monitoring results. Guide and drive partners to complete vulnerability remediation and verification to ensure timely risk mitigation.
  • Regulatory Review & Audit Response: Act as the overseas security liaison to cooperate with local regulatory authorities (e.g., central banks, data protection bureaus) and external auditors during inspections and inquiries. Prepare technical evidence regarding system architecture and security policies, and draft compliance reports.
  • Security Standard Localization & Enablement: Assist the Team Lead in promoting and adapting HQ's security control standards and AI-driven automated assessment strategies for overseas business lines. Translate complex compliance requirements (e.g., PCI-DSS) into actionable technical baselines, collect frontline feedback from overseas teams, and contribute to the continuous improvement of security capabilities.

Role Qualifications

  • Education & Experience: Bachelor’s degree or above in Computer Science, Information Security, or related fields.
  • Experience in information security, security architecture, or security operations. Prior experience in overseas finance, cross-border payments, or global internet companies is highly preferred.
  • Technical & Architecture Capabilities: Solid technical foundation in security, with a strong understanding of enterprise security architecture design, common Web/API vulnerability principles, and remediation strategies. Familiarity with data lifecycle encryption and security baseline configurations for mainstream cloud platforms (AWS/GCP/Azure).
  • Compliance & InfoSec Knowledge: Familiarity with major overseas data privacy regulations (e.g., GDPR, CCPA) and financial security standards (e.g., PCI-DSS, ISO27001). Ability to translate compliance requirements into actionable technical metrics.
  • English Proficiency: Fluent in English as a working language. Excellent cross-cultural communication skills, with the ability to independently draft technical compliance reports in English, respond to regulatory inquiries, and handle email communications.[
  • Operations & Resilience: Strong execution and closed-loop thinking skills. Ability to independently drive cross-functional collaboration with limited resources, and handle unexpected security incidents or regulatory inquiries calmly.
  • Bonus Points: Certifications such as CISSP, CCSP, CISP-PTE, or CISA are highly preferred. Prior experience in Information Security/Compliance Auditing (technical focus) at Big 4 firms or renowned consulting companies is a plus.

EEO Statement

  • We create customer value – We strive to always create valuable experiences for our users in everything we do. Our focus is to always innovate new experiences that are safe, pleasant, and efficient.
  • We are data-driven – We are strong believers in making informed decisions, that’s why we are data-driven. We can better navigate the business landscape strategically by analyzing valuable metrics.
  • We believe in Win-win Collaboration – Success is a team sport. When we work to help our partners and colleagues win, we win, too. While keeping everyone's best interest at heart, we communicate with candor and execute with excellence in all we do.
  • We believe in integrity – Integrity is at the very core of our business. We are people who always want to do the right thing. Our intentions are sincere, we speak our minds and listen to each other.
  • We always strive to do better. That means venturing beyond our comfort zones, learning from our mistakes, and helping each other grow.
  • We believe in Diversity and Inclusion – Diversity is one of our biggest strengths. Our differences are what makes us distinct. We respect each other and believe in equal opportunities for all.
Diversity & Inclusion

Diversity is not a future vision or a wish for something we want someday; it is a non-negotiable value of who we are today.

 

We embrace inclusion, plurality, and respect, and to achieve this, we rely on the governance of the Diversity Committee, which works alongside HR, our leadership, and identity groups—99Adapta, 99Afro, 99Colors, 99Womem, and 99Familys.

 

This is our ongoing journey, with much more still to come.

  We reinforce that this position is open to everyone, including pregnant people and people with disabilities (PwD).  I acknowledge that prior to submitting this application, I have read and accepted the Privacy Notice for Candidates which is available on https://careers.didiglobal.com/terms

Skills

AWSAzureGCPPenetration TestingComplianceGDPRCISSP

Similar Jobs

30

Director- Business, Crisis & Third Party Risk | Retail Bank

Capitalone·McLean, VA +1

1d ago

Senior Third-Party Risk Management Analyst

Communitybrands·US-HQ-Home Office, US·Remote

1d ago

Manager, Third Party Risk Management

Sunlife·Sun Life Toronto One York, Canada +1

2d ago

Manager, Third Party Risk Management

Sunlife·Sun Life Toronto One York, Canada +1

2d ago

Resilience and Third-Party Risk Intern, Spring 2027

Northwestern Mutual·Milwaukee, WI Corporate·Onsite

2d ago

Third Party Risk Management Lead

Tokiomarinekiln·London - 20 Fenchurch Street, UK

2d ago

Senior Consultant, Third Party Issue Management - Third Party Risk Management

NT Careers·Chicago, IL +1

3d ago

Senior Third Party Risk (TPRM) Cybersecurity Analyst

The Future of Health Starts with You·Cork, IRL - 3300 Cork Airport Business Pk·Hybrid

3d ago

Third-Party Risk Analyst

Clio·Burnaby, Canada +3·Remote

3d ago

Senior Analyst, ORM & Third-Party Risk

Canadian Tire Corporation·Oakville 01, Canada

3d ago

Associate Director, Third Party Risk Governance & Framework

Depository Trust Company·Tampa, FL

5d ago

Third Party Risk Analytics and Intelligence Associate Director

Depository Trust Company·Tampa, FL

1w ago

Sr Third Party Risk Manager

Transamerica·Denver, Colorado +2

1w ago

Third Party Risk Senior Associate

Crowe Careers·Noida, India

1w ago

Director, Risk Management: Cyber & Third Party Risk

Capitalone·McLean, VA +2

1w ago

Business Analyst - Third Party Risk Management & Risk Remediation

Capco·Poland - Cracow +1·Hybrid

1w ago

Associate, Third Party Risk Management

Ms·Dallas TX 5960, US

1w ago

Associate, Third Party Risk Management

Morgan Stanley·Dallas, TX

1w ago

Third Party Risk Analyst

TAL·Sydney, NSW·Hybrid

2w ago

Third-Party Risk Analyst

Solventum·Bangalore Kar, IN·Hybrid

2w ago

Senior Security Engineer - Enterprise & Third Party Risk Management

LinkedIn·Mountain View, CA·Hybrid

2w ago

Staff Security Engineer - Enterprise & Third Party Risk Management

LinkedIn·Mountain View, CA·Hybrid

2w ago

UK Sourcing Category Manager / Third Party Risk Lead

Unum·Dorking, Surrey +2

2w ago

Specialist, Third Party Risk

NT Careers·Limerick, Ireland

2w ago

VP Third-Party Risk Management - GM Financial Bank

GM Financial·Salt Lake City, UT·Hybrid

2w ago

Manager, Cyber Security (Third Party Risk)

Capitalone·McLean, VA +1

2w ago

AVP – FLGRC (Third Party Risk Management)

M&G·Pune, India

2w ago

IT Third-Party Risk Assessor

Mufgub·Watermark - 410 North Scottsdale Road, US +1

3w ago

Senior Risk Analyst, Privacy & Third-Party Risk

Troweprice·Baltimore, MD

3w ago

Third-Party Risk Manager Lead

Endurance·GBR - London, Fenchurch St.·Hybrid

3w ago