- Location
- GUA-Mars Brasil, Brazil
- Workplace
- Hybrid
- Type
- Full-time
- Seniority
- Lead
- Experience
- 10+ years
- Closing date
- Today
- Source
- Workday
Description
Job Description:
As a Global Information Risk Lead, you will guide the end-to-end risk lifecycle and provide oversight for core program functions. Your primary responsibilities will include leading global risk governance initiatives, being a steward of the risk assessment framework, and driving the resolution of complex findings. In this strategic capacity, you will identify, assess, and advise on the treatment of critical information risks, shaping the security posture and continued success of our business.
What are we looking for?
The position is an individual contributor role but is part of a global team. Risks are submitted via the GRC reporting system and the results of proactive top-down risk assessments. This role will work closely with different risk owners from Mars businesses to support risk remediation end to end. Insights from risk management are presented and prepared for the Risk Director, who distributes results to various committees and senior executive teams.
What will be your key responsibilities?
Independently lead execution of Information Security risk assessments and business risk reviews.
Partner with risk owners across the business to document, assign, and track risk remediation plans through their lifecycle.
Apply formal risk rating methodology to ensure consistent, accurate, and repeatable risk prioritization.
Embed and support end-to-end risk management services in the assigned area of the business (risk identification, assessment, and issue management).
Deliver comprehensive analysis of risk data to generate actionable insights.
Drive process optimization by identifying continuous improvement opportunities and leading initiatives from concept to execution.
Maintain and monitor KRI/KPIs to reflect risk trends and provide executive-level reporting.
What can you expect from Mars?
Business or technical degree
10+ years of experience in digital technologies/governance / GRC
Technical experience in Risk Management, Issue Management, Information Security, and GRC practices.
Strong follow-through, execution and attention to detail within a complex environment across multiple, diverse stakeholders.
Track record of developing external networks to benchmark internal processes against industry standards and build best practices and strategies.
A history of building strong internal networks, ability to inspire others and help others build capabilities.
Excellent communication and presentation skills, with a proven ability to create executive-level materials.
Familiarity with the NIST Cybersecurity Framework (CSF) or other industry-standard security frameworks.
Expertise in business process design and workflow optimization.
Proven ability to set and achieve goals and manage multiple projects and priorities.
#TBdigital