This role has closed. Mars has taken the posting down.
hirly last saw it live on 28 September 2026. See similar open roles below, or browse the live board.
Mars
Global Information Risk & Governance Analyst
BRA-Sao Paulo-Guararema
Similar open jobs
- Senior IAM / Identity Governance Analyst - Construction Technology (Short-Term)Truelogic · BrazilFirst seen 31d agoremote
- Data Quality and Governance Analyst 2Jll · Warsaw, POLFirst seen today
- Governance Analyst, Architecture & EngineeringManulife · Toronto, OntarioFirst seen today
- ET Risk and Compliance - Risk and Controls Governance AnalystEY · Kochi, KL, INFirst seen today
- ET Risk and Compliance - Risk and Controls Governance AnalystEY · Kochi, KL, INFirst seen today
- Governance AnalystUkgrantt · 21 LocationsFirst seen yesterday
- Cyber Security Governance Analyst | Remote, USAOptiv · 6 LocationsFirst seen yesterdayremote
- Data Governance AnalystCSpring · Indianapolis, INFirst seen 2d ago
- Data Quality & Governance Analyst (Nashville, TN)Oracle · Nashville, TN, United StatesFirst seen 3d ago
- Governance Analyst, Architecture & EngineeringManulife · Toronto, OntarioFirst seen 3d ago
- Data Governance AnalystGhr · 3 LocationsFirst seen 3d ago
- Data Governance AnalystGhr · 3 LocationsFirst seen 3d ago
- Data Product & Governance AnalystUsbank · Warsaw, PolandFirst seen 4d ago
- All-Source Tradecraft and Governance AnalystBah · 2 LocationsFirst seen 4d ago
- Enterprise Cybersecurity GRC Governance AnalystBah · McLean, VAFirst seen 4d ago
hirly's read of this role
- Seniority
- Mid level
- Country
- BR
- Work mode
- On-site / unstated
- First seen by hirly
- 24 Sept 2026
Derived automatically from the posting.
the posting
Job Description:
As the Global Information Risk & Governance Analyst, you will manage the end-to-end risk management program and policy lifecycle. In this role, you will lead risk assessments and govern the identification, assessment, and response to security risks. Additionally, you will be responsible for the development, maintenance, and compliance of security policies and standards.
What are we looking for?
The position is an individual contributor role but is part of a global team. Risks are submitted via the GRC reporting system and the results of proactive top-down risk assessments. This role will work closely with different risk owners from Mars businesses to support risk remediation end-to-end. Insights from risk management are presented and prepared for the Risk Director, who distributes results to various committees and senior executive teams.
What will be your key responsibilities?
- Partner with risk owners across the business to document, assign, and track risk remediation plans through their lifecycle.
- Apply formal risk rating methodology to ensure consistent, accurate, and repeatable risk prioritization.
- Embed and support end-to-end risk management services in assigned area of the business (risk identification, assessment, and issue management).
- Deliver comprehensive analysis of risk data to generate actionable insights.
- Drive process optimization by identifying continuous improvement opportunities and leading initiatives from concept to execution.
- Develop and implement processes to ensure organizational compliance by monitoring changes to external regulations and standards, performing periodic gap assessments, and integrating necessary updates into the policy lifecycle.
- Operate the Policy Exception Management Process, aligning with key technical and business teams to evaluate and decide on exception requests using a formal, risk-based approach.
- Execute the policy attestation process and investigate non-compliance.
- Maintain and monitor KRI/KPIs to reflect risk trends, policy compliance, and executive-level reporting.
What are we looking for?
- 1. Education & Professional Qualification
- Bachelor’s degree in information security, IT, or a similar field, or equivalent work experience
- Experience in Information Security GRC or IT Risk or Governance role
- 2. Knowledge/Experience
- Familiarity with Risk Management, Issue Management, Information Security, and GRC practices.
- Strong follow-through, execution, and attention to detail within a complex environment across multiple, diverse stakeholders.
- Excellent communication and presentation skills, with a proven ability to create executive-level materials.
- Familiarity with the NIST Cybersecurity Framework (CSF) or other industry-standard security frameworks.
- Proven ability to set and achieve goals and manage multiple projects and priorities.
#TBdigital