Likely filled
This role has closed. Mars has taken the posting down.
hirly last saw it live on 28 September 2026. See similar open roles below, or browse the live board.
Mars
Global Information Risk & Governance Lead
BRA-Sao Paulo-Guararema
Similar open jobs
- Senior Risk Governance Manager (w/m/d)TARGOBANK AG · Düsseldorf, Nordrhein-Westfalen, GermanyFirst seen 3d ago
- SVP, Model Risk Governance Manager (Hybrid)Citi · Tampa Florida United StatesFirst seen 5d ago
- AI Risk and AI Risk Governance Manager-1Huntington · Charlotte, NCFirst seen 5d ago
- Senior Manager, Credit Risk GovernanceStandard Chartered Bank · Bangalore, Karnataka, IndiaFirst seen 7d ago
- Cybersecurity Lead Analyst - Vulnerability, Cyber Risk Governance, Security OperationsCGI · IndiaFirst seen 9d ago
- Manager, Risk Management (Credit Risk Governance)Hlb · HLT-Hong Leong Tower | Group Risk ManagementFirst seen 20d ago
- AI Risk Governance LeadVanguard · 2 LocationsFirst seen 31d ago
- Associate Director, Third Party Risk Governance & FrameworkDTCC · Tampa, FL, United StatesFirst seen today
- Risk Governance and POA&M SMELOGC2 · Washington, DCFirst seen yesterdayremote
- Senior Risk Governance Officer (2-year Max Term)Asx · SydneyFirst seen 2d ago
- Summer Associate Internship (Enterprise Risk - Data Risk Governance)Navy Federal Credit Union · Vienna, VA, United StatesFirst seen 5d ago
- AVP, Risk GovernanceCiti · Kowloon Hong KongFirst seen 5d ago
- ICT Risk Governance & Oversight - Assistant Vice PresidentState Street · 2 LocationsFirst seen 5d ago
- Model Risk Governance Associate DirectorDTCC · Boston, MA, United States; Dallas, TX, United States; Tampa, FL, United States; Jersey City, NJ, United StatesFirst seen 6d ago
- Controllers Risk Governance, Salt Lake City, Senior AnalystLateral · Salt Lake City, UT, United StatesFirst seen 6d ago
hirly's read of this role
- Seniority
- Lead / management
- Country
- BR
- Work mode
- On-site / unstated
- First seen by hirly
- 24 Sept 2026
Derived automatically from the posting.
the posting
Job Description:
As the Global Information Risk & Governance Lead, you will manage the end-to-end risk management program and policy lifecycle. In this role, you will lead risk assessments and govern the identification, assessment, and response to security risks. Additionally, you will be responsible for the development, maintenance, and compliance of security policies and standards.
What will be your key responsibilities?
- Independently lead execution of Information Security risk assessments and business risk reviews.
- Partner with risk owners across the business to document, assign, and track risk remediation plans through their lifecycle.
- Apply formal risk rating methodology to ensure consistent, accurate, and repeatable risk prioritization.
- Embed and support end-to-end risk management services in assigned area of the business (risk identification, assessment, and issue management).
- Deliver comprehensive analysis of risk data to generate actionable insights.
- Drive process optimization by identifying continuous improvement opportunities and leading initiatives from concept to execution.
- Lead and own the Global Information Security policy and standards lifecycle, including initiation, maintenance, and revision.
- Develop and implement processes to ensure organizational compliance by monitoring changes to external regulations and standards, performing periodic gap assessments, and integrating necessary updates into the policy lifecycle.
- Operate the Policy Exception Management Process, aligning with key technical and business teams to evaluate and decide on exception requests using a formal, risk-based approach.
- Execute the policy attestation process and investigate non-compliance.
- Maintain and monitor KRI/KPIs to reflect risk trends, policy compliance, and executive-level reporting.
What are we looking for?
- 1. Education & Professional Qualification
- Bachelor’s degree in information security, IT, or a similar field, or equivalent work experience
- 7+ years of experience in Information Security GRC or IT Risk or Governance role
- 2. Knowledge/Experience
- Technical experience in Risk Management, Issue Management, Information Security, and GRC practices.
- Strong follow-through, execution, and attention to detail within a complex environment across multiple, diverse stakeholders.
- Excellent communication, writing, and presentation skills, with a proven ability to create executive-level materials.
- Familiarity with the NIST Cybersecurity Framework (CSF) or other industry-standard security frameworks.
- Expertise in business process design and workflow optimization.
- Proven ability to set and achieve goals and manage multiple projects and priorities.
- Expertise in leading the full lifecycle of security policies and standards, from creation and stakeholder review to publication and ongoing maintenance.
#TBdigital