Lead and improve operational resilience, business continuity, disaster recovery, and incident response programs. Conduct BIAs, define RTO/RPO, create recovery plans and playbooks, run exercises and tests, maintain risk and control registers, support ISO 27001/27002 and ISO 22301/22313 compliance, respond to security questionnaires, and collaborate with engineering and security teams to implement controls and remediation.
GRC at TRACTIAN
The Engineering team at Tractian is at the forefront of developing cutting-edge infrastructure, technologies, and products to harness the power of IoT data. Our team of talented Engineers collaborates to build robust systems, innovative solutions, and scalable platforms that drive Tractian's success. We are instrumental in shaping the company's decision-making process, optimizing operational efficiency, and delivering exceptional experiences to our consumers.
What you'll do
As a GRC Analyst, you will be responsible for developing and implementing robust governance, risk management, and compliance (GRC) practices within our technology-driven organization. You will play a key role in establishing frameworks and processes that ensure the security, integrity, and regulatory compliance of our technology systems. You will collaborate with cross-functional teams to assess risks, implement controls, and drive continuous improvement of our GRC program.
Key Responsibilities
- Lead and continuously improve the organization's operational resilience, business continuity, and risk management activities – including identifying, assessing, documenting, monitoring, and reviewing operational, technology, cybersecurity risks.
- Perform Business Impact Analysis (BIA), define recovery objectives (RTO/RPO), develop disruption scenarios, and establish contingency, recovery, and business continuity strategies for critical business services.
- Develop, implement, maintain, and continuously improve the organization's Business
- Continuity (BCM), Disaster Recovery (DR), and Incident Response (IR) activities, including policies, standards, procedures, recovery plans, and playbooks, aligned with corporate objectives, regulatory requirements, and industry best practices.
- Plan, facilitate, execute, and document tabletop exercises, recovery tests, backup and recovery validation, failover exercises, and other resilience testing activities, ensuring lessons learned and corrective actions are tracked.
- Maintain the enterprise risk register, controls, mitigation plans, and audit evidence within the organization's GRC/compliance platform, partnering with control owners to drive remediation activities through completion.
- Collaborate with Engineering, Development, Infrastructure, Security, and business stakeholders to design, implement, and continuously improve risk, resilience, recovery, and incident management processes.
- Support and continuously improve compliance with ISO 27001, ISO 27002, ISO 22301, and ISO 22313 through assessments, internal controls, audits, and remediation activities.
- Support customer security and compliance due diligence activities, including responding to security questionnaires (e.g., SIG, CAIQ, RFPs) in collaboration with the GRC team and subject matter experts.
- Provide guidance to business and technology teams on governance, risk, operational resilience, and compliance matters.
- Partner closely with Engineering, Infrastructure, Product, Security, and business teams to integrate governance, risk, and compliance practices into business and technology initiatives.
- Collaborate with cross-functional teams on a variety of Security GRC initiatives, contributing to governance, risk, compliance, and assurance programs in support of shared organizational goals.
Requirements
- Background in Information Technology, Information Security, Governance, Risk & Compliance (GRC), Internal Audit, Compliance, or Quality Management.
- Experience implementing and operating Business Continuity Management (BCM) and
- Disaster Recovery (DR) programs based on ISO 22301 and ISO 22313.
- Experience conducting Business Impact Analysis (BIA), defining RTO/RPO, recovery strategies, contingency planning, and business disruption scenarios.
- Experience planning and facilitating tabletop exercises and technical recovery tests for Business Continuity, Disaster Recovery, and Incident Response.
- Experience developing and maintaining policies, standards, procedures, and playbooks related to Business Continuity, Disaster Recovery, and Incident Response.
- Experience with ISO 27001 / ISO 27002 compliance.
- Knowledge of data protection best practices and compliance requirements under the LGPD and GDPR.
- Hands-on experience implementing controls and managing remediation plans.
- Knowledge of risk management frameworks (e.g., ISO 27005, NIST).
- Experience collaborating with Engineering and Development teams on resilience and compliance initiatives.
- Advanced Portuguese proficiency.
- Advanced English proficiency.
Nice to Have
- Experience with compliance automation and GRC platforms (e.g., Vanta, Drata, etc.).
- Experience with Business Continuity Management (BCM) tools.
- Experience working with multiple security frameworks and regulatory environments.
- Experience using task and project management platforms (e.g., Jira, Linear, Monday, etc.) to manage remediation plans and compliance initiatives.
- Market-recognized security certifications.
- Experience leveraging automation and Artificial Intelligence (AI) to improve GRC processes, evidence collection, reporting, and compliance operations.
Soft Skills
- Ability to collaborate effectively across technical and business teams.
- Excellent communication skills.
- Proactive, analytical, and solution-oriented.
- Highly organized, with strong attention to documentation and audit evidence.
- Team-oriented mindset (one person’s problem is everyone’s problem).
- Comfortable working in dynamic environments and navigating ambiguity.
- Ability to independently drive assigned initiatives and deliver high-quality results.
- Continuous improvement mindset focused on strengthening organizational resilience.
- Competitive Compensation
- 30 days of paid annual leave
- Education and courses stipend
- Earn a trip anywhere in the world every 4 years
- R$1.035/month for meals allowance
- Health plan with national coverage and without coparticipation
- Dental Insurance: we help you with dental treatment for a better quality of life.
- Wellhub Membership: Access a wide range of gyms and training programs.
Similar Jobs
Information Technology • Productivity • Software • Infrastructure as a Service (IaaS)
Develop scalable Java and Kotlin software for NinjaOne’s ticketing and billing products. Build reliable systems for ticket workflows, invoicing, quoting, accounting integrations, and endpoint-management connections. Responsibilities include implementing enterprise software, scaling data structures and services, applying object-oriented design, developing REST APIs, working with relational databases and Redis, and maintaining rigorous testing and quality standards.
Top Skills:
AWSC++GoJavaJerseyKotlinPostgresRedisRestSpring
Digital Media • Gaming • Software • Esports • Automation
Manage public affairs and government relationships for bet365’s regulated Brazilian market entry. Build partnerships with policymakers, regulators, media, sports bodies, law firms, and consultants. Monitor legislation, participate in public consultations, prepare political analysis and reports, respond to regulatory inquiries, and develop strategies influencing policy decisions. The role requires Brazilian regulatory expertise, corporate diplomacy, Portuguese fluency, English proficiency, residence in Brasília, and frequent travel.
eCommerce • Fashion • Retail • Sales • Wearables • Design
Provides personalized luxury retail service, styling advice, and product expertise while meeting individual and store sales goals. Builds client relationships through cross-selling, upselling, clienteling, social selling, and follow-up. Performs POS transactions, inventory processing, replenishment, visual merchandising, online pickups, and stockroom organization. Supports store operations, brand initiatives, team collaboration, and customer experience standards while working flexible retail schedules.
Top Skills:
Clienteling ToolsIpadLaptopMobile PosPosSocial Selling Platforms
What you need to know about the Austin Tech Scene
Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.
Key Facts About Austin Tech
- Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
- Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
- Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
- Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center



