The Role
Lead and improve operational resilience, business continuity, disaster recovery, and incident response programs. Conduct BIAs, define RTO/RPO, create recovery plans and playbooks, run exercises and tests, maintain risk and control registers, support ISO 27001/27002 and ISO 22301/22313 compliance, respond to security questionnaires, and collaborate with engineering and security teams to implement controls and remediation.
Summary Generated by Built In
GRC at TRACTIAN
The Engineering team at Tractian is at the forefront of developing cutting-edge infrastructure, technologies, and products to harness the power of IoT data. Our team of talented Engineers collaborates to build robust systems, innovative solutions, and scalable platforms that drive Tractian's success. We are instrumental in shaping the company's decision-making process, optimizing operational efficiency, and delivering exceptional experiences to our consumers.
What you'll do
As a GRC Analyst, you will be responsible for developing and implementing robust governance, risk management, and compliance (GRC) practices within our technology-driven organization. You will play a key role in establishing frameworks and processes that ensure the security, integrity, and regulatory compliance of our technology systems. You will collaborate with cross-functional teams to assess risks, implement controls, and drive continuous improvement of our GRC program.
Key Responsibilities
- Lead and continuously improve the organization's operational resilience, business continuity, and risk management activities – including identifying, assessing, documenting, monitoring, and reviewing operational, technology, cybersecurity risks.
- Perform Business Impact Analysis (BIA), define recovery objectives (RTO/RPO), develop disruption scenarios, and establish contingency, recovery, and business continuity strategies for critical business services.
- Develop, implement, maintain, and continuously improve the organization's Business
- Continuity (BCM), Disaster Recovery (DR), and Incident Response (IR) activities, including policies, standards, procedures, recovery plans, and playbooks, aligned with corporate objectives, regulatory requirements, and industry best practices.
- Plan, facilitate, execute, and document tabletop exercises, recovery tests, backup and recovery validation, failover exercises, and other resilience testing activities, ensuring lessons learned and corrective actions are tracked.
- Maintain the enterprise risk register, controls, mitigation plans, and audit evidence within the organization's GRC/compliance platform, partnering with control owners to drive remediation activities through completion.
- Collaborate with Engineering, Development, Infrastructure, Security, and business stakeholders to design, implement, and continuously improve risk, resilience, recovery, and incident management processes.
- Support and continuously improve compliance with ISO 27001, ISO 27002, ISO 22301, and ISO 22313 through assessments, internal controls, audits, and remediation activities.
- Support customer security and compliance due diligence activities, including responding to security questionnaires (e.g., SIG, CAIQ, RFPs) in collaboration with the GRC team and subject matter experts.
- Provide guidance to business and technology teams on governance, risk, operational resilience, and compliance matters.
- Partner closely with Engineering, Infrastructure, Product, Security, and business teams to integrate governance, risk, and compliance practices into business and technology initiatives.
- Collaborate with cross-functional teams on a variety of Security GRC initiatives, contributing to governance, risk, compliance, and assurance programs in support of shared organizational goals.
Requirements
- Background in Information Technology, Information Security, Governance, Risk & Compliance (GRC), Internal Audit, Compliance, or Quality Management.
- Experience implementing and operating Business Continuity Management (BCM) and
- Disaster Recovery (DR) programs based on ISO 22301 and ISO 22313.
- Experience conducting Business Impact Analysis (BIA), defining RTO/RPO, recovery strategies, contingency planning, and business disruption scenarios.
- Experience planning and facilitating tabletop exercises and technical recovery tests for Business Continuity, Disaster Recovery, and Incident Response.
- Experience developing and maintaining policies, standards, procedures, and playbooks related to Business Continuity, Disaster Recovery, and Incident Response.
- Experience with ISO 27001 / ISO 27002 compliance.
- Knowledge of data protection best practices and compliance requirements under the LGPD and GDPR.
- Hands-on experience implementing controls and managing remediation plans.
- Knowledge of risk management frameworks (e.g., ISO 27005, NIST).
- Experience collaborating with Engineering and Development teams on resilience and compliance initiatives.
- Advanced English proficiency.
Nice to Have
- Experience with compliance automation and GRC platforms (e.g., Vanta, Drata, etc.).
- Experience with Business Continuity Management (BCM) tools.
- Experience working with multiple security frameworks and regulatory environments.
- Experience using task and project management platforms (e.g., Jira, Linear, Monday, etc.) to manage remediation plans and compliance initiatives.
- Market-recognized security certifications.
- Experience leveraging automation and Artificial Intelligence (AI) to improve GRC processes, evidence collection, reporting, and compliance operations.
Soft Skills
- Ability to collaborate effectively across technical and business teams.
- Excellent communication skills.
- Proactive, analytical, and solution-oriented.
- Highly organized, with strong attention to documentation and audit evidence.
- Team-oriented mindset (one person’s problem is everyone’s problem).
- Comfortable working in dynamic environments and navigating ambiguity.
- Ability to independently drive assigned initiatives and deliver high-quality results.
- Continuous improvement mindset focused on strengthening organizational resilience.
- Competitive salary and stock options
- 30 days of paid annual leave
- Education and courses stipend
- Earn a trip anywhere in the world every 4 years
- R$1.035/month for meals allowance
- Health plan with national coverage and without coparticipation
- Dental Insurance: we help you with dental treatment for a better quality of life.
- Wellhub and Sports Incentive: R$300/mo extra if you practice activities
Skills Required
- Background in Information Technology, Information Security, Governance, Risk & Compliance (GRC), Internal Audit, Compliance, or Quality Management
- Experience implementing and operating Business Continuity Management (BCM) and Disaster Recovery (DR) programs based on ISO 22301 and ISO 22313
- Experience conducting Business Impact Analysis (BIA), defining RTO/RPO, recovery strategies, contingency planning, and disruption scenarios
- Experience planning, facilitating, and documenting tabletop exercises and technical recovery tests for BCM, DR, and Incident Response
- Experience developing and maintaining policies, standards, procedures, recovery plans, and playbooks related to BCM, DR, and IR
- Experience with ISO 27001 and ISO 27002 compliance
- Knowledge of data protection best practices and compliance requirements under LGPD and GDPR
- Hands-on experience implementing controls and managing remediation plans
- Knowledge of risk management frameworks (e.g., ISO 27005, NIST)
- Experience collaborating with Engineering, Development, Infrastructure, Security, and business stakeholders on resilience and compliance initiatives
- Advanced English proficiency
- Experience with compliance automation and GRC platforms (e.g., Vanta, Drata)
- Experience with Business Continuity Management (BCM) tools
- Experience using task and project management platforms (e.g., Jira, Linear, Monday) to manage remediation and compliance initiatives
- Experience working with multiple security frameworks and regulatory environments
- Market-recognized security certifications
- Experience leveraging automation and Artificial Intelligence (AI) to improve GRC processes, evidence collection, and reporting
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Tractian is a machine-intelligence company delivering integrated hardware, cloud software and AI to prevent machine failures and boost industrial uptime. Their offering combines vibration and condition sensors, TracOS maintenance-management software, and AI-driven analytics to enable predictive maintenance, energy optimization and operational visibility for factories and asset-heavy operations globally.

.png)







