Rodeo
Get started

B Lab

IT Security & Compliance Lead (São Paulo, BR)

São Paulo
R$212.9k – R$261.1k/yr
Posted about 22 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

IT Security & Compliance Lead

Job Overview

This is a Full-Time Role (40 hours per week, 5DWW) with no option for part-time work. While this is a remote-first opportunity, the candidate filling this role must be a resident of Brazil at the start of employment. Additionally, they must be within commuting distance of São Paulo.

About the Team

The Technology & Data portfolio provides the digital infrastructure, engineering and data capabilities that enable effective delivery, innovation and learning across the B Lab Global Network. Infrastructure & Information Management (Operational Technology) is responsible for information security, workforce enablement and the adoption of digital tools across the network.

About the Opportunity

B Lab is seeking an IT Security & Compliance Lead to own security governance across the global network. Consolidation increases security exposure as organizations with different controls come together, and this role exists to set a consistent baseline and raise our security posture proactively rather than reactively.

Core Responsibilities

  • Security Governance, Audits, and Assessments
    • Conduct regular security audits and risk assessments of network systems, applications and processes, and maintain a prioritized risk register
    • Establish and maintain a security baseline across the network, aligned to a recognized framework (for example ISO/IEC 27001:2022)
    • Track and report security posture and maturity over time to the Technology leadership team, with clear metrics
    • Run security reviews of new and existing vendors and technology platforms (third-party risk), including SaaS tools used by regional and market teams
    • Coordinate external penetration testing and vulnerability scanning, and track remediation with system owners
  • Identity, access and platform security
    • Define and monitor access control standards (MFA, SSO, least privilege, joiner/mover/leaver processes) across core platforms such as Google Workspace and Salesforce
    • Partner with Regional IT Administrators on endpoint and device security standards for a distributed, remote-first workforce, moving toward a zero-trust model
    • Advise Product & Platform Engineering on secure-by-design practices for B Lab's digital
  • Security policy development and awareness
    • Own and maintain the information security policy set (including the Information Security, Backup & Recovery and Security Incident Management policies) and the standards and procedures that support it
    • Refine policies as the network consolidates, and communicate changes clearly to staff across regions and languages
    • Own the network-wide security awareness program (KnowBe4), including training, phishing simulations and completion reporting
    • Contribute the security perspective to the B Lab AI Policy and to the safe adoption of AI tools
  • Incident response and resilience
    • Own and maintain the incident response plan, covering detection, escalation, containment, communication and post-incident review
    • Serve as lead coordinator during security incidents, working with Legal, Communications and affected regions
    • Support business continuity and disaster recovery planning, including testing backup and recovery procedures
  • Compliance and risk management support
    • Support data protection compliance across the regions where B Lab operates (for example GDPR, UK GDPR and Brazil's LGPD), in partnership with Legal and the Data Governance Lead
    • Partner with Legal, HR, Finance and other teams on compliance matters, such as data processing agreements, data subject requests and breach notification
    • Maintain documentation and evidence that supports audits, partner and funder due diligence, and regulatory inquiries

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

About You

  • 3+ years of experience in information security, IT governance, risk and compliance (GRC), or a closely related field
  • Strong understanding of networking concepts, cybersecurity, and implementing best practices to ensure compliance with data and regulatory tech laws.
  • Strong understanding of at least one recognized cybersecurity framework
  • Experience conducting security audits, risk assessments and vendor security reviews
  • Working knowledge of data protection regulations relevant to a global organization (for example GDPR, LGPD)
  • Experience developing or maintaining incident response and business continuity plans
  • Hands-on familiarity with cloud and SaaS security, especially Google Workspace administration and identity and access management
  • Ability to explain security risk in plain language to non-technical colleagues, and to write clear policies

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Compensation Details

  • A yearly salary in the range of R$212,960 - R$261,030 (not including the 13th salary)
  • Sick & other leave in accordance with Brazilian statutory leave allowance
  • Company provided laptop
  • Paid time off during organization-wide closures for wellness
  • Professional Development and time off: 40 hours paid time off with access to professional development after 1 year of service
  • Paid time off for volunteering - after one year of service
  • One time home office set-up allowance
  • Additional perks you may qualify for: monthly home office allowance, monthly food allowance & monthly health insurance reimbursement

Hiring Process

We require all of the following in order to consider your application:

  • Resume
  • Complete responses to our standard set of application questions

About B Lab

B Lab™ is the nonprofit behind Certified B Corporations™, a community of businesses that meet verified social, environmental, and governance standards. Together, our movement is working towards a more inclusive, equitable, and fair economic system.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

São Paulo, São Paulo, Brazil

Sign up to applySee more jobs like this