iFood05.03.26
AI SCORE 8.5

Staff Software Engineer - IT Risk & Security (Remote)

$90K–$120K/year

About the Role

Join iFood as a Staff Software Engineer - IT Risk & Security (Remote) and transform your career! We are a leading technology company in Latin America, connecting thousands of restaurants to millions of consumers daily, with an average of 100 million orders per month. Beyond food delivery, we also operate in the marketplace, pharmacy, and pet sectors. Our fintech, iFood Pago, offers a range of financial services including benefits and payment solutions for restaurants. Be part of a team that is always at the forefront of technology and innovation.

What You'll Do

  • Lead processes for identifying, analyzing, evaluating, and treating IT and information security risks.
  • Develop and maintain risk management methodologies aligned with ISO 27005, ISO 31000, and NIST Cybersecurity Framework.
  • Create and update risk matrices, impact analyses, and treatment plans.
  • Conduct risk analyses for projects, processes, suppliers, and new technologies.
  • Monitor risk indicators (KRIs) and report to the executive committee.
  • Plan, conduct, and document internal audits in compliance with ISO 27001, LGPD, PCI DSS, and other frameworks.
  • Act as the focal point for external audits, certifications, and third-party assessments.
  • Prepare audit plans, checklists, non-compliance reports, and action plans.
  • Oversee remediation of identified gaps from audits.
  • Conduct audits of critical suppliers and third-party security assessments.
  • Ensure compliance with regulations such as LGPD, GDPR, PCI DSS, SOX, and more.
  • Develop, review, and update information security policies, standards, and procedures.
  • Implement security controls based on frameworks like ISO 27002, CIS Controls, and COBIT, tailored to the organization.
  • Generate executive reports on risks, compliance, and audits for the board and management.
  • Develop dashboards and indicators (KPIs/KRIs) to present risk status, incidents, and compliance in strategic committees.

Requirements

  • Bachelor's degree in Information Technology, Information Security, Engineering, Administration, Law, or related fields.
  • A minimum of 4 years of experience in risk management, compliance, or IT auditing.
  • Proven experience in conducting internal audits and supporting external audits.
  • Familiarity with risk management methodologies (ISO 27005, ISO 31000, NIST RMF).
  • Experience with ISO 27001 certification processes.
  • Advanced English proficiency (reading standards and communication with international auditors).

Nice to Have

  • Postgraduate/MBA in Risk Management, GRC, Information Security, Auditing, or related fields.
  • Certifications (ISO 27001 Lead Auditor or Lead Implementer PECB, CRISC, CISA, CISSP).
  • Previous experience in fast-growing companies and dynamic environments.
  • Experience with additional frameworks: PCI DSS, CIS Controls, NIST 800-53.
  • Knowledge in Secure Development (OWASP SAMM, OWASP ASVS, OWASP Top 10).
  • Experience with AI and risk management automation and data analysis (Python, Power BI, Looker Studio, SQL, etc.).

What We Offer

  • Competitive salary and benefits package.
  • Remote work flexibility.
  • Opportunities for professional growth and development.
  • Innovative and collaborative work environment.
  • Access to cutting-edge technology and tools.
Language Requirements
EnglishC1
BasicIntermediateAdvancedNative
Why This Job8.5 of 10

This role offers a unique opportunity to work with a leading FinTech company, focusing on IT risk and security. Enjoy remote work and a competitive salary.

Salary Range
Required
0/1
Optional
0/1
Bonus
0/1

Who Will Succeed Here

Proficient in implementing risk management frameworks such as ISO 27001 and NIST Cybersecurity Framework, with hands-on experience in conducting compliance audits and assessments.

Demonstrates strong analytical skills and attention to detail, particularly in using Python for data analysis and Power BI for visualizing risk metrics, ensuring clear communication of security posture to stakeholders.

Possesses a proactive mindset towards continuous improvement and learning, adapting to the evolving landscape of cybersecurity threats while working effectively in a remote setting.

Learning Resources

ISO 27001:2013 - Information Security Management System (ISMS)guide

Career Path

Staff Software Engineer - IT Risk & Security(Now)Lead Security Engineer(1-2 years)Director of IT Risk & Security(3-5 years)

Market Overview

Market Size 2024
$16.4B
Annual Growth
11.2%
AI Adoption
45%
Investment in Cybersecurity
+30%
Labour Demand for Risk Management Professionals
+25%
Avg Salary for Staff Software Engineer in Risk Management
$125K

Skills & Requirements

Required
Risk ManagementISO 27001NIST Cybersecurity Framework
Growing in Demand
Cloud SecurityDevSecOpsThreat Intelligence
Declining
Traditional Firewall ManagementStatic Code Analysis Tools

Domain Trends

Increased Regulatory Compliance
With 70% of companies facing increased scrutiny from regulators, the demand for compliance expertise in IT risk management is surging.
Integration of AI in Risk Management
45% of organizations are investing in AI-driven risk assessment tools, transforming traditional risk management practices.
Shift to Remote Risk Assessments
As remote work continues, 60% of businesses have adopted remote risk assessment methodologies, driving the need for professionals skilled in digital risk frameworks.

Industry News

Loading latest industry news...

Finding relevant articles from the last 6 months

All job postings are automatically gathered by algorithms. We do not review or verify listings, be careful when applying and do not sign-in with iCloud or Google services.