Software Engineer
Senior security professional leading governance, risk, and compliance initiatives, implementing ISO 27001 and NIST frameworks, managing cloud security on AWS, conducting audits, and driving compliance through GRC tools.
About Grupo QuintoAndar
We are Grupo QuintoAndar , the largest real estate ecosystem in Latin America. Guided by a shared purpose of helping people love where they live, we have a diversified portfolio of brands and solutions across different countries in Latin America, covering all phases of the housing journey. We also have a Technology Hub in Portugal. We develop technology and innovation to transform and enhance the overall living experience.
With the support of a world-class team of investors and advisors, including Kaszek, Qualcomm, General Atlantic, and SoftBank, Grupo QuintoAndar is currently valued at over USD 5.1 billion and continues to grow year over year.
Here, you will work with top professionals in the market, in an environment that breathes innovation, collaboration, and high performance. To learn more about our story, visit: https://grupoquintoandar.com/pt/ .
Location & Remote Work
Our technology team operates under a "remote-first" model, which means we work from home and can live anywhere in Brazil. We also offer the option of working from our São Paulo offices or partner coworking spaces, up to twice a week.
Hiring Process Stages
The stages of our hiring processes aim to assess your experiences and allow you to meet our teams and explore career opportunities. They are structured as follows:
About the Team
We are looking for a senior person to act in the evolution of the Information Security GRC discipline, focusing on transforming risks, controls, and requirements into practical business decisions.
This is not a position for someone focused only on frameworks, audits, or documentation. We are looking for someone strong in GRC, but with the technical repertoire to discuss controls, architecture, third parties, identity, data, cloud, and technology in practice.
The goal of this position is to increase the company's security maturity, bring more quality to risk decisions, and ensure that governance and compliance processes are useful in practice, and not just correct on paper.
What we expect from this position
We expect someone who connects Information Security risks to the business context and transforms this into practical action. Someone who moves well between executive and technical discussions, can structure and evolve governance and risk management processes, conducts consistent assessments, orchestrates the evolution of teams, and supports decisions with clarity, credibility, and a focus on results.
We are looking for a profile that goes beyond compliance on paper, understands controls in practice, evaluates their effectiveness, and has the seniority to act on different fronts of the team, such as cyber risks, policies and standards, third-party
Posted June 24, 2026