--- title: 'Grupo QuintoAndar | Information Security Manager - GRC at Grupo QuintoAndar' canonical: 'https://feeny.ai/job/grupo-quintoandar-information-security-manager-grc-grupo-quintoandar-brazil-v5dzq7bnhnsj' type: 'job' last_seen: '2026-09-14' --- # Grupo QuintoAndar | Information Security Manager - GRC at Grupo QuintoAndar - **Company:** Grupo QuintoAndar - **Location:** Brazil - **Posted:** 2026-08-04 - **Last confirmed live:** 2026-09-14 - **Apply:** https://job-boards.greenhouse.io/quintoandar/jobs/4341782009 ## Job description ## About Grupo QuintoAndar We are Grupo QuintoAndar, the largest real estate ecosystem in Latin America. Guided by a shared purpose of helping people love where they live, we have a diversified portfolio of brands and solutions across different countries in Latin America, covering all phases of the housing journey. We also have a Technology Hub in Portugal. We develop technology and innovation to transform and enhance the overall living experience. With the support of a world-class team of investors and advisors, including Kaszek, Qualcomm, General Atlantic, and SoftBank, Grupo QuintoAndar is currently valued at over USD 5.1 billion and continues to grow year over year. Here, you will work with top professionals in the market, in an environment that breathes innovation, collaboration, and high performance. To learn more about our story, visit:https://grupoquintoandar.com/pt/https://grupoquintoandar.com/pt/. Location & Remote Work Our technology team operates under a "remote-first" model, which means we work from home and can live anywhere in Brazil. We also offer the option of working from our São Paulo offices or partner coworking spaces, up to twice a week. ## About the Position We are looking for a leader to take on the role of Manager of Information Security, GRC. Your mission will be to define the area's vision, structure our practices, and lead the transformation: shifting the perception that GRC is merely an operational and bureaucratic function to making it a dynamic, strategic enabler focused on real business risk. This is not a position for managing spreadsheets. As the GRC leader within the Cybersecurity structure, you will work side-by-side with the CISO and others leadership to safely enable critical projects. We seek someone with technical capability, execution skills, and strategic vision, able to drive projects end-to-end and ensure that security governance makes our business faster, more scalable, and resilient. You must have proven experience in GRC leadership that goes beyond regulatory compliance and paper-based frameworks, understanding control architectures and the technological nuances of an agile, cloud-native environment (Cloud, AI, Data). You will be primarily responsible for accountability regarding cyber risk, guiding the company through complex scenarios. The Manager of GRC will report directly to the CISO and will be responsible for managing the investment, the internal team, and the third-party (3P) partners supporting the GRC operation. Main Responsibilities - GRC Leadership & Strategy: Develop and lead the GRC strategy, building and executing roadmap in full alignment with the company's business objectives, budget, and risk appetite. - Security Service Channel & Portfolio: Own the company's security service channel and security portfolio, acting as the primary intake and coordination point for security requests and initiatives, ensuring visibility and prioritization across the security program. - Information Security Governance & Artificial Intelligence: Lead the Information Security Governance model. Take the lead in AI governance, establishing guidelines, controls, and policies to ensure the safe, ethical, and compliant use of new technologies across the company. - IAM Governance: Lead IAM Governance projects, ensuring identity and access management controls and processes are aligned with the company's risk and SOX compliance requirements. - People Management & Development (EM): Lead, inspire, and develop a high-performance team of GRC specialists, promoting engagement, autonomy, and technical excellence. - Operationalized Risk Management: Lead the end-to-end cyber risk management program (identification, treatment, monitoring, and remediation plans), with strong ability to financially quantify cyber risk using methodologies such as FAIR (Factor Analysis of Information Risk). - Third-Party Risk Management (TPRM) & Cyber Resilience: Lead third-party risk management and cyber resilience programs, ensuring the extended supply chain and critical vendors meet the company's security and compliance standards. - Continuous Compliance: Ensure compliance with regulations (e.g., LGPD, SOx, GDPR) and frameworks, acting as the company's voice to respond to and negotiate with internal and external audits and regulatory bodies, implementing a Continuous Compliance model. - Committees & Metrics (KPIs/KRIs): Act as a member of the Information Security Committee, defining and reporting strategic, tactical, and operational indicators, risk metrics, and maturity evolution to executive leadership and supporting the preparation of materials for these forums. - Culture & Awareness: Lead the corporate security awareness strategy, transforming the human factor into the first line of defense through engaging programs and metrics that prove a reduction in behavioral risk. - Policies (ISP): Structure, simplify, review, and maintain the framework of policies, standards, procedures, and processes related to Information Security. - Partnership & Focal Point: Act as the primary focal point and business partner for GRC topics with Technology, Engineering, Product, Legal, Privacy, Finance, Compliance, Internal Audit, and business leaders. Identify opportunities to build practical, structural processes that mitigate risks. ## Requirements - 10+ years of experience in Information Security GRC, with at least 5 years in leadership and team management roles within complex, dynamic, and multinational corporate environments (preferably tech companies, scale-ups, or the financial sector). - Experience managing security demand intake and portfolio prioritization, ideally leveraging ITSM practices. - Deep mastery and critical vision in structuring frameworks and standards such as NIST CSF 2.0, ISO 27001/27002, CIS Controls, SOX and ISO 31000. - Exceptional ability to translate technical cyber risks into financial and operational impacts using methodologies such as FAIR. - Experience designing and operationalizing security KPI/KRI frameworks and maturity models for executive reporting. - Experience designing vendor risk assessment methodologies and TPRM programs. - Experience leading IAM Governance initiatives, ensuring identity and access management controls and processes are aligned with the company's risk and compliance requirements. - Experience supporting SOX compliance programs, including IT General Controls (ITGC). - Experience designing and running security awareness and behavior change programs. - GRC Engineering mindset: ability to use automation and AI to solve GRC problems at scale (e.g., automated evidence collection, continuous controls monitoring, risk quantification), reducing manual and bureaucratic work. - Fluency in Portuguese and advanced English. ## Nice to have - Certifications such as CISSP, CISM, CRISC, or ISO 27001 Lead Auditor will be considered a differential. ## Benefits - Competitive salary - Profit sharing - Meal allowance - Health insurance - Dental plan - Life insurance - Childcare subsidy and Atypical Parenthood subsidy - Wellhub - Home office allowance - Employee assistance program (mental health, social, legal, and financial support) - Extended parental leave - Day off on birthday, Mother’s Day, and Father’s Day - Benefits Club (discounts on everyday services) - Discounts at educational institutions - Reading kit for children – PlayKids Diversity & Inclusion at Grupo QuintoAndar We value diversity and want everyone to feel welcome here, regardless of their age, gender identity, sexual orientation, race, color, ethnicity, origin, disability, religion, or any other characteristic. All our job openings are open to all individuals! You'll notice there are some diversity questions in the application form. For affirmative action roles, this information may be used to verify your alignment with the target audience for the opportunity. In such cases, it may be used for elimination purposes. For non-affirmative action roles, this data will be used anonymously, exclusively to monitor and improve our inclusion practices in the hiring process, and will have no impact on your application. Privacy and Data Protection The Grupo QuintoAndar operates in compliance with privacy and data protection laws, including, but not limited to, the Brazilian General Personal Data Protection Law (LGPD) (Law No. 13,709/2018), and ensures the security of your data. To learn more, please access our[Privacy Notice for Candidates](https://carreiras.quintoandar.com.br/aviso-de-privacidade-para-pessoas-candidatas/?lang=en). For questions or to exercise your rights as a data subject, please contact us through our[Service Channel](https://www.cognitoforms.com/QuintoAndarcom/LeiGeralDeProte%C3%A7%C3%A3oDeDadosPessoaisLGPD). ## #LI-CO2 ## About Grupo QuintoAndar ## Company Overview - **One-liner**: Grupo QuintoAndar is the largest real estate ecosystem in Latin America, connecting people with rental, sale, and classified property solutions through technology. - **Entity Type**: Private (Series E) - **Headquarters**: São Paulo, Brazil (with offices in 6 Latin American countries and a tech hub in Lisbon, Portugal) - **Founded**: 2013 - **Founders**: Not publicly available (Gabriel Braga serves as CEO) ## Core Business - **Primary industries**: Real estate technology, property marketplace, brokerage, classifieds - **Target customers**: B2C (home seekers and property owners), B2B (real estate agents and brokers), and enterprise (property managers) - **Mission/purpose**: Help people love where they live by offering a simple and transparent living experience ## Products & Services - **QuintoAndar (Brokerage)**: Full-service rental and sales platform for residential properties in Brazil, handling everything from listing to contract management. - **Casa Mineira**: Leading real estate agency in Belo Horizonte, Brazil, offering brokerage services. - **Imovelweb, Zonaprop, Plusvalia, Aondevivir, Inmuebles24, Urbania, Compreoalquile**: Classifieds brands in Argentina, Ecuador, Panama, Peru, Mexico, and other Latin American markets that connect agents and brokers with home seekers. - **Noknox**: A SaaS platform providing apps for condominiums, connecting residents with managers, doormen, and service providers. - **Tokko**: A CRM and lead management platform for real estate professionals (SaaS). - **Benvi**: New brand launched in Mexico for the local market. ## Market Standing - **Valuation**: US$5.1 billion (as of latest round, date not specified) - **Key Metric**: Total funding raised – more than US$755 million - **Notable Investors/Partners**: SoftBank, Dragoneer, QED Investors, Qualcomm, Maverick, Ribbit, Alta Park, Kaszek - **Growth Signals**: - 3,500+ employees across 6 countries and a European tech hub - Over 10,000 properties sold or rented per month - +50 million monthly website visits - 45% women in leadership; increased Black representation from 12% to 31% in 18 months - BRL 80 billion in assets under management by QuintoAndar - Expanded to Mexico with new brand Benvi ## Competitive Advantages - **Ecosystem breadth**: Covers the full housing journey from search and brokerage to condo management and professional tools, creating a network effect. - **Scale dominance**: Largest real estate group in Latin America with #1 classifieds positions in Mexico, Argentina, Peru, and Ecuador. - **Technology-first approach**: Remote-first tech team, proprietary SaaS and marketplace platforms, data-driven matching. - **Strong investor backing**: Over $755M raised from top-tier global VCs provides capital for expansion and innovation. ## Strategic Focus - **International expansion**: Entering Mexico and other Latin American markets through organic brands and acquisitions. - **Product diversification**: Adding tools for property managers (Noknox) and agents (Tokko) to deepen the ecosystem. - **Diversity & inclusion**: Actively increasing representation of underrepresented groups, with affinity groups for gender, race, LGBTQIAP+, disability, and social impact. - **Remote/hybrid work**: Technology team operates "remote-first" with optional office or coworking use up to twice a week. ## Why Work Here - **Culture**: Strong emphasis on diversity, inclusion, and belonging – 80% of employees strongly share the company’s D&I values. Affinity groups drive strategic discussions. - **Work model**: Remote-first for tech roles (anywhere in Brazil), hybrid/office options for other teams. Offices in São Paulo and Campinas, plus partner coworking spaces. - **Benefits**: Comprehensive health insurance (physical and mental), meal stipend, variable compensation, parental assistance, and competitive compensation packages. - **Growth environment**: Fast-scaling company with a decade of market experience, offering opportunities to work on technology that transforms a traditional industry. - **Global exposure**: Teams across multiple countries and a tech hub in Lisbon, enabling cross-cultural collaboration. ## Sources 1. [Grupo QuintoAndar Official Site](https://grupoquintoandar.com/) 2. [QuintoAndar Careers – Why Work Here](https://carreiras.quintoandar.com.br/por-que-trabalhar-aqui/?lang=en) 3. [QuintoAndar Careers – Home](https://carreiras.quintoandar.com.br/?lang=en) 4. [Grupo QuintoAndar LinkedIn](https://www.linkedin.com/company/grupo-quintoandar) 5. [QuintoAndar Newsroom – About](https://www.quintoandar.com.br/newsroom/sobre/) ## Other roles at Grupo QuintoAndar - [Grupo QuintoAndar | Analista de Reclame Aqui Pleno - Afirmativa PCD](https://feeny.ai/job/grupo-quintoandar-analista-de-reclame-aqui-pleno-afirmativa-pcd-grupo-3s5smqm8z3pg) — São Paulo São Paulo, Brazil - [Grupo QuintoAndar | Especialista em Sistemas de Cobrança (CyberFinancial)](https://feeny.ai/job/grupo-quintoandar-especialista-em-sistemas-de-cobranca-cyberfinancial-grupo-0rhx93wj2q1n) — São Paulo São Paulo, Brazil - [Grupo QuintoAndar| Gerente de Planejamento e Performance](https://feeny.ai/job/grupo-quintoandar-gerente-de-planejamento-e-performance-grupo-quintoandar-sao-xbdez69c9mqh) — São Paulo São Paulo, Brazil - [Grupo QuintoAndar | Growth Intelligence Specialist - Supply Governance](https://feeny.ai/job/grupo-quintoandar-growth-intelligence-specialist-supply-governance-grupo-kxy5az34wtnf) — São Paulo São Paulo, Brazil - [Grupo QuintoAndar | Account Manager - Onboarding B2B (Campinas)](https://feeny.ai/job/grupo-quintoandar-account-manager-onboarding-b2b-campinas-grupo-quintoandar-sao-mcd513p94nr7) — São Paulo São Paulo, Brazil - [Grupo QuintoAndar | Analista Pleno de Sales Operations](https://feeny.ai/job/grupo-quintoandar-analista-pleno-de-sales-operations-grupo-quintoandar-sao-btt2m2gne2br) — São Paulo São Paulo, Brazil - [Grupo QuintoAndar | Analista de Inside Sales Júnior (Inbound)](https://feeny.ai/job/grupo-quintoandar-analista-de-inside-sales-junior-inbound-grupo-quintoandar-sao-xm2rv47grx69) — São Paulo São Paulo, Brazil - [Farmer SMB](https://feeny.ai/job/farmer-smb-grupo-quintoandar-mexico-city-mexico-city-j5w9j84y84te) — Mexico City Mexico City, Mexico - [Banco de Talentos I Telesales Executive - Argentina](https://feeny.ai/job/banco-de-talentos-i-telesales-executive-argentina-grupo-quintoandar-argentina-rq8sj0dhnf53) — Argentina - [Grupo QuintoAndar | Analista de Inside Sales Sênior (Consórcio)](https://feeny.ai/job/grupo-quintoandar-analista-de-inside-sales-senior-consorcio-grupo-quintoandar-hqh4ctc2rvnh) — São Paulo São Paulo, Brazil